Windows
Analysis Report
zyx3qItgQK.exe
Overview
General Information
Sample name: | zyx3qItgQK.exerenamed because original name is a hash value |
Original sample name: | 1D641A341DF0631BF135F5767440DF01.exe |
Analysis ID: | 1384274 |
MD5: | 1d641a341df0631bf135f5767440df01 |
SHA1: | 2e76be5d5a7f0bae3657a649eb60f47c4fbde3cf |
SHA256: | 3fa1b0d5ab8cc2b3435718e8b625e63e651a6d3df4d7657dc8c3859caeb5b4e9 |
Tags: | exenjratRAT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- zyx3qItgQK.exe (PID: 5576 cmdline:
C:\Users\u ser\Deskto p\zyx3qItg QK.exe MD5: 1D641A341DF0631BF135F5767440DF01) - ESET Service.exe (PID: 5872 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" MD5: 1D641A341DF0631BF135F5767440DF01) - netsh.exe (PID: 3908 cmdline:
netsh fire wall add a llowedprog ram "C:\Us ers\user\A ppData\Roa ming\ESET Service.ex e" "ESET S ervice.exe " ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF) - conhost.exe (PID: 3536 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - taskkill.exe (PID: 1812 cmdline:
taskkill / F /IM task mgr.exe MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - conhost.exe (PID: 6708 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- ESET Service.exe (PID: 3492 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" . . MD5: 1D641A341DF0631BF135F5767440DF01)
- ESET Service.exe (PID: 3928 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" . . MD5: 1D641A341DF0631BF135F5767440DF01)
- ESET Service.exe (PID: 4044 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" . . MD5: 1D641A341DF0631BF135F5767440DF01)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
NjRAT | RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored. |
{"Host": "6.tcp.eu.ngrok.io", "Port": "12041", "Version": "im523", "Campaign ID": "HacKed", "Install Name": "ESET Service.exe", "Install Dir": "AppData"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Click to see the 7 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
System Summary |
---|
Source: | Author: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Timestamp: | 192.168.2.63.69.115.17849707120412033132 01/31/24-18:02:40.293747 |
SID: | 2033132 |
Source Port: | 49707 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849711120412825564 01/31/24-18:03:57.860489 |
SID: | 2825564 |
Source Port: | 49711 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949713120412814856 01/31/24-18:04:50.646104 |
SID: | 2814856 |
Source Port: | 49713 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949714120412825563 01/31/24-18:05:23.258517 |
SID: | 2825563 |
Source Port: | 49714 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949712120412033132 01/31/24-18:04:17.975768 |
SID: | 2033132 |
Source Port: | 49712 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949714120412825564 01/31/24-18:05:51.313700 |
SID: | 2825564 |
Source Port: | 49714 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949715120412825564 01/31/24-18:05:55.916285 |
SID: | 2825564 |
Source Port: | 49715 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849707120412825563 01/31/24-18:02:40.497750 |
SID: | 2825563 |
Source Port: | 49707 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849710120412825564 01/31/24-18:03:36.423392 |
SID: | 2825564 |
Source Port: | 49710 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949712120412814856 01/31/24-18:04:18.182874 |
SID: | 2814856 |
Source Port: | 49712 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849699120412814860 01/31/24-18:02:13.547863 |
SID: | 2814860 |
Source Port: | 49699 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849707120412825564 01/31/24-18:03:10.096095 |
SID: | 2825564 |
Source Port: | 49707 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949713120412033132 01/31/24-18:04:50.445338 |
SID: | 2033132 |
Source Port: | 49713 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849711120412825563 01/31/24-18:03:45.587236 |
SID: | 2825563 |
Source Port: | 49711 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849707120412814856 01/31/24-18:02:40.497750 |
SID: | 2814856 |
Source Port: | 49707 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849710120412033132 01/31/24-18:03:12.896650 |
SID: | 2033132 |
Source Port: | 49710 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949714120412814856 01/31/24-18:05:23.258517 |
SID: | 2814856 |
Source Port: | 49714 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949715120412814856 01/31/24-18:05:55.717331 |
SID: | 2814856 |
Source Port: | 49715 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849710120412814860 01/31/24-18:03:43.043933 |
SID: | 2814860 |
Source Port: | 49710 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849711120412814860 01/31/24-18:03:57.860489 |
SID: | 2814860 |
Source Port: | 49711 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849711120412033132 01/31/24-18:03:45.382419 |
SID: | 2033132 |
Source Port: | 49711 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849710120412814856 01/31/24-18:03:13.103025 |
SID: | 2814856 |
Source Port: | 49710 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949712120412814860 01/31/24-18:04:48.199794 |
SID: | 2814860 |
Source Port: | 49712 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849699120412825564 01/31/24-18:02:13.547863 |
SID: | 2825564 |
Source Port: | 49699 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849711120412814856 01/31/24-18:03:45.587236 |
SID: | 2814856 |
Source Port: | 49711 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849699120412825563 01/31/24-18:02:08.215265 |
SID: | 2825563 |
Source Port: | 49699 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849699120412033132 01/31/24-18:02:07.907549 |
SID: | 2033132 |
Source Port: | 49699 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949713120412814860 01/31/24-18:05:18.691447 |
SID: | 2814860 |
Source Port: | 49713 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849699120412814856 01/31/24-18:02:08.215265 |
SID: | 2814856 |
Source Port: | 49699 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949712120412825563 01/31/24-18:04:18.182874 |
SID: | 2825563 |
Source Port: | 49712 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.69.115.17849707120412814860 01/31/24-18:03:10.096095 |
SID: | 2814860 |
Source Port: | 49707 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949712120412825564 01/31/24-18:04:47.577535 |
SID: | 2825564 |
Source Port: | 49712 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949714120412033132 01/31/24-18:05:23.054371 |
SID: | 2033132 |
Source Port: | 49714 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949715120412814860 01/31/24-18:05:55.916285 |
SID: | 2814860 |
Source Port: | 49715 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949714120412814860 01/31/24-18:05:51.313700 |
SID: | 2814860 |
Source Port: | 49714 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.618.197.239.10949713120412825564 01/31/24-18:05:18.691447 |
SID: | 2825564 |
Source Port: | 49713 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.63.68.171.11949715120412033132 01/31/24-18:05:55.518415 |
SID: | 2033132 |
Source Port: | 49715 |
Destination Port: | 12041 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Spreading |
---|
Source: | File created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Operating System Destruction |
---|
Source: | Process information set: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 2_2_04C90346 | |
Source: | Code function: | 2_2_04C9010E | |
Source: | Code function: | 2_2_04C900EC | |
Source: | Code function: | 2_2_04C9030B |
Source: | Binary or memory string: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 2_2_00A8BDA2 | |
Source: | Code function: | 2_2_00A8BD6B |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 2_2_010631ED |
Persistence and Installation Behavior |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Registry value created or modified: | Jump to behavior |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 0_2_0131000C |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_0131000C |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: |
Source: | Process created: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Process created: |
Source: | Process created: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 11 Replication Through Removable Media | 1 Windows Management Instrumentation | 221 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 11 Masquerading | 1 Input Capture | 111 Security Software Discovery | Remote Services | 1 Input Capture | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 12 Process Injection | 311 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 221 Registry Run Keys / Startup Folder | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 Access Token Manipulation | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 12 Process Injection | LSA Secrets | 1 Peripheral Device Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Obfuscated Files or Information | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Software Packing | DCSync | 13 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/ATRAPS.Gen | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay | ||
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay | ||
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
6.tcp.eu.ngrok.io | 3.69.115.178 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.197.239.109 | unknown | United States | 16509 | AMAZON-02US | true | |
3.69.115.178 | 6.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | true | |
3.68.171.119 | unknown | United States | 16509 | AMAZON-02US | true |
Joe Sandbox version: | 39.0.0 Ruby |
Analysis ID: | 1384274 |
Start date and time: | 2024-01-31 18:01:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | zyx3qItgQK.exerenamed because original name is a hash value |
Original Sample Name: | 1D641A341DF0631BF135F5767440DF01.exe |
Detection: | MAL |
Classification: | mal100.spre.troj.adwa.spyw.evad.winEXE@12/10@4/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: zyx3qItgQK.exe
Time | Type | Description |
---|---|---|
18:02:06 | Autostart | |
18:02:14 | Autostart | |
18:02:24 | Autostart | |
18:02:32 | Autostart | |
18:02:37 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
18.197.239.109 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.69.115.178 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.68.171.119 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
6.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, RisePro Stealer | Browse |
| ||
Get hash | malicious | Pushdo | Browse |
| ||
AMAZON-02US | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, RisePro Stealer | Browse |
| ||
Get hash | malicious | Pushdo | Browse |
| ||
AMAZON-02US | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, RisePro Stealer | Browse |
| ||
Get hash | malicious | Pushdo | Browse |
|
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\zyx3qItgQK.exe |
File Type: | |
Category: | modified |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\zyx3qItgQK.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 37888 |
Entropy (8bit): | 5.573297734149507 |
Encrypted: | false |
SSDEEP: | 384:KstKUiDtblmJEpRGyEf7JfJuQCY6iX1rAF+rMRTyN/0L+EcoinblneHQM3epzXk/:dtiHpR9Ef7JsQCFilrM+rMRa8Nuelt |
MD5: | 1D641A341DF0631BF135F5767440DF01 |
SHA1: | 2E76BE5D5A7F0BAE3657A649EB60F47C4FBDE3CF |
SHA-256: | 3FA1B0D5AB8CC2B3435718E8B625E63E651A6D3DF4D7657DC8C3859CAEB5B4E9 |
SHA-512: | 08D78D42B96734006BF0986DD666D0C5A15E2EC4C13817E82F3FE6AF55CEDE59F3685466A2B004AD765FE291B360625490C17E97FA89EF0965B09E7A448CE853 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\zyx3qItgQK.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7891fdab3e9ec8884436ba440a809c8a.exe
Download File
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 37888 |
Entropy (8bit): | 5.573297734149507 |
Encrypted: | false |
SSDEEP: | 384:KstKUiDtblmJEpRGyEf7JfJuQCY6iX1rAF+rMRTyN/0L+EcoinblneHQM3epzXk/:dtiHpR9Ef7JsQCFilrM+rMRa8Nuelt |
MD5: | 1D641A341DF0631BF135F5767440DF01 |
SHA1: | 2E76BE5D5A7F0BAE3657A649EB60F47C4FBDE3CF |
SHA-256: | 3FA1B0D5AB8CC2B3435718E8B625E63E651A6D3DF4D7657DC8C3859CAEB5B4E9 |
SHA-512: | 08D78D42B96734006BF0986DD666D0C5A15E2EC4C13817E82F3FE6AF55CEDE59F3685466A2B004AD765FE291B360625490C17E97FA89EF0965B09E7A448CE853 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7891fdab3e9ec8884436ba440a809c8a.exe:Zone.Identifier
Download File
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 50 |
Entropy (8bit): | 4.320240000427043 |
Encrypted: | false |
SSDEEP: | 3:It1KV2LKMACovK0x:e1KzxvD |
MD5: | 5B0B50BADE67C5EC92D42E971287A5D9 |
SHA1: | 90D5C99143E7A56AD6E5EE401015F8ECC093D95A |
SHA-256: | 04DDE2489D2D2E6846D42250D813AB90B5CA847D527F8F2C022E6C327DC6DB53 |
SHA-512: | C064DC3C4185A38D1CAEBD069ACB9FDBB85DFB650D6A241036E501A09BC89FD06E267BE9D400D20E6C14B4068473D1C6557962E8D82FDFD191DB7EABB6E66821 |
Malicious: | true |
Preview: |
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 37888 |
Entropy (8bit): | 5.573297734149507 |
Encrypted: | false |
SSDEEP: | 384:KstKUiDtblmJEpRGyEf7JfJuQCY6iX1rAF+rMRTyN/0L+EcoinblneHQM3epzXk/:dtiHpR9Ef7JsQCFilrM+rMRa8Nuelt |
MD5: | 1D641A341DF0631BF135F5767440DF01 |
SHA1: | 2E76BE5D5A7F0BAE3657A649EB60F47C4FBDE3CF |
SHA-256: | 3FA1B0D5AB8CC2B3435718E8B625E63E651A6D3DF4D7657DC8C3859CAEB5B4E9 |
SHA-512: | 08D78D42B96734006BF0986DD666D0C5A15E2EC4C13817E82F3FE6AF55CEDE59F3685466A2B004AD765FE291B360625490C17E97FA89EF0965B09E7A448CE853 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\netsh.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 313 |
Entropy (8bit): | 4.971939296804078 |
Encrypted: | false |
SSDEEP: | 6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha |
MD5: | 689E2126A85BF55121488295EE068FA1 |
SHA1: | 09BAAA253A49D80C18326DFBCA106551EBF22DD6 |
SHA-256: | D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25 |
SHA-512: | C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 5.573297734149507 |
TrID: |
|
File name: | zyx3qItgQK.exe |
File size: | 37'888 bytes |
MD5: | 1d641a341df0631bf135f5767440df01 |
SHA1: | 2e76be5d5a7f0bae3657a649eb60f47c4fbde3cf |
SHA256: | 3fa1b0d5ab8cc2b3435718e8b625e63e651a6d3df4d7657dc8c3859caeb5b4e9 |
SHA512: | 08d78d42b96734006bf0986dd666d0c5a15e2ec4c13817e82f3fe6af55cede59f3685466a2b004ad765fe291b360625490c17e97fa89ef0965b09e7a448ce853 |
SSDEEP: | 384:KstKUiDtblmJEpRGyEf7JfJuQCY6iX1rAF+rMRTyN/0L+EcoinblneHQM3epzXk/:dtiHpR9Ef7JsQCFilrM+rMRa8Nuelt |
TLSH: | 3D032A4D7FE18168C5FD467B05B2D41207BBE04B6E23D90ECEE564AA37636C18B50AF2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......e................................. ........@.. ....................................@................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x40abbe |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x65B41CD0 [Fri Jan 26 20:57:52 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xab70 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc000 | 0x240 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x8bc4 | 0x8c00 | 459c332f63a31fff36bf80b50c01a6e0 | False | 0.4636160714285714 | data | 5.604798648983626 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc000 | 0x240 | 0x400 | f7ce2f7b506ce16c06c85a549ef2cd98 | False | 0.3134765625 | data | 4.968771659524424 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe000 | 0xc | 0x200 | 163d66697186c0743c0da6f82247a39a | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0xc058 | 0x1e7 | XML 1.0 document, ASCII text, with CRLF line terminators | 0.5338809034907598 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.63.69.115.17849707120412033132 01/31/24-18:02:40.293747 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849711120412825564 01/31/24-18:03:57.860489 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949713120412814856 01/31/24-18:04:50.646104 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.68.171.11949714120412825563 01/31/24-18:05:23.258517 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.618.197.239.10949712120412033132 01/31/24-18:04:17.975768 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.68.171.11949714120412825564 01/31/24-18:05:51.313700 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.63.68.171.11949715120412825564 01/31/24-18:05:55.916285 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.63.69.115.17849707120412825563 01/31/24-18:02:40.497750 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849710120412825564 01/31/24-18:03:36.423392 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949712120412814856 01/31/24-18:04:18.182874 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.69.115.17849699120412814860 01/31/24-18:02:13.547863 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849707120412825564 01/31/24-18:03:10.096095 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949713120412033132 01/31/24-18:04:50.445338 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.69.115.17849711120412825563 01/31/24-18:03:45.587236 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849707120412814856 01/31/24-18:02:40.497750 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849710120412033132 01/31/24-18:03:12.896650 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.68.171.11949714120412814856 01/31/24-18:05:23.258517 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.63.68.171.11949715120412814856 01/31/24-18:05:55.717331 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.63.69.115.17849710120412814860 01/31/24-18:03:43.043933 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849711120412814860 01/31/24-18:03:57.860489 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849711120412033132 01/31/24-18:03:45.382419 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849710120412814856 01/31/24-18:03:13.103025 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949712120412814860 01/31/24-18:04:48.199794 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.69.115.17849699120412825564 01/31/24-18:02:13.547863 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849711120412814856 01/31/24-18:03:45.587236 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849699120412825563 01/31/24-18:02:08.215265 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.63.69.115.17849699120412033132 01/31/24-18:02:07.907549 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949713120412814860 01/31/24-18:05:18.691447 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.69.115.17849699120412814856 01/31/24-18:02:08.215265 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949712120412825563 01/31/24-18:04:18.182874 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.69.115.17849707120412814860 01/31/24-18:03:10.096095 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
192.168.2.618.197.239.10949712120412825564 01/31/24-18:04:47.577535 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.68.171.11949714120412033132 01/31/24-18:05:23.054371 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.63.68.171.11949715120412814860 01/31/24-18:05:55.916285 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.63.68.171.11949714120412814860 01/31/24-18:05:51.313700 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
192.168.2.618.197.239.10949713120412825564 01/31/24-18:05:18.691447 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
192.168.2.63.68.171.11949715120412033132 01/31/24-18:05:55.518415 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 31, 2024 18:02:07.601418018 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:07.805454016 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:07.805577040 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:07.907548904 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:08.215066910 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:08.215265036 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:08.419259071 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:13.547863007 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:13.752088070 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:28.900213003 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:28.900429010 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:38.062952995 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:38.063191891 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:40.079741001 CET | 49699 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:40.081720114 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:40.283947945 CET | 12041 | 49699 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:40.285665989 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:40.285768032 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:40.293746948 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:40.497543097 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:40.497750044 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:40.704612017 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:02:45.985716105 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:02:46.189863920 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:01.408046961 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:01.408262968 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:04.016621113 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:04.220837116 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:05.422851086 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:05.627454996 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:09.891772985 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:10.095874071 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:10.096095085 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:10.300097942 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:10.553540945 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:10.553673983 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:12.563251972 CET | 49707 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:12.686687946 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:12.767330885 CET | 12041 | 49707 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:12.893023014 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:12.893107891 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:12.896650076 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:13.102838993 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:13.103024960 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:13.309340000 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:13.309528112 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:13.515840054 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:13.515919924 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:13.722246885 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:13.724965096 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:13.931380033 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:13.933017015 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:14.139467001 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:14.140997887 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:14.347431898 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:14.347940922 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:14.554300070 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:14.554886103 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:14.761329889 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:14.761437893 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:14.967714071 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:14.967852116 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:15.174918890 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:15.175065994 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:15.381402969 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:15.381515980 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:15.587723017 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:15.587874889 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:15.794327021 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:15.794482946 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:16.000735044 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:16.000849009 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:16.207130909 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:16.316586018 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:16.522900105 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:16.523035049 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:16.730045080 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:16.730274916 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:16.936695099 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:18.462435007 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:18.668821096 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:18.668972015 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:18.875329018 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:18.875544071 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:19.082005978 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:19.082247972 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:19.288566113 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:19.288774014 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:19.495158911 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:19.495253086 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:19.701575994 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:19.701700926 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:19.907911062 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:19.908051968 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:20.114242077 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:20.114315987 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:20.320647001 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:20.320739031 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:20.527123928 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:20.527244091 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:20.733539104 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:20.733762980 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:20.939939022 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:20.940077066 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:21.146306038 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:21.146503925 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:21.352988958 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:21.353179932 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:21.559432983 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:21.559568882 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:21.766057968 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:21.766273975 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:21.972605944 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:21.972764969 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:22.179260969 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:22.179394960 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:22.385607958 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:22.385739088 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:22.592129946 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:22.592344999 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:22.798768044 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:22.798854113 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:23.005201101 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:23.005403996 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:23.212618113 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:23.212690115 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:23.419682980 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:23.419892073 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:23.629147053 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:23.629268885 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:23.837130070 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:23.837222099 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:24.043637037 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:24.043847084 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:24.250507116 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:24.250653982 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:24.457289934 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:24.457396984 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:24.663806915 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:24.663904905 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:24.870610952 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:24.870702982 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:25.077100039 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:25.077184916 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:25.283478022 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:25.283571005 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:25.492559910 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:25.492657900 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:25.700622082 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:25.700737953 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:25.907181978 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:25.907291889 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:26.115231037 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:26.115314960 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:26.321651936 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:26.321763992 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:26.528301001 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:26.528404951 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:26.734882116 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:26.735022068 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:26.944813013 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:26.944966078 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:27.151447058 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:27.151541948 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:27.357853889 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:27.357934952 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:27.564412117 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:27.564667940 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:27.771356106 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:27.771533966 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:27.981117010 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:27.981219053 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:28.187783003 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:28.187941074 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:28.394503117 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:28.394599915 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:28.601280928 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:28.601389885 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:28.807903051 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:28.807991028 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:29.014520884 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:29.014626980 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:29.220937014 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:29.221079111 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:29.427647114 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:29.428050995 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:29.634608030 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:29.634783030 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:29.841295958 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:29.841414928 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:30.047949076 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:30.048135042 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:30.254626036 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:30.254765987 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:30.461827993 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:30.461968899 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:30.668775082 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:30.668912888 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:30.876468897 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:30.876558065 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:31.083039999 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:31.083163023 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:31.289518118 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:31.289648056 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:31.496117115 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:31.496198893 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:31.702677011 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:31.702816010 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:31.909219980 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:31.909388065 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:32.115822077 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:32.115915060 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:32.322360039 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:32.322534084 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:32.528887033 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:32.528995991 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:32.735898018 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:32.735979080 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:32.942154884 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:32.942230940 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:33.152281046 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:33.152393103 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:33.369033098 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:33.369131088 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:33.576632023 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:33.576771021 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:33.783014059 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:33.783226013 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:33.989511967 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:34.033833981 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:34.240119934 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:34.240199089 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:34.446418047 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:34.576956034 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:34.783373117 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:34.783528090 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:34.989964008 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:36.423392057 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:36.629802942 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:36.629914045 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:36.836122036 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:36.836333036 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:37.042574883 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:37.042635918 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:37.248862028 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:37.248934031 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:37.455301046 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:37.455403090 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:37.661576986 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:37.661690950 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:37.867861032 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:37.867933035 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:38.074071884 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:38.076492071 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:38.282614946 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:38.284929991 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:38.491097927 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:38.491163969 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:38.697371960 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:38.697443008 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:38.903558016 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:38.903683901 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:39.109802008 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:39.109880924 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:39.316071987 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:39.316173077 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:39.522322893 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:39.522440910 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:39.728607893 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:39.728708982 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:39.934999943 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:39.935103893 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:40.141377926 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:40.141499996 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:40.347789049 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:40.347893000 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:40.557548046 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:40.557820082 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:40.768435001 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:40.768515110 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:40.974749088 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:40.974951982 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:41.181274891 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:41.181428909 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:41.389956951 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:41.390049934 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:41.597595930 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:41.597753048 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:41.804147005 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:41.804239035 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:42.010566950 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:42.010660887 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:42.217143059 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:42.217540026 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:42.423923016 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:42.423993111 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:42.630192995 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:42.630274057 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:42.836669922 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:42.836797953 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:43.043826103 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:43.043932915 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:43.161653042 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:43.161719084 CET | 49710 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:43.250216961 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:43.367850065 CET | 12041 | 49710 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:45.174611092 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:45.379576921 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:45.379733086 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:45.382419109 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:45.587100983 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:45.587235928 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:45.791943073 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:49.704380035 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:49.909182072 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:03:57.860488892 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:03:58.068228006 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:04:13.088044882 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:04:13.088115931 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:04:15.635255098 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:04:15.635339022 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:04:17.641540051 CET | 49711 | 12041 | 192.168.2.6 | 3.69.115.178 |
Jan 31, 2024 18:04:17.763516903 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:17.846463919 CET | 12041 | 49711 | 3.69.115.178 | 192.168.2.6 |
Jan 31, 2024 18:04:17.970702887 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:17.970813990 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:17.975768089 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:18.182794094 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:18.182873964 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:18.390026093 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:21.548099041 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:21.755295038 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:36.963793993 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:36.964099884 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:39.454431057 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:39.661676884 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:41.110712051 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:41.317789078 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:45.610511065 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:45.817495108 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:45.876240969 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:46.083256960 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:46.844952106 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:47.052134991 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:47.052253962 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:47.259253025 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:47.577534914 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:47.784687996 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:47.784951925 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:47.992389917 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:47.992615938 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:48.199696064 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:48.199794054 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:48.230387926 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:48.230470896 CET | 49712 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:48.407084942 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:48.437495947 CET | 12041 | 49712 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:50.238300085 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:50.442935944 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:50.443037033 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:50.445338011 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:50.646011114 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:50.646104097 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:50.846951008 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:50.847023010 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:51.047754049 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:51.047847986 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:51.248553038 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:51.248641014 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:51.449410915 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:51.449518919 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:51.650374889 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:51.650475979 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:51.851134062 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:51.851334095 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:52.052052975 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:52.052244902 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:52.252867937 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:52.253115892 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:52.453947067 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:52.454019070 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:52.654653072 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:52.654793978 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:52.855489016 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:52.855592966 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:53.056530952 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:53.056776047 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:53.257496119 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:04:53.257585049 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:04:53.458517075 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:05:08.706800938 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:05:08.706971884 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:05:10.563657999 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:05:10.764460087 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:05:18.691447020 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:05:18.892263889 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:05:20.706190109 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:05:20.706271887 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:05:22.719924927 CET | 49713 | 12041 | 192.168.2.6 | 18.197.239.109 |
Jan 31, 2024 18:05:22.847780943 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:22.920859098 CET | 12041 | 49713 | 18.197.239.109 | 192.168.2.6 |
Jan 31, 2024 18:05:23.051953077 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:23.052150965 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:23.054371119 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:23.258429050 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:23.258517027 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:23.462826014 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:26.767024994 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:26.971398115 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:42.022066116 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:42.022135973 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:49.891871929 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:50.096159935 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:51.313699961 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:51.517978907 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:53.311817884 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:53.311953068 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:55.313688993 CET | 49714 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:55.316647053 CET | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:55.515499115 CET | 12041 | 49715 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:55.515594959 CET | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:55.517741919 CET | 12041 | 49714 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:55.518414974 CET | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:55.717165947 CET | 12041 | 49715 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:55.717330933 CET | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:55.916188002 CET | 12041 | 49715 | 3.68.171.119 | 192.168.2.6 |
Jan 31, 2024 18:05:55.916285038 CET | 49715 | 12041 | 192.168.2.6 | 3.68.171.119 |
Jan 31, 2024 18:05:56.115215063 CET | 12041 | 49715 | 3.68.171.119 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 31, 2024 18:02:07.478013039 CET | 54871 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 31, 2024 18:02:07.598102093 CET | 53 | 54871 | 1.1.1.1 | 192.168.2.6 |
Jan 31, 2024 18:03:12.565818071 CET | 49942 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 31, 2024 18:03:12.685225010 CET | 53 | 49942 | 1.1.1.1 | 192.168.2.6 |
Jan 31, 2024 18:04:17.642935991 CET | 51782 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 31, 2024 18:04:17.762331009 CET | 53 | 51782 | 1.1.1.1 | 192.168.2.6 |
Jan 31, 2024 18:05:22.726516962 CET | 62376 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 31, 2024 18:05:22.845422983 CET | 53 | 62376 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 31, 2024 18:02:07.478013039 CET | 192.168.2.6 | 1.1.1.1 | 0x8d76 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 31, 2024 18:03:12.565818071 CET | 192.168.2.6 | 1.1.1.1 | 0x62a2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 31, 2024 18:04:17.642935991 CET | 192.168.2.6 | 1.1.1.1 | 0x37c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 31, 2024 18:05:22.726516962 CET | 192.168.2.6 | 1.1.1.1 | 0x7694 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 31, 2024 18:02:07.598102093 CET | 1.1.1.1 | 192.168.2.6 | 0x8d76 | No error (0) | 3.69.115.178 | A (IP address) | IN (0x0001) | false | ||
Jan 31, 2024 18:03:12.685225010 CET | 1.1.1.1 | 192.168.2.6 | 0x62a2 | No error (0) | 3.69.115.178 | A (IP address) | IN (0x0001) | false | ||
Jan 31, 2024 18:04:17.762331009 CET | 1.1.1.1 | 192.168.2.6 | 0x37c3 | No error (0) | 18.197.239.109 | A (IP address) | IN (0x0001) | false | ||
Jan 31, 2024 18:05:22.845422983 CET | 1.1.1.1 | 192.168.2.6 | 0x7694 | No error (0) | 3.68.171.119 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 18:01:50 |
Start date: | 31/01/2024 |
Path: | C:\Users\user\Desktop\zyx3qItgQK.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x850000 |
File size: | 37'888 bytes |
MD5 hash: | 1D641A341DF0631BF135F5767440DF01 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 18:01:56 |
Start date: | 31/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x490000 |
File size: | 37'888 bytes |
MD5 hash: | 1D641A341DF0631BF135F5767440DF01 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 18:02:03 |
Start date: | 31/01/2024 |
Path: | C:\Windows\SysWOW64\netsh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa60000 |
File size: | 82'432 bytes |
MD5 hash: | 4E89A1A088BE715D6C946E55AB07C7DF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 4 |
Start time: | 18:02:03 |
Start date: | 31/01/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 18:02:03 |
Start date: | 31/01/2024 |
Path: | C:\Windows\SysWOW64\taskkill.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfe0000 |
File size: | 74'240 bytes |
MD5 hash: | CA313FD7E6C2A778FFD21CFB5C1C56CD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 6 |
Start time: | 18:02:03 |
Start date: | 31/01/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 18:02:15 |
Start date: | 31/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb60000 |
File size: | 37'888 bytes |
MD5 hash: | 1D641A341DF0631BF135F5767440DF01 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 18:02:24 |
Start date: | 31/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa60000 |
File size: | 37'888 bytes |
MD5 hash: | 1D641A341DF0631BF135F5767440DF01 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 13 |
Start time: | 18:02:32 |
Start date: | 31/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 37'888 bytes |
MD5 hash: | 1D641A341DF0631BF135F5767440DF01 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 11% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 37 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 05010310 Relevance: 3.9, Strings: 3, Instructions: 188COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050103BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010958 Relevance: 3.0, Strings: 2, Instructions: 483COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2AA07 Relevance: 1.6, APIs: 1, Instructions: 72fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2A2D2 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2AC24 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2A8A4 Relevance: 1.6, APIs: 1, Instructions: 59COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2AA3E Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2A8C6 Relevance: 1.5, APIs: 1, Instructions: 48COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2AC46 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E2A2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0501088A Relevance: 1.3, Strings: 1, Instructions: 38COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010080 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010007 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 013105E0 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01310606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E223F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00E223BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0131000C Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 20.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 5.4% |
Total number of Nodes: | 260 |
Total number of Limit Nodes: | 11 |
Graph
Function 00A8BD6B Relevance: 1.6, APIs: 1, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C9030B Relevance: 1.6, APIs: 1, Instructions: 64nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8BDA2 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C900EC Relevance: 1.6, APIs: 1, Instructions: 50nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C90346 Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C9010E Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060310 Relevance: 7.7, Strings: 6, Instructions: 187COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010603BD Relevance: 7.6, Strings: 6, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061618 Relevance: 4.1, Strings: 3, Instructions: 335COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061689 Relevance: 4.0, Strings: 3, Instructions: 280COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010616A7 Relevance: 4.0, Strings: 3, Instructions: 277COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010616BA Relevance: 4.0, Strings: 3, Instructions: 276COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061F47 Relevance: 3.1, Strings: 2, Instructions: 613COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060958 Relevance: 3.0, Strings: 2, Instructions: 481COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060509 Relevance: 2.6, Strings: 2, Instructions: 50COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AC19 Relevance: 1.6, APIs: 1, Instructions: 96fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C9191C Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91BAA Relevance: 1.6, APIs: 1, Instructions: 92COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91814 Relevance: 1.6, APIs: 1, Instructions: 91timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91208 Relevance: 1.6, APIs: 1, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C9193E Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C92E0D Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AD30 Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B51A Relevance: 1.6, APIs: 1, Instructions: 78COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C90DE2 Relevance: 1.6, APIs: 1, Instructions: 77networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C913BE Relevance: 1.6, APIs: 1, Instructions: 77fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C90006 Relevance: 1.6, APIs: 1, Instructions: 77COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010623E0 Relevance: 1.6, Strings: 1, Instructions: 327COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C9122E Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C9023C Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AC5A Relevance: 1.6, APIs: 1, Instructions: 76fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C931E3 Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C930FF Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B0D2 Relevance: 1.6, APIs: 1, Instructions: 73fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91655 Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8BBF3 Relevance: 1.6, APIs: 1, Instructions: 70COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C92D47 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8BE38 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C913DE Relevance: 1.6, APIs: 1, Instructions: 67fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91AEE Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C90E02 Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91E86 Relevance: 1.6, APIs: 1, Instructions: 66libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B19B Relevance: 1.6, APIs: 1, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91852 Relevance: 1.6, APIs: 1, Instructions: 64timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B330 Relevance: 1.6, APIs: 1, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C93206 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C93122 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C903C0 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C90032 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B0F2 Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C92D6A Relevance: 1.6, APIs: 1, Instructions: 58COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91682 Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AA81 Relevance: 1.6, APIs: 1, Instructions: 57comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91EA6 Relevance: 1.6, APIs: 1, Instructions: 56libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A2D2 Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C92E46 Relevance: 1.6, APIs: 1, Instructions: 55COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A078 Relevance: 1.6, APIs: 1, Instructions: 54networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8BC22 Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B352 Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B48C Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AD72 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A9E4 Relevance: 1.6, APIs: 1, Instructions: 51COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C90282 Relevance: 1.5, APIs: 1, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91B1E Relevance: 1.5, APIs: 1, Instructions: 49networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B1D6 Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C91C1A Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04C903EE Relevance: 1.5, APIs: 1, Instructions: 45COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8BE72 Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A09A Relevance: 1.5, APIs: 1, Instructions: 42networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AA06 Relevance: 1.5, APIs: 1, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B4AE Relevance: 1.5, APIs: 1, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8AAAE Relevance: 1.5, APIs: 1, Instructions: 39comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8B572 Relevance: 1.5, APIs: 1, Instructions: 38COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A8A2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061200 Relevance: 1.5, Strings: 1, Instructions: 283COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010624E5 Relevance: 1.5, Strings: 1, Instructions: 228COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062535 Relevance: 1.5, Strings: 1, Instructions: 217COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062577 Relevance: 1.5, Strings: 1, Instructions: 210COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060B03 Relevance: 1.4, Strings: 1, Instructions: 194COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010625EB Relevance: 1.4, Strings: 1, Instructions: 189COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010626CD Relevance: 1.4, Strings: 1, Instructions: 142COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010627E8 Relevance: 1.3, Strings: 1, Instructions: 89COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01063118 Relevance: 1.3, Strings: 1, Instructions: 71COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060E55 Relevance: 1.3, Strings: 1, Instructions: 63COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062E49 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060014 Relevance: .2, Instructions: 177COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010605C5 Relevance: .2, Instructions: 177COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010611D0 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060BA8 Relevance: .2, Instructions: 153COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060634 Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010615D0 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060C22 Relevance: .1, Instructions: 125COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061BF0 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061BE0 Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062C98 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060C8D Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01070DD3 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060D40 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060773 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05492400 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01070E0C Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062B08 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062BB0 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061D61 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010629F9 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BAB5A0 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061D70 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010705DF Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060889 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01060D98 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01061EB8 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01070EC8 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01070606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0549246B Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05491D17 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BAB5EF Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A823F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A823BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01062C59 Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 17.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 12 |
Total number of Limit Nodes: | 0 |
Graph
Callgraph
Function 05330310 Relevance: 3.9, Strings: 3, Instructions: 193COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 053303BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05330080 Relevance: .1, Instructions: 128COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05330006 Relevance: .0, Instructions: 44COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015605E1 Relevance: .0, Instructions: 42COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01560606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 014723F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 014723BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 17.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 05220310 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 052203BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0113A710 Relevance: 1.6, APIs: 1, Instructions: 70COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0113A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05220080 Relevance: .1, Instructions: 128COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01740648 Relevance: .0, Instructions: 48COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 017405E0 Relevance: .0, Instructions: 43COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05220006 Relevance: .0, Instructions: 42COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01740606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011323F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011323BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 17.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 00B00310 Relevance: 7.7, Strings: 6, Instructions: 194COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B003BD Relevance: 7.6, Strings: 6, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0062A710 Relevance: 1.6, APIs: 1, Instructions: 70COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0062A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B00080 Relevance: .1, Instructions: 130COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B00006 Relevance: .0, Instructions: 49COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A205E0 Relevance: .0, Instructions: 44COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A20606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006223F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006223BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |