Click to jump to signature section
Source: https://vt4uy12m.78194238.xyzvt4uy12m.73997077.xyz:443 | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.78356950.xyz/aef88a4362b4d5bdbf5526805b01a2b95556900b87148d4a799fc53c648856f9p | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.77563613.xyz | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.77304456.xyz | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.78356950.xyz/aef88a4362b4d5bdbf5526805b01a2b95556900b87148d4a799fc53c648856f9 | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.74264021.xyz/aef88a4362b4d5bdbf5526805b01a2b95556900b87148d4a799fc53c648856f9https: | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.75263034.xyz/aef88a4362b4d5bdbf5526805b01a2b95556900b87148d4a799fc53c648856f9https: | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.77707980.xyz/aef88a4362b4d5bdbf5526805b01a2b95556900b87148d4a799fc53c648856f9 | Avira URL Cloud: Label: phishing |
Source: https://vt4uy12m.77700543.xyz | Avira URL Cloud: Label: phishing |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Iframe src: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Iframe src: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Iframe src: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Iframe src: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Number of links: 0 |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: Base64 decoded: http://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Title: Aurora Slim does not match URL |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: Has password / email / username input fields |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: <input type="password" .../> found |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/c008o/0x4AAAAAAAPaW4Bymy7OrEjx/dark/normal | HTTP Parser: No favicon |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="author".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="author".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="author".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="author".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="copyright".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="copyright".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="copyright".. found |
Source: http://127.0.0.1:8060/#/auth/login | HTTP Parser: No <meta name="copyright".. found |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries | Jump to behavior |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49743 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.16:49732 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49746 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.85.189:443 -> 192.168.2.16:49757 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49745 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 138.199.40.58:443 -> 192.168.2.16:49752 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49741 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49742 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.85.189:443 -> 192.168.2.16:49755 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49737 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 138.199.57.67:443 -> 192.168.2.16:49750 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49738 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49744 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 89.187.177.16:443 -> 192.168.2.16:49762 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.16:49766 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49774 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49775 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49776 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49777 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49779 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 138.199.40.58:443 -> 192.168.2.16:49781 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 89.187.177.16:443 -> 192.168.2.16:49783 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 138.199.57.67:443 -> 192.168.2.16:49785 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49787 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.85.189:443 -> 192.168.2.16:49788 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49789 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49790 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49791 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.85.189:443 -> 192.168.2.16:49792 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49793 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49798 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49799 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49800 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49811 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.16:49808 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49823 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49824 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 138.199.40.58:443 -> 192.168.2.16:49826 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49828 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49831 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49832 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49837 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49839 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49838 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49844 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 89.187.177.16:443 -> 192.168.2.16:49849 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 138.199.57.67:443 -> 192.168.2.16:49847 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.85.189:443 -> 192.168.2.16:49852 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.85.189:443 -> 192.168.2.16:49854 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49858 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49857 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.21.65.48:443 -> 192.168.2.16:49856 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.163.159:443 -> 192.168.2.16:49861 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.209.108:443 -> 192.168.2.16:49865 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49875 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49876 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49877 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49878 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49879 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49880 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.16:49884 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49895 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49896 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49897 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49898 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49900 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.67.213.254:443 -> 192.168.2.16:49901 version: TLS 1.2 |
Source: aurora-live-20240221.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: D:\nt-driver-builder\wintun-0.14\Release\arm64\driver\wintun.pdbGCTL source: aurora-live-20240221.exe, 00000000.00000000.1208016037.0000000002A23000.00000008.00000001.01000000.00000003.sdmp |
Source: | Binary string: C:\Users\Jason A. Donenfeld\Projects\wintun\Release\amd64\wintun.pdb source: aurora-live-20240221.exe, 00000000.00000000.1208016037.0000000002A23000.00000008.00000001.01000000.00000003.sdmp |
Source: | Binary string: D:\nt-driver-builder\wintun-0.14\Release\amd64\driver\wintun.pdb source: aurora-live-20240221.exe, 00000000.00000000.1208016037.0000000002A23000.00000008.00000001.01000000.00000003.sdmp |
Source: | Binary string: .3dm.aab.aam.aas.abc.ace.afl.aif.aim.aip.alz.ani.aos.aps.apk.arc.arj.art.asf.asm.asp.asx.avi.avs.bin.bmp.boo.boz.bsh.bz2.c++.cab.cat.cco.cdf.cer.cha.cpp.cpt.crl.crt.crx.csh.csv.cxx.dar.dcr.deb.def.der.dif.dir.dmg.doc.dot.drw.dvi.dwf.dwg.dxf.dxr.elc.eml.env.eps.etx.evy.f77.f90.fdf.fif.fli.flo.flv.flx.fmf.for.fpx.frl.gsd.gsm.gsp.gss.hdf.hgl.hlb.hlp.hpg.hqx.hta.htc.htt.htx.ice.ico.ics.icz.idc.ief.igs.ima.inf.ins.isu.ivr.ivy.jam.jav.jcm.jpe.jps.vue.jut.kar.kfo.flw.kml.kmz.kon.kpr.kpt.ksp.kwd.kwt.ksh.lam.lha.lhx.lma.log.lsp.lst.lsx.ltx.lzh.lzx.m1v.m2a.m2v.m3u.man.map.mar.mbd.mc$.mcd.mcf.mcp.mht.mid.mif.mjf.mme.mod.mov.mp2.mp3.mp4.mpa.mpc.mpe.mpg.mpp.mpt.mpv.mpx.mrc.mzz.nap.ncm.nif.nix.nsc.nvd.oda.odb.odc.odf.odg.odi.odm.odp.ods.odt.oga.ogg.ogv.omc.otc.otf.otg.oth.oti.otm.otp.ots.ott.p10.p12.p7a.p7c.p7m.p7r.p7s.pas.pbm.pcl.pct.pcx.pdb.pgm.pic.pkg.pko.plx.pm4.pm5.pnm.pot.pov.ppa.ppm.pps.ppt.ppz.pre.prt.psd.pvu.pwz.pyc.qcp.qd3.qif.qtc.qti.ram.rar.ras.rgb.rmi.rmm.rmp.rng.rnx.rpm.rtf.rtx.s3m.s7z.sbk.scm.sdp.sdr.sea.set.sgm.sid.skd.skm.skp.skt.sit.smi.snd.sol.spc.spl.spr.spx.src.ssi.ssm.sst.stl.stp.svf.svr.swf.tar.tbk.tcl.tex.tgz.tif.tsi.tsp.tsv.txt.uil.uni.unv.uri.uue.vcd.vcf.vcs.vda.vdo.vew.viv.vmd.vmf.voc.vos.vox.vqe.vqf.vql.vrt.vsd.vst.vsw.w60.w61.w6w.wav.wb1.web.wiz.wk1.wmf.wml.wp5.wp6.wpd.wq1.wri.wrl.wrz.wsc.wtk.xbm.xdr.xgz.xif.xla.xlb.xlc.xld.xlk.xll.xlm.xls.xlt.xlv.xlw.xmz.xpm.xsr.xwd.xyz.zip.zoo.zsh.xpiheroHTML...`.nanTrueTRUENull.NaN.NAN.Inf.INFyaml-513Hash"%s"tomlText$outU+%XU+%svminvmaxgradturn#f00QUOTaposbsolexclgeqqgneqhArrisinlcubleqqlneqlparlsqbngeqngtrnleqperpplusprecquotrcubrealrparrsqbsemismidsparsuccvertxveeclipdefsfillfonthreflinemaskrecttcp4tcp6/Tunudp4obfscertmodeexecABRTALRMKILLPIPEQUITSEGVTERMCIRCHALTstunAMP;Acy;Afr;And;Bcy;Bfr;Cap;Cfr;Chi;Cup;Dcy;Del;Dfr;Dot;ENG;ETH;Ecy;Efr;Eta;Fcy;Ffr;Gcy;Gfr;Hat;Hfr;Icy;Ifr;Int;Jcy;Jfr;Kcy;Kfr;Lcy;Lfr;Lsh;Map;Mcy;Mfr;Ncy;Nfr;Not;Ocy;Ofr;Pcy;Pfr;Phi;Psi;Qfr;REG;Rcy;Rfr;Rho;Rsh;Scy;Sfr;Sub;Sum;Sup;Tab;Tau;Tcy;Tfr;Ucy;Ufr;Vcy;Vee;Vfr;Wfr;Xfr;Ycy;Yfr;Zcy;Zfr;acd;acy;afr;amp;and;ang;apE;ape;ast;bcy;bfr;bot;cap;cfr;chi;cir;cup;dcy;deg;dfr;die;div;dot;ecy;efr;egs;ell;els;eng;eta;eth;fcy;ffr;gEl;gap;gcy;gel;geq;ges;gfr;ggg;glE;gla;glj;gnE;gne;hfr;icy;iff;ifr;int;jcy;jfr;kcy;kfr;lEg;lap;lat;lcy;leg;leq;les;lfr;lgE;lnE;lne;loz;lrm;lsh;map;mcy;mfr;mho;mid;nap;ncy;nfr;nge;ngt;nis;niv;nle;nlt;not;npr;nsc;num;ocy;ofr;ogt;ohm;olt;ord;orv;par;pcy;pfr;phi;piv;prE;pre;psi;qfr;rcy;reg;rfr;rho;rl |