Windows
Analysis Report
RFQ 10046335 PO 4502042346 PR 11148099 411128.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- RFQ 10046335 PO 4502042346 PR 11148099 411128.exe (PID: 7576 cmdline:
"C:\Users\ user\Deskt op\RFQ 100 46335 PO 4 502042346 PR 1114809 9 411128.e xe" MD5: 0B57430159E81D152455D3D2936F44E0) - conhost.exe (PID: 7596 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7640 cmdline:
C:\Windows \system32\ WindowsPow erShell\v1 .0\powersh ell.exe Ad d-MpPrefer ence -Excl usionPath $env:UserP rofile MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 7648 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - WmiPrvSE.exe (PID: 7860 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) - jsc.exe (PID: 7752 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\jsc .exe" MD5: 94C8E57A80DFCA2482DEDB87B93D4FD9)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
{"C2 url": ["195.10.205.102:1912"], "Bot Id": "foz", "Authorization Header": "c74790bd166600f1f665c8ce201776eb"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_RedLine_1 | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Click to see the 2 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp: | 06/28/24-08:47:31.833377 |
SID: | 2043231 |
Source Port: | 49731 |
Destination Port: | 1912 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 06/28/24-08:47:29.500952 |
SID: | 2046056 |
Source Port: | 1912 |
Destination Port: | 49731 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 06/28/24-08:47:24.044676 |
SID: | 2046045 |
Source Port: | 49731 |
Destination Port: | 1912 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 06/28/24-08:47:24.248710 |
SID: | 2043234 |
Source Port: | 1912 |
Destination Port: | 49731 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF65F3DD7E0 | |
Source: | Code function: | 0_2_00007FF65F363D20 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F32DD30 | |
Source: | Code function: | 0_2_00007FF65F2A1C50 | |
Source: | Code function: | 0_2_00007FF65F2A1C50 |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF65F2D38B0 | |
Source: | Code function: | 0_2_00007FF65F2D21B0 | |
Source: | Code function: | 0_2_00007FF65F2CC0A0 | |
Source: | Code function: | 0_2_00007FF65F2B2080 | |
Source: | Code function: | 0_2_00007FF65F2DE8E0 | |
Source: | Code function: | 0_2_00007FF65F2D58C0 | |
Source: | Code function: | 0_2_00007FF65F2B3130 | |
Source: | Code function: | 0_2_00007FF65F2C17B4 | |
Source: | Code function: | 0_2_00007FF65F357F40 | |
Source: | Code function: | 0_2_00007FF65F2ABF90 | |
Source: | Code function: | 0_2_00007FF65F2D67E0 | |
Source: | Code function: | 0_2_00007FF65F2CC7D0 | |
Source: | Code function: | 0_2_00007FF65F2B3EF0 | |
Source: | Code function: | 0_2_00007FF65F2AB6F0 | |
Source: | Code function: | 0_2_00007FF65F2A6ED0 | |
Source: | Code function: | 0_2_00007FF65F2C1D60 | |
Source: | Code function: | 0_2_00007FF65F2BD620 | |
Source: | Code function: | 0_2_00007FF65F2C6C90 | |
Source: | Code function: | 0_2_00007FF65F2D5490 | |
Source: | Code function: | 0_2_00007FF65F2CBC80 | |
Source: | Code function: | 0_2_00007FF65F2C02A0 | |
Source: | Code function: | 0_2_00007FF65F2B9A90 | |
Source: | Code function: | 0_2_00007FF65F2A82D0 | |
Source: | Code function: | 0_2_00007FF65F2D4B10 | |
Source: | Code function: | 0_2_00007FF65F2D71B0 | |
Source: | Code function: | 0_2_00007FF65F2D29B0 | |
Source: | Code function: | 0_2_00007FF65F2B81F0 | |
Source: | Code function: | 0_2_00007FF65F2D31E0 | |
Source: | Code function: | 0_2_00007FF65F2A39D0 | |
Source: | Code function: | 4_2_00B325D8 | |
Source: | Code function: | 4_2_00B3DC74 | |
Source: | Code function: | 4_2_05437660 | |
Source: | Code function: | 4_2_054396C8 | |
Source: | Code function: | 4_2_0543B170 | |
Source: | Code function: | 4_2_05436928 | |
Source: | Code function: | 4_2_0543B9E8 |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF65F2B2F60 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | |||
Source: | File created: | |||
Source: | File created: | |||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_0-16182 |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | Code function: | 0_2_00007FF65F2B2B90 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 0_2_00007FF65F2A8130 | |
Source: | Code function: | 0_2_00007FF65F30B70C |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_00007FF65F30BDA4 |
Source: | Code function: | 0_2_00007FF65F370D30 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00007FF65F2AEB00 |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 221 Windows Management Instrumentation | 1 DLL Side-Loading | 1 Access Token Manipulation | 111 Masquerading | 1 OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | Boot or Logon Initialization Scripts | 311 Process Injection | 11 Disable or Modify Tools | LSASS Memory | 321 Security Software Discovery | Remote Desktop Protocol | 2 Data from Local System | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 241 Virtualization/Sandbox Evasion | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Access Token Manipulation | NTDS | 241 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 311 Process Injection | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Deobfuscate/Decode Files or Information | Cached Domain Credentials | 135 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Obfuscated Files or Information | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 Software Packing | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 DLL Side-Loading | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse | ||
39% | ReversingLabs | Win64.Spyware.RedLine |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
39% | ReversingLabs | Win64.Spyware.RedLine |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
2% | Virustotal | Browse | ||
2% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
4% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
1% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
3% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
2% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
2% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
2% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
195.10.205.102 | unknown | Russian Federation | 35813 | TSSCOM-ASRU | true |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1463997 |
Start date and time: | 2024-06-28 08:46:08 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 30s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | RFQ 10046335 PO 4502042346 PR 11148099 411128.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@8/8@0/1 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
02:47:21 | API Interceptor | |
02:47:29 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TSSCOM-ASRU | Get hash | malicious | AsyncRAT | Browse |
| |
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | LummaC Stealer, PrivateLoader, PureLog Stealer, RedLine, RisePro Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC Stealer, PrivateLoader, PureLog Stealer, RedLine, RisePro Stealer, SmokeLoader, Xmrig | Browse |
| ||
Get hash | malicious | LummaC Stealer, PrivateLoader, RedLine, RisePro Stealer, SmokeLoader | Browse |
|
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3094 |
Entropy (8bit): | 5.33145931749415 |
Encrypted: | false |
SSDEEP: | 96:Pq5qHwCYqh3oPtI6eqzxP0aymTqdqlq7qqjqcEZ5D:Pq5qHwCYqh3qtI6eqzxP0atTqdqlq7qV |
MD5: | 3FD5C0634443FB2EF2796B9636159CB6 |
SHA1: | 366DDE94AEFCFFFAB8E03AD8B448E05D7489EB48 |
SHA-256: | 58307E94C67E2348F5A838DE4FF668983B38B7E9A3B1D61535D3A392814A57D6 |
SHA-512: | 8535E7C0777C6B0876936D84BDE2BDC59963CF0954D4E50D65808E6E806E8B131DF5DB8FA0E030FAE2702143A7C3A70698A2B9A80519C9E2FFC286A71F0B797C |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1628158735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul5mxllp:NllU4x/ |
MD5: | 3A925CB766CE4286E251C26E90B55CE8 |
SHA1: | 3FA8EE6E901101A4661723B94D6C9309E281BD28 |
SHA-256: | 4E844662CDFFAAD50BA6320DC598EBE0A31619439D0F6AB379DF978FE81C7BF8 |
SHA-512: | F348B4AFD42C262BBED07D6BDEA6EE4B7F5CFA2E18BFA725225584E93251188D9787506C2AFEAC482B606B1EA0341419F229A69FF1E9100B01DE42025F915788 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\RFQ 10046335 PO 4502042346 PR 11148099 411128.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2440192 |
Entropy (8bit): | 7.07799900264123 |
Encrypted: | false |
SSDEEP: | 49152:IF50a6aPVOFMx3SmroCZscivbS6mqxEWoKmqZJffp3vSsqPUYeaw1GlNOmTCbCuF:KroA7PxBOb |
MD5: | 0B57430159E81D152455D3D2936F44E0 |
SHA1: | 245C53304354AD8C703B2DD4FCE1CC1EC46573BB |
SHA-256: | BEA6547E13A91DEA30B43F7B50A6E95D8CBC285C9A2C397FA52D17CE8351CC30 |
SHA-512: | C70103E599A534BD6AAD4238DF567223FC4D2A7B07632BE09C42EA2F46E3C941523EAD3B3EE27ABE72445DED4E33A646421A176D82FAB637B4B500782B629F40 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\RFQ 10046335 PO 4502042346 PR 11148099 411128.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 7.07799900264123 |
TrID: |
|
File name: | RFQ 10046335 PO 4502042346 PR 11148099 411128.exe |
File size: | 2'440'192 bytes |
MD5: | 0b57430159e81d152455d3d2936f44e0 |
SHA1: | 245c53304354ad8c703b2dd4fce1cc1ec46573bb |
SHA256: | bea6547e13a91dea30b43f7b50a6e95d8cbc285c9a2c397fa52d17ce8351cc30 |
SHA512: | c70103e599a534bd6aad4238df567223fc4d2a7b07632be09c42ea2f46e3c941523ead3b3ee27abe72445ded4e33a646421a176d82fab637b4b500782b629f40 |
SSDEEP: | 49152:IF50a6aPVOFMx3SmroCZscivbS6mqxEWoKmqZJffp3vSsqPUYeaw1GlNOmTCbCuF:KroA7PxBOb |
TLSH: | C6B5BD15E3E801A8D877D630CA62A332DBB079961730D58F065DD65A2F73EA19B3F312 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......'..Ec...c...c....v..j....v..n....v..M...j.D.m...(...h...c...n....w..k....w..b...c...b....w..$...pq..b...pq..b...Richc.......... |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x14006b3dc |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x667DA332 [Thu Jun 27 17:36:50 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 97f00b2383bd4369e5094078fdccae7a |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F4F7D1F6780h |
dec eax |
add esp, 28h |
jmp 00007F4F7D1F5FC7h |
int3 |
int3 |
jmp 00007F4F7D1F6AFCh |
int3 |
int3 |
int3 |
dec eax |
sub esp, 28h |
dec ebp |
mov eax, dword ptr [ecx+38h] |
dec eax |
mov ecx, edx |
dec ecx |
mov edx, ecx |
call 00007F4F7D1F6162h |
mov eax, 00000001h |
dec eax |
add esp, 28h |
ret |
int3 |
int3 |
int3 |
inc eax |
push ebx |
inc ebp |
mov ebx, dword ptr [eax] |
dec eax |
mov ebx, edx |
inc ecx |
and ebx, FFFFFFF8h |
dec esp |
mov ecx, ecx |
inc ecx |
test byte ptr [eax], 00000004h |
dec esp |
mov edx, ecx |
je 00007F4F7D1F6165h |
inc ecx |
mov eax, dword ptr [eax+08h] |
dec ebp |
arpl word ptr [eax+04h], dx |
neg eax |
dec esp |
add edx, ecx |
dec eax |
arpl ax, cx |
dec esp |
and edx, ecx |
dec ecx |
arpl bx, ax |
dec edx |
mov edx, dword ptr [eax+edx] |
dec eax |
mov eax, dword ptr [ebx+10h] |
mov ecx, dword ptr [eax+08h] |
dec eax |
mov eax, dword ptr [ebx+08h] |
test byte ptr [ecx+eax+03h], 0000000Fh |
je 00007F4F7D1F615Dh |
movzx eax, byte ptr [ecx+eax+03h] |
and eax, FFFFFFF0h |
dec esp |
add ecx, eax |
dec esp |
xor ecx, edx |
dec ecx |
mov ecx, ecx |
pop ebx |
jmp 00007F4F7D1F6172h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
nop word ptr [eax+eax+00000000h] |
dec eax |
cmp ecx, dword ptr [001D73A9h] |
jne 00007F4F7D1F6162h |
dec eax |
rol ecx, 10h |
test cx, FFFFh |
jne 00007F4F7D1F6153h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x23ec60 | 0x58 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x23ecb8 | 0x104 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x264000 | 0x4b918 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x250000 | 0x1368c | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x2b0000 | 0x5ec | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x216600 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x216800 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x2164c0 | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x198000 | 0x818 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x6fef8 | 0x70000 | dd316bc2c65b1ae399457fdba120fa82 | False | 0.45282200404575895 | data | 6.641185225824904 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.managed | 0x71000 | 0xd9b18 | 0xd9c00 | 74b435642e339cdb1b2a678eb60c92d8 | False | 0.4628401711394948 | data | 6.464502436229499 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
hydrated | 0x14b000 | 0x4c540 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0x198000 | 0xa89e4 | 0xa8a00 | 5136a3db5b9bcc5734abe5310647f73e | False | 0.48930052353595255 | data | 6.720923141068736 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x241000 | 0xe668 | 0x1a00 | f7893d3998d6fe23c3c2fd83a455cf8d | False | 0.22581129807692307 | data | 3.2697501080046183 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x250000 | 0x1368c | 0x13800 | e5aeded247d82c5d18901a5f5b1c4999 | False | 0.49800931490384615 | data | 6.163194359627306 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x264000 | 0x4b918 | 0x4ba00 | eb47f429e2704c0f322922e73df5efeb | False | 0.9971849173553718 | data | 7.998508779194308 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x2b0000 | 0x5ec | 0x600 | 22b17bd43d0ff4894ef88b7e105d8348 | False | 0.5989583333333334 | data | 5.299377162126531 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
BINARY | 0x264110 | 0x4b2a4 | data | 1.0003280541516715 | ||
RT_VERSION | 0x2af3b4 | 0x378 | data | 0.35923423423423423 | ||
RT_MANIFEST | 0x2af72c | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
ADVAPI32.dll | AdjustTokenPrivileges, CreateWellKnownSid, DeregisterEventSource, DuplicateTokenEx, GetSecurityDescriptorLength, GetTokenInformation, GetWindowsAccountDomainSid, LookupPrivilegeValueW, OpenProcessToken, OpenThreadToken, RegCloseKey, RegCreateKeyExW, RegDeleteKeyExW, RegDeleteTreeW, RegDeleteValueW, RegEnumKeyExW, RegEnumValueW, RegFlushKey, RegOpenKeyExW, RegQueryInfoKeyW, RegQueryValueExW, RegSetValueExA, RegSetValueExW, RegisterEventSourceW, ReportEventW, RevertToSelf, SetThreadToken |
bcrypt.dll | BCryptDestroyKey, BCryptEncrypt, BCryptGenRandom, BCryptOpenAlgorithmProvider, BCryptSetProperty, BCryptDecrypt, BCryptCloseAlgorithmProvider, BCryptImportKey |
KERNEL32.dll | TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, InitializeCriticalSectionAndSpinCount, EncodePointer, RaiseException, RtlPcToFileHeader, AllocConsole, CancelThreadpoolIo, CloseHandle, CloseThreadpoolIo, CompareStringEx, CompareStringOrdinal, CopyFileExW, CreateDirectoryW, CreateEventExW, CreateFileW, CreateProcessA, CreateSymbolicLinkW, CreateThreadpoolIo, DeleteCriticalSection, DeleteFileW, DeleteVolumeMountPointW, DeviceIoControl, DuplicateHandle, EnterCriticalSection, EnumCalendarInfoExEx, EnumTimeFormatsEx, ExitProcess, ExpandEnvironmentStringsW, FileTimeToSystemTime, FindClose, FindFirstFileExW, FindNLSStringEx, FindNextFileW, FindStringOrdinal, FlushFileBuffers, FormatMessageW, FreeConsole, FreeLibrary, GetCPInfo, GetCalendarInfoEx, GetConsoleOutputCP, GetConsoleWindow, GetCurrentProcess, GetCurrentProcessId, GetCurrentProcessorNumberEx, GetCurrentThread, GetDynamicTimeZoneInformation, GetEnvironmentVariableW, GetFileAttributesExW, GetFileInformationByHandle, GetFileInformationByHandleEx, GetFileType, GetFinalPathNameByHandleW, GetFullPathNameW, GetLastError, GetLocaleInfoEx, GetLogicalDrives, GetLongPathNameW, GetModuleFileNameW, GetModuleHandleA, GetOverlappedResult, GetProcAddress, GetStdHandle, GetSystemDirectoryW, GetSystemTime, GetThreadPriority, GetTickCount64, GetTimeZoneInformation, GetUserPreferredUILanguages, GetVolumeInformationW, InitializeConditionVariable, InitializeCriticalSection, IsDebuggerPresent, LCMapStringEx, LeaveCriticalSection, LoadLibraryExW, LocalAlloc, LocalFree, LocaleNameToLCID, MoveFileExW, MultiByteToWideChar, QueryPerformanceCounter, QueryPerformanceFrequency, RaiseFailFastException, ReadFile, RemoveDirectoryW, ReplaceFileW, ResetEvent, ResolveLocaleName, ResumeThread, SetEvent, SetFileAttributesW, SetFileInformationByHandle, SetLastError, SetThreadErrorMode, SetThreadPriority, Sleep, SleepConditionVariableCS, StartThreadpoolIo, SystemTimeToFileTime, TzSpecificLocalTimeToSystemTime, VirtualAlloc, VirtualFree, WaitForMultipleObjectsEx, WakeConditionVariable, WideCharToMultiByte, WriteFile, FlushProcessWriteBuffers, WaitForSingleObjectEx, RtlVirtualUnwind, RtlCaptureContext, RtlRestoreContext, VerSetConditionMask, AddVectoredExceptionHandler, FlsAlloc, FlsGetValue, FlsSetValue, CreateEventW, SwitchToThread, CreateThread, GetCurrentThreadId, SuspendThread, GetThreadContext, SetThreadContext, QueryInformationJobObject, GetModuleHandleW, GetModuleHandleExW, GetProcessAffinityMask, VerifyVersionInfoW, InitializeContext, GetEnabledXStateFeatures, SetXStateFeaturesMask, VirtualQuery, GetSystemTimeAsFileTime, InitializeCriticalSectionEx, DebugBreak, WaitForSingleObject, SleepEx, GlobalMemoryStatusEx, GetSystemInfo, GetLogicalProcessorInformation, GetLogicalProcessorInformationEx, GetLargePageMinimum, VirtualUnlock, VirtualAllocExNuma, IsProcessInJob, GetNumaHighestNodeNumber, GetProcessGroupAffinity, K32GetProcessMemoryInfo, RtlUnwindEx, InitializeSListHead, IsProcessorFeaturePresent, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RtlLookupFunctionEntry |
ole32.dll | CoTaskMemAlloc, CoTaskMemFree, CoUninitialize, CoWaitForMultipleHandles, CoInitializeEx, CoCreateGuid, CoGetApartmentType |
USER32.dll | LoadStringW |
api-ms-win-crt-math-l1-1-0.dll | __setusermatherr, floor, pow, modf, sin, cos, ceil, tan |
api-ms-win-crt-heap-l1-1-0.dll | free, calloc, _set_new_mode, malloc, _callnewh |
api-ms-win-crt-string-l1-1-0.dll | strncpy_s, strcpy_s, _stricmp, wcsncmp, strcmp |
api-ms-win-crt-convert-l1-1-0.dll | strtoull |
api-ms-win-crt-runtime-l1-1-0.dll | _register_thread_local_exe_atexit_callback, _c_exit, _cexit, __p___wargv, __p___argc, _exit, exit, _initterm_e, terminate, _crt_atexit, _initterm, _register_onexit_function, _get_initial_wide_environment, abort, _initialize_onexit_table, _initialize_wide_environment, _configure_wide_argv, _seh_filter_exe, _set_app_type |
api-ms-win-crt-stdio-l1-1-0.dll | __stdio_common_vsscanf, __p__commode, __acrt_iob_func, __stdio_common_vfprintf, __stdio_common_vsprintf_s, _set_fmode |
api-ms-win-crt-locale-l1-1-0.dll | _configthreadlocale |
Name | Ordinal | Address |
---|---|---|
DotNetRuntimeDebugHeader | 1 | 0x140241d50 |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
06/28/24-08:47:31.833377 | TCP | 2043231 | ET TROJAN Redline Stealer TCP CnC Activity | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
06/28/24-08:47:29.500952 | TCP | 2046056 | ET TROJAN Redline Stealer/MetaStealer Family Activity (Response) | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
06/28/24-08:47:24.044676 | TCP | 2046045 | ET TROJAN [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization) | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
06/28/24-08:47:24.248710 | TCP | 2043234 | ET MALWARE Redline Stealer TCP CnC - Id1Response | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 28, 2024 08:47:23.101418972 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:23.106427908 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:23.109050035 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:23.118577003 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:23.123532057 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:23.777523041 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:23.824374914 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:24.044676065 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:24.050185919 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:24.248709917 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:24.293123960 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:29.296793938 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:29.301635027 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.500952005 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.500981092 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.500998020 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.501013041 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.501028061 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.501035929 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:29.501055002 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:29.501131058 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.785341978 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.791244030 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.791380882 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.791551113 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.791610003 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.791652918 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.791666985 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.791713953 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.791954994 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.792009115 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.792021990 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.792028904 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.792035103 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.792052984 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.792066097 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.792069912 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.792108059 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.796566010 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.796590090 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.796641111 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.796647072 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.796653986 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.796694040 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.796711922 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.796762943 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.796839952 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.796912909 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.797327995 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.797414064 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.797467947 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.797530890 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.801944971 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802005053 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802182913 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802264929 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802270889 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802324057 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802412033 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802473068 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802484035 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802496910 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802544117 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802584887 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802598000 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802611113 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802642107 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802650928 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802654028 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802665949 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802704096 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802751064 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802762985 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802850008 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802854061 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.802862883 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802875042 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.802911043 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.804439068 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.804451942 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.804464102 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.804774046 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807244062 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807320118 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807332993 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807343006 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807344913 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807367086 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807372093 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807379007 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807396889 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807411909 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807425022 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807456017 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807461023 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807590008 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807602882 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807614088 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807615042 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807629108 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807631969 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807651043 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807661057 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807662964 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807674885 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807706118 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807713985 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.807718039 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807766914 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807780027 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807791948 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807815075 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807826996 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807838917 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807877064 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807889938 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807902098 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807915926 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807928085 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807985067 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.807997942 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808010101 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808104038 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808123112 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808239937 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808253050 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808264971 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808312893 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808326006 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808336973 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808358908 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808372021 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808382988 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808394909 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808408976 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808491945 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808505058 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808516979 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808537006 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808552980 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808573008 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808573961 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.808585882 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808598042 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808609962 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808633089 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808643103 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.808645964 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808657885 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808789015 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808800936 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808811903 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808824062 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808836937 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.808847904 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.809695959 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812027931 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812081099 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812093019 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812112093 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812135935 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812149048 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812160969 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812172890 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812186956 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812206984 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812310934 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812323093 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812345028 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812357903 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812411070 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812423944 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.812438011 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813184977 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813278913 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813395023 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813462973 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813474894 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813487053 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813508034 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813519955 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813571930 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813585043 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813596964 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813625097 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813637018 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813648939 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813672066 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813684940 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813697100 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813716888 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813730955 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813743114 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813764095 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813776970 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813788891 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813821077 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813854933 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.813885927 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813915014 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.813967943 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.813981056 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814008951 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814021111 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814033031 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814044952 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814059019 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814069986 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814104080 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814116001 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814126968 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814147949 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814160109 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814172983 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814445019 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814450026 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814455032 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814523935 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814536095 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814548016 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814569950 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814583063 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814599991 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814611912 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814624071 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814635038 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814657927 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814676046 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814688921 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814709902 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814722061 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814733982 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814929008 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814941883 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814953089 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814965963 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814976931 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.814989090 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.815078974 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.815080881 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.815093040 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.815104961 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.815116882 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818759918 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818772078 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818784952 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818797112 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818820000 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818831921 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818854094 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818866014 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818907976 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818934917 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.818941116 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818988085 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.818996906 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.819000959 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819041014 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819055080 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819067955 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819081068 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819092989 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819104910 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819118977 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819130898 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819142103 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819154024 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819165945 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819178104 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819227934 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819240093 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819251060 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819262981 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819284916 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819297075 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819308996 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819320917 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819333076 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819344044 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819355965 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819367886 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819380999 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819394112 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819405079 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819427013 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819438934 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819504023 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819515944 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819542885 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819555998 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819566965 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819578886 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819591045 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819665909 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819678068 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.819689035 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.820856094 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.820868969 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.823971987 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824136972 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.824146986 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824160099 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824208975 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824213028 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.824280977 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824292898 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824315071 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824326992 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824338913 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824351072 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824362993 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824393034 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824405909 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824433088 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824445009 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824505091 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824517012 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824528933 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824542999 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824594021 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824635029 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824675083 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824687958 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824733973 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824747086 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824765921 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824780941 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824794054 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824805021 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824824095 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824892998 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824904919 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.824915886 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825223923 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825243950 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825256109 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825269938 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825283051 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825294018 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825306892 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825318098 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825330019 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825344086 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825355053 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825366974 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825377941 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825391054 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825402021 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825413942 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825424910 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825437069 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825592041 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.825603962 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.828985929 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.828999043 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829102993 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829114914 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829127073 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829138041 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829171896 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829185009 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829262972 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829274893 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829294920 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829308987 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829323053 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829377890 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829384089 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.829391003 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829402924 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829452038 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829454899 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.829464912 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829477072 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829488993 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829500914 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829514980 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829546928 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829585075 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829622030 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829668045 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829679966 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829691887 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829705000 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829751015 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829762936 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829773903 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829787016 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829808950 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829823971 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829854965 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829866886 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829889059 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829957008 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829969883 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829982042 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.829994917 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830029964 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830041885 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830054045 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830070972 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830075979 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830117941 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830130100 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830141068 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830162048 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830173969 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.830188036 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834331989 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834343910 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834356070 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834389925 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834402084 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834450006 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834462881 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834476948 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834558964 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834572077 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834583998 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834608078 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.834614038 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834625959 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834638119 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834661961 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834675074 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.834676027 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834687948 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834702015 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834733009 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834744930 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834755898 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834779024 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834790945 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834868908 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834913969 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834927082 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834966898 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834971905 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834983110 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.834995031 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.835006952 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.835028887 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.835040092 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.835052013 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.877223969 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.877429962 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.877530098 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.877530098 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.877573967 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.882464886 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882515907 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882529020 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882543087 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882555008 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882566929 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882596970 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882608891 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882631063 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882642031 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882654905 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882666111 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882678986 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882694006 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882709026 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882733107 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882746935 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882759094 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882805109 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882817984 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882829905 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882842064 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882853031 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882865906 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.882877111 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.925144911 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:30.925381899 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:30.977224112 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:31.832619905 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:31.833376884 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Jun 28, 2024 08:47:31.838313103 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:32.037343979 CEST | 1912 | 49731 | 195.10.205.102 | 192.168.2.4 |
Jun 28, 2024 08:47:32.071404934 CEST | 49731 | 1912 | 192.168.2.4 | 195.10.205.102 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 02:47:18 |
Start date: | 28/06/2024 |
Path: | C:\Users\user\Desktop\RFQ 10046335 PO 4502042346 PR 11148099 411128.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff65f2a0000 |
File size: | 2'440'192 bytes |
MD5 hash: | 0B57430159E81D152455D3D2936F44E0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 02:47:18 |
Start date: | 28/06/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 02:47:19 |
Start date: | 28/06/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 02:47:19 |
Start date: | 28/06/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 02:47:19 |
Start date: | 28/06/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x4c0000 |
File size: | 47'584 bytes |
MD5 hash: | 94C8E57A80DFCA2482DEDB87B93D4FD9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
Has exited: | true |
Target ID: | 5 |
Start time: | 02:47:23 |
Start date: | 28/06/2024 |
Path: | C:\Windows\System32\wbem\WmiPrvSE.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff693ab0000 |
File size: | 496'640 bytes |
MD5 hash: | 60FF40CFD7FB8FE41EE4FE9AE5FE1C51 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Analysis Process: RFQ 10046335 PO 4502042346 PR 11148099 411128.exePID: 7576, Parent PID: 2580COMMON
Execution Graph
Execution Coverage: | 5.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 26.4% |
Total number of Nodes: | 978 |
Total number of Limit Nodes: | 28 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A8130 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 105COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F30BDA4 Relevance: 3.2, APIs: 2, Instructions: 199COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D38B0 Relevance: .4, Instructions: 397COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D21B0 Relevance: .3, Instructions: 316COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B2750 Relevance: 15.8, APIs: 6, Strings: 3, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2AD0F0 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 90memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A3630 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 82sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B2570 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 132COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B8DCB Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 106COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B2EA0 Relevance: 1.3, APIs: 1, Instructions: 7COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B2F60 Relevance: 19.3, APIs: 10, Strings: 1, Instructions: 81memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A6ED0 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 245COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2BD620 Relevance: 4.7, APIs: 2, Strings: 1, Instructions: 195COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D58C0 Relevance: 1.0, Instructions: 950COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D67E0 Relevance: .7, Instructions: 655COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D71B0 Relevance: .6, Instructions: 574COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2C6C90 Relevance: .4, Instructions: 431COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F357F40 Relevance: .4, Instructions: 430COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2C1D60 Relevance: .4, Instructions: 412COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2C17B4 Relevance: .4, Instructions: 357COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2AB6F0 Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F32DD30 Relevance: .3, Instructions: 262COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B81F0 Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2CBC80 Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D5490 Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A82D0 Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F3DD7E0 Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2B9A90 Relevance: .1, Instructions: 125COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2CC0A0 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F363D20 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2D29B0 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A39D0 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A1C50 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A3000 Relevance: 26.4, APIs: 12, Strings: 3, Instructions: 144librarythreadloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A3007 Relevance: 26.4, APIs: 12, Strings: 3, Instructions: 142librarythreadloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2ADBD0 Relevance: 24.1, APIs: 8, Strings: 8, Instructions: 101stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2ACBA0 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 84libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A33B0 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 50threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2A3EB0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 126COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F30BA10 Relevance: 6.0, APIs: 4, Instructions: 39timethreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F30CF30 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 44COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF65F2AE4E0 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 37stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 7.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 44 |
Total number of Limit Nodes: | 4 |
Graph
Function 054396C8 Relevance: 1.1, Instructions: 1063COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05437660 Relevance: .7, Instructions: 749COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543B170 Relevance: .3, Instructions: 339COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B3AE30 Relevance: 1.7, APIs: 1, Instructions: 205COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B35935 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B34248 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B3C9A0 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B3D2F9 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B3A870 Relevance: 1.6, APIs: 1, Instructions: 55libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B3B2A0 Relevance: 1.6, APIs: 1, Instructions: 55libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B3B020 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05436D88 Relevance: .4, Instructions: 406COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05436098 Relevance: .3, Instructions: 347COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05437C89 Relevance: .3, Instructions: 295COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543E4E0 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543B15F Relevance: .2, Instructions: 193COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543D120 Relevance: .2, Instructions: 168COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543B818 Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05436459 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543B7CD Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543F878 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543EB97 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543F6F8 Relevance: .1, Instructions: 99COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097D4C4 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05436E11 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05438BC0 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098D006 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05438BD0 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097D4BF Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543E428 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543E838 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543E828 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097DA81 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543D690 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543D6A0 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543D720 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097DA80 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543F868 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05437650 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543F6E8 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0543D8B2 Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|