Windows
Analysis Report
kuEfaZxkiY.exe
Overview
General Information
Sample name: | kuEfaZxkiY.exerenamed because original name is a hash value |
Original sample name: | 117EEF8A227E6CE3646718D0ED6FB7B1.exe |
Analysis ID: | 1393953 |
MD5: | 117eef8a227e6ce3646718d0ed6fb7b1 |
SHA1: | db6e21bf637604aa0be4f73142a1b7447cc83553 |
SHA256: | 80488bf5f30ea2398ff207b9045a0e230aff2d052ea56156a0e96b57784dc0e5 |
Tags: | exeRedLineStealer |
Infos: | |
Detection
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- kuEfaZxkiY.exe (PID: 7080 cmdline:
C:\Users\u ser\Deskto p\kuEfaZxk iY.exe MD5: 117EEF8A227E6CE3646718D0ED6FB7B1) - conhost.exe (PID: 7160 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Windows_Trojan_RedLineStealer_f54632eb | unknown | unknown |
| |
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Windows_Trojan_RedLineStealer_f54632eb | unknown | unknown |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Windows_Trojan_RedLineStealer_f54632eb | unknown | unknown |
| |
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
|
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Networking |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00F9E7B0 | |
Source: | Code function: | 0_2_00F9DC90 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 2 Virtualization/Sandbox Evasion | OS Credential Dumping | 1 Security Software Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Disable or Modify Tools | LSASS Memory | 2 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 11 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 12 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Timestomp | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
87% | ReversingLabs | ByteCode-MSIL.Infostealer.RedLine | ||
78% | Virustotal | Browse | ||
100% | Avira | HEUR/AGEN.1305500 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
9% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
2% | Virustotal | Browse | ||
2% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
2% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
9% | Virustotal | Browse | ||
2% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
2% | Virustotal | Browse | ||
9% | Virustotal | Browse | ||
9% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
9% | Virustotal | Browse | ||
2% | Virustotal | Browse | ||
2% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
0.tcp.in.ngrok.io | 3.6.115.182 | true | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.6.115.182 | 0.tcp.in.ngrok.io | United States | 16509 | AMAZON-02US | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1393953 |
Start date and time: | 2024-02-17 20:41:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | kuEfaZxkiY.exerenamed because original name is a hash value |
Original Sample Name: | 117EEF8A227E6CE3646718D0ED6FB7B1.exe |
Detection: | MAL |
Classification: | mal96.troj.winEXE@2/0@1/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryValueKey calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3.6.115.182 | Get hash | malicious | RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
0.tcp.in.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Nanocore | Browse |
| ||
Get hash | malicious | njRat | Browse |
| ||
Get hash | malicious | njRat | Browse |
| ||
Get hash | malicious | njRat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
File type: | |
Entropy (8bit): | 5.960239123976663 |
TrID: |
|
File name: | kuEfaZxkiY.exe |
File size: | 97'792 bytes |
MD5: | 117eef8a227e6ce3646718d0ed6fb7b1 |
SHA1: | db6e21bf637604aa0be4f73142a1b7447cc83553 |
SHA256: | 80488bf5f30ea2398ff207b9045a0e230aff2d052ea56156a0e96b57784dc0e5 |
SHA512: | b889b1b965251c74776d3f8981f042f6364157d3c3049e59ad3fbd12dc5d95b938db37870b2bb0de6781e7ee48c0a6cf80318b31b60b6df2be96241a34d478a1 |
SSDEEP: | 1536:Fqsgaq+A/lbG6jejoigIP43Ywzi0Zb78ivombfexv0ujXyyed2z3teulgS6pQl:DfZeYP+zi0ZbYe1g0ujyzdfQ |
TLSH: | B0A35D2067AC9F19EAFD1B74B4B2012043F1E08A9091FB4B4DC154E71FA7B865957EF2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....................0..t..........>.... ........@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x41933e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0xF00CA9A2 [Wed Aug 14 23:34:58 2097 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x192e8 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x1a000 | 0x4de | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x1c000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x17344 | 0x17400 | 38e22ac8e4d3010d0b39c201a2c0ce18 | False | 0.4487567204301075 | data | 6.015291136298434 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x1a000 | 0x4de | 0x600 | e3145af1e7dfa1e41fe7799ae002b612 | False | 0.3756510416666667 | data | 3.723940100220831 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x1c000 | 0xc | 0x200 | 89ebbf373068a00e5c68d2ac72a26374 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x1a0a0 | 0x254 | data | 0.4597315436241611 | ||
RT_MANIFEST | 0x1a2f4 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 17, 2024 20:42:01.792113066 CET | 49729 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.070998907 CET | 17383 | 49729 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.071491003 CET | 49729 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.091609955 CET | 49729 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.354696989 CET | 17383 | 49729 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.355135918 CET | 49729 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.366194010 CET | 49729 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.367120028 CET | 49730 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.370184898 CET | 17383 | 49729 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.633975029 CET | 17383 | 49729 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.644026995 CET | 17383 | 49730 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.644282103 CET | 49730 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.644577026 CET | 49730 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.644800901 CET | 17383 | 49729 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.921449900 CET | 17383 | 49730 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.925757885 CET | 17383 | 49730 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:02.925976038 CET | 49730 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:02.926309109 CET | 49730 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:03.204368114 CET | 17383 | 49730 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:07.951719046 CET | 49731 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:08.228625059 CET | 17383 | 49731 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:08.228920937 CET | 49731 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:08.229341984 CET | 49731 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:08.507121086 CET | 17383 | 49731 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:08.507185936 CET | 17383 | 49731 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:08.507227898 CET | 17383 | 49731 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:08.508773088 CET | 49732 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:08.786103010 CET | 17383 | 49732 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:08.786590099 CET | 49732 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:08.787210941 CET | 49732 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:09.063839912 CET | 17383 | 49732 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:09.063874006 CET | 17383 | 49732 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:09.063890934 CET | 17383 | 49732 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:09.064066887 CET | 49732 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:09.065391064 CET | 49732 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:09.345135927 CET | 17383 | 49732 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:09.346069098 CET | 17383 | 49732 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:14.076436996 CET | 49733 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:14.347162962 CET | 17383 | 49733 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:14.347407103 CET | 49733 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:14.347752094 CET | 49733 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:14.618899107 CET | 17383 | 49733 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:14.618962049 CET | 17383 | 49733 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:14.618987083 CET | 17383 | 49733 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:14.620450974 CET | 49734 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:14.897140026 CET | 17383 | 49734 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:14.897476912 CET | 49734 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:14.897855997 CET | 49734 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:15.174422026 CET | 17383 | 49734 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:15.174482107 CET | 17383 | 49734 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:15.174520016 CET | 17383 | 49734 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:15.174587965 CET | 49734 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:15.174747944 CET | 49734 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:15.451549053 CET | 17383 | 49734 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:15.451616049 CET | 17383 | 49734 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:20.185735941 CET | 49738 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:20.462649107 CET | 17383 | 49738 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:20.462809086 CET | 49738 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:20.463119030 CET | 49738 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:20.739754915 CET | 17383 | 49738 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:20.739814043 CET | 17383 | 49738 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:20.739851952 CET | 17383 | 49738 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:20.741075993 CET | 49740 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:21.012978077 CET | 17383 | 49740 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:21.013071060 CET | 49740 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:21.013288975 CET | 49740 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:21.286633968 CET | 17383 | 49740 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:21.286698103 CET | 17383 | 49740 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:21.286736965 CET | 17383 | 49740 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:26.310903072 CET | 49742 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:26.587691069 CET | 17383 | 49742 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:26.587932110 CET | 49742 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:26.588409901 CET | 49742 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:26.865295887 CET | 17383 | 49742 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:26.865360975 CET | 17383 | 49742 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:26.865381002 CET | 17383 | 49742 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:26.865678072 CET | 49742 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:26.865905046 CET | 49742 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:27.144587994 CET | 17383 | 49742 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:27.144650936 CET | 17383 | 49742 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:31.872966051 CET | 49743 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:32.146126986 CET | 17383 | 49743 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:32.146363974 CET | 49743 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:32.146611929 CET | 49743 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:32.419807911 CET | 17383 | 49743 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:32.419871092 CET | 17383 | 49743 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:32.419908047 CET | 17383 | 49743 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:32.420025110 CET | 49743 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:32.420243025 CET | 49743 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:32.692466974 CET | 17383 | 49743 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:32.692518950 CET | 17383 | 49743 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:37.435472965 CET | 49744 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:37.715094090 CET | 17383 | 49744 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:37.715399981 CET | 49744 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:37.716052055 CET | 49744 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:37.994910002 CET | 17383 | 49744 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:37.994970083 CET | 17383 | 49744 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:37.994997978 CET | 17383 | 49744 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:37.997251987 CET | 49745 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:38.276055098 CET | 17383 | 49745 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:38.276313066 CET | 49745 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:38.276479006 CET | 49745 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:38.554795027 CET | 17383 | 49745 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:38.554833889 CET | 17383 | 49745 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:38.554867983 CET | 17383 | 49745 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:43.562434912 CET | 49746 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:43.835509062 CET | 17383 | 49746 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:43.836189985 CET | 49746 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:43.836918116 CET | 49746 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:44.109375954 CET | 17383 | 49746 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:44.109451056 CET | 17383 | 49746 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:44.109539986 CET | 17383 | 49746 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:44.109817028 CET | 49746 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:44.109940052 CET | 49746 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:44.382559061 CET | 17383 | 49746 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:44.382622957 CET | 17383 | 49746 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:49.123548031 CET | 49747 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:49.398596048 CET | 17383 | 49747 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:49.399146080 CET | 49747 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:49.401427984 CET | 49747 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:49.674555063 CET | 17383 | 49747 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:49.674624920 CET | 17383 | 49747 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:49.674864054 CET | 49747 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:49.675272942 CET | 49747 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:49.676204920 CET | 17383 | 49747 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:49.949655056 CET | 17383 | 49747 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:49.949717045 CET | 17383 | 49747 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:54.686002016 CET | 49748 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:54.958385944 CET | 17383 | 49748 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:54.958889961 CET | 49748 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:54.959295988 CET | 49748 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:55.231556892 CET | 17383 | 49748 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.231612921 CET | 17383 | 49748 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.231625080 CET | 17383 | 49748 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.233160973 CET | 49749 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:55.506181002 CET | 17383 | 49749 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.506422997 CET | 49749 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:55.506906986 CET | 49749 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:55.780055046 CET | 17383 | 49749 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.780111074 CET | 17383 | 49749 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.780138016 CET | 17383 | 49749 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:55.780400038 CET | 49749 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:55.780726910 CET | 49749 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:42:56.053250074 CET | 17383 | 49749 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:42:56.053297997 CET | 17383 | 49749 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:00.794926882 CET | 49751 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:01.065777063 CET | 17383 | 49751 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.065980911 CET | 49751 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:01.066286087 CET | 49751 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:01.339160919 CET | 17383 | 49751 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.339219093 CET | 17383 | 49751 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.339241982 CET | 17383 | 49751 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.340784073 CET | 49752 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:01.614892960 CET | 17383 | 49752 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.615166903 CET | 49752 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:01.615818977 CET | 49752 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:01.890714884 CET | 17383 | 49752 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.893192053 CET | 17383 | 49752 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:01.893249989 CET | 17383 | 49752 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:06.935445070 CET | 49753 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:07.214459896 CET | 17383 | 49753 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:07.214793921 CET | 49753 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:07.494191885 CET | 17383 | 49753 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:07.494225025 CET | 17383 | 49753 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:07.494509935 CET | 49753 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:08.468148947 CET | 49753 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:08.468492031 CET | 49753 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:08.748471975 CET | 17383 | 49753 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:08.748501062 CET | 17383 | 49753 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:13.484968901 CET | 49754 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:13.755852938 CET | 17383 | 49754 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:13.756177902 CET | 49754 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:13.756833076 CET | 49754 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:14.027251005 CET | 17383 | 49754 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:14.027317047 CET | 17383 | 49754 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:14.027431965 CET | 49754 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:14.027812958 CET | 17383 | 49754 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:14.028069019 CET | 49754 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:14.298269033 CET | 17383 | 49754 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:14.299401999 CET | 17383 | 49754 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:19.047694921 CET | 49755 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:19.328527927 CET | 17383 | 49755 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:19.328808069 CET | 49755 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:19.329188108 CET | 49755 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:19.610318899 CET | 17383 | 49755 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:19.610388994 CET | 17383 | 49755 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:19.610431910 CET | 17383 | 49755 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:19.612095118 CET | 49756 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:19.890917063 CET | 17383 | 49756 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:19.891068935 CET | 49756 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:19.891447067 CET | 49756 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:20.171693087 CET | 17383 | 49756 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:20.171758890 CET | 17383 | 49756 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:20.171798944 CET | 17383 | 49756 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:20.171956062 CET | 49756 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:20.172702074 CET | 49756 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:20.450563908 CET | 17383 | 49756 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:20.450958014 CET | 17383 | 49756 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:25.185410976 CET | 49757 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:25.458693981 CET | 17383 | 49757 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:25.458925009 CET | 49757 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:25.459287882 CET | 49757 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:25.731739044 CET | 17383 | 49757 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:25.734400988 CET | 17383 | 49757 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:25.734436989 CET | 17383 | 49757 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:25.735761881 CET | 49758 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:26.006771088 CET | 17383 | 49758 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:26.007006884 CET | 49758 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:26.007471085 CET | 49758 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:26.278208017 CET | 17383 | 49758 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:26.278904915 CET | 17383 | 49758 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:26.278933048 CET | 17383 | 49758 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:31.296818018 CET | 49759 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:31.574023008 CET | 17383 | 49759 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:31.574271917 CET | 49759 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:31.574500084 CET | 49759 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:31.851898909 CET | 17383 | 49759 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:31.851927996 CET | 17383 | 49759 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:31.851941109 CET | 17383 | 49759 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:31.853226900 CET | 49760 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:32.125861883 CET | 17383 | 49760 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:32.126019955 CET | 49760 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:32.126351118 CET | 49760 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:32.400147915 CET | 17383 | 49760 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:32.400167942 CET | 17383 | 49760 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:32.400180101 CET | 17383 | 49760 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:32.400357008 CET | 49760 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:32.400504112 CET | 49760 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:32.672883987 CET | 17383 | 49760 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:32.672900915 CET | 17383 | 49760 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:37.404107094 CET | 49761 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:37.680509090 CET | 17383 | 49761 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:37.680723906 CET | 49761 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:37.681013107 CET | 49761 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:37.958142996 CET | 17383 | 49761 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:37.958267927 CET | 17383 | 49761 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:37.958287954 CET | 17383 | 49761 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:37.959394932 CET | 49762 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:38.235636950 CET | 17383 | 49762 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:38.235759974 CET | 49762 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:38.236052036 CET | 49762 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:38.512255907 CET | 17383 | 49762 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:38.512295008 CET | 17383 | 49762 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:38.512330055 CET | 17383 | 49762 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:43.529036999 CET | 49763 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:43.801767111 CET | 17383 | 49763 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:43.801990986 CET | 49763 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:43.802356005 CET | 49763 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:44.074451923 CET | 17383 | 49763 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:44.074481964 CET | 17383 | 49763 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:44.074532032 CET | 17383 | 49763 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:44.074734926 CET | 49763 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:44.075125933 CET | 49763 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:44.347404003 CET | 17383 | 49763 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:44.347433090 CET | 17383 | 49763 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:49.093497038 CET | 49764 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:49.365957022 CET | 17383 | 49764 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:49.366102934 CET | 49764 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:49.366439104 CET | 49764 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:49.638921022 CET | 17383 | 49764 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:49.639648914 CET | 17383 | 49764 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:49.639691114 CET | 17383 | 49764 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:49.641046047 CET | 49765 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:49.917193890 CET | 17383 | 49765 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:49.917290926 CET | 49765 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:49.917583942 CET | 49765 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:50.193734884 CET | 17383 | 49765 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:50.193753958 CET | 17383 | 49765 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:50.193768978 CET | 17383 | 49765 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:50.193922997 CET | 49765 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:50.194259882 CET | 49765 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:50.470133066 CET | 17383 | 49765 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:50.470490932 CET | 17383 | 49765 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:55.201044083 CET | 49766 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:55.475099087 CET | 17383 | 49766 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:55.475343943 CET | 49766 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:55.475730896 CET | 49766 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:55.749507904 CET | 17383 | 49766 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:55.749536037 CET | 17383 | 49766 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:55.749552965 CET | 17383 | 49766 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:55.750691891 CET | 49767 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:56.023344994 CET | 17383 | 49767 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:56.023469925 CET | 49767 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:56.023765087 CET | 49767 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:43:56.296001911 CET | 17383 | 49767 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:56.296030998 CET | 17383 | 49767 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:43:56.296050072 CET | 17383 | 49767 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:44:01.311908960 CET | 49768 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:44:01.582617998 CET | 17383 | 49768 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:44:01.582786083 CET | 49768 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:44:01.583507061 CET | 49768 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:44:01.853809118 CET | 17383 | 49768 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:44:01.853853941 CET | 17383 | 49768 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:44:01.853914022 CET | 49768 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:44:01.854099035 CET | 17383 | 49768 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:44:01.854218960 CET | 49768 | 17383 | 192.168.2.4 | 3.6.115.182 |
Feb 17, 2024 20:44:02.124614000 CET | 17383 | 49768 | 3.6.115.182 | 192.168.2.4 |
Feb 17, 2024 20:44:02.124789000 CET | 17383 | 49768 | 3.6.115.182 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Feb 17, 2024 20:42:01.658457994 CET | 49739 | 53 | 192.168.2.4 | 1.1.1.1 |
Feb 17, 2024 20:42:01.751817942 CET | 53 | 49739 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Feb 17, 2024 20:42:01.658457994 CET | 192.168.2.4 | 1.1.1.1 | 0x991f | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Feb 17, 2024 20:42:01.751817942 CET | 1.1.1.1 | 192.168.2.4 | 0x991f | No error (0) | 3.6.115.182 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49729 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:02.091609955 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49730 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:02.644577026 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49731 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:08.229341984 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49732 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:08.787210941 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49733 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:14.347752094 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49734 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:14.897855997 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49738 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:20.463119030 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49740 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:21.013288975 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49742 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:26.588409901 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49743 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:32.146611929 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49744 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:37.716052055 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49745 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:38.276479006 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49746 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:43.836918116 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49747 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:49.401427984 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49748 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:54.959295988 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49749 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:42:55.506906986 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49751 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:01.066286087 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49752 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:01.615818977 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49753 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:08.468148947 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49754 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:13.756833076 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49755 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:19.329188108 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49756 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:19.891447067 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49757 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:25.459287882 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49758 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:26.007471085 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49759 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:31.574500084 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49760 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:32.126351118 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49761 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:37.681013107 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49762 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:38.236052036 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49763 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:43.802356005 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49764 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:49.366439104 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49765 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:49.917583942 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49766 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:55.475730896 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49767 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:43:56.023765087 CET | 244 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49768 | 3.6.115.182 | 17383 | 7080 | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Feb 17, 2024 20:44:01.583507061 CET | 244 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:41:59 |
Start date: | 17/02/2024 |
Path: | C:\Users\user\Desktop\kuEfaZxkiY.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x860000 |
File size: | 97'792 bytes |
MD5 hash: | 117EEF8A227E6CE3646718D0ED6FB7B1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 20:41:59 |
Start date: | 17/02/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 12.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 16 |
Total number of Limit Nodes: | 0 |
Graph
Function 00F9E7B0 Relevance: .9, Instructions: 927COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F90CE0 Relevance: 1.5, APIs: 1, Instructions: 49COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F90CE8 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F9DC90 Relevance: 1.6, Strings: 1, Instructions: 369COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |