Windows
Analysis Report
004552024107.bat.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64native
- 004552024107.bat.exe (PID: 6660 cmdline:
"C:\Users\ user\Deskt op\0045520 24107.bat. exe" MD5: 2D40C2AEFEF620E7FB177F0CF24D8EA5) - 004552024107.bat.exe (PID: 7736 cmdline:
"C:\Users\ user\Deskt op\0045520 24107.bat. exe" MD5: 2D40C2AEFEF620E7FB177F0CF24D8EA5)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_GuLoader_3 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00405A4F | |
Source: | Code function: | 0_2_00406620 | |
Source: | Code function: | 2_2_00405A4F | |
Source: | Code function: | 2_2_00406620 |
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | DNS query: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_0040550F |
Source: | Code function: | 0_2_004033D8 | |
Source: | Code function: | 2_2_004033D8 |
Source: | Code function: | 0_2_004072D1 | |
Source: | Code function: | 0_2_00406AFA | |
Source: | Code function: | 0_2_6C601B28 | |
Source: | Code function: | 2_2_004072D1 | |
Source: | Code function: | 2_2_00406AFA | |
Source: | Code function: | 2_2_001588F8 | |
Source: | Code function: | 2_2_001538F8 | |
Source: | Code function: | 2_2_00154910 | |
Source: | Code function: | 2_2_0015F15B | |
Source: | Code function: | 2_2_0015EA08 | |
Source: | Code function: | 2_2_0015BB68 | |
Source: | Code function: | 2_2_00154040 | |
Source: | Code function: | 2_2_37BB5DA8 | |
Source: | Code function: | 2_2_37BBA5E0 | |
Source: | Code function: | 2_2_37BB1AE8 | |
Source: | Code function: | 2_2_37BB3C20 | |
Source: | Code function: | 2_2_37BB4610 | |
Source: | Code function: | 2_2_37BB9270 | |
Source: | Code function: | 2_2_37BBC7F8 | |
Source: | Code function: | 2_2_37BB56C0 | |
Source: | Code function: | 2_2_37BB0040 | |
Source: | Code function: | 2_2_001589B0 | |
Source: | Code function: | 2_2_0015BF10 |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_004033D8 | |
Source: | Code function: | 2_2_004033D8 |
Source: | Code function: | 0_2_004047BF |
Source: | Code function: | 0_2_00402198 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_6C601B28 |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | HTTP traffic detected: |
Source: | WMI Queries: |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Code function: | 0_2_00405A4F | |
Source: | Code function: | 0_2_00406620 | |
Source: | Code function: | 2_2_00405A4F | |
Source: | Code function: | 2_2_00406620 |
Source: | API call chain: | graph_0-4658 | ||
Source: | API call chain: | graph_0-4508 |
Source: | Code function: | 0_2_00401A43 |
Source: | Code function: | 0_2_6C601B28 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_004033D8 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 3 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 1 Native API | 1 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 1 Deobfuscate/Decode Files or Information | 1 Credentials in Registry | 126 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 1 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 11 Process Injection | 1 Obfuscated Files or Information | Security Account Manager | 31 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | NTDS | 12 Virtualization/Sandbox Evasion | Distributed Component Object Model | 1 Clipboard Data | 12 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Masquerading | LSA Secrets | 1 System Network Configuration Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Virtualization/Sandbox Evasion | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Access Token Manipulation | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 11 Process Injection | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1338492 | ||
18% | ReversingLabs | |||
16% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | Virustotal | Browse | ||
0% | ReversingLabs | |||
1% | Virustotal | Browse | ||
0% | ReversingLabs | |||
0% | Virustotal | Browse | ||
0% | ReversingLabs | |||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ip-api.com | 208.95.112.1 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
208.95.112.1 | ip-api.com | United States | 53334 | TUT-ASUS | true | |
185.222.58.113 | unknown | Netherlands | 51447 | ROOTLAYERNETNL | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1465162 |
Start date and time: | 2024-07-01 12:06:54 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 15m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301 |
Run name: | Suspected Instruction Hammering |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 004552024107.bat.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@3/17@1/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, backgroundTaskHost.exe, svchost.exe
- Execution Graph export aborted for target 004552024107.bat.exe, PID 7736 because it is empty
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
208.95.112.1 | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Blackshades, DarkTortilla, Quasar | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, DCRat, XWorm | Browse |
| ||
185.222.58.113 | Get hash | malicious | GuLoader | Browse |
| |
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ip-api.com | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Blackshades, DarkTortilla, Quasar | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, DCRat, XWorm | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ROOTLAYERNETNL | Get hash | malicious | GuLoader | Browse |
| |
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
TUT-ASUS | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Blackshades, DarkTortilla, Quasar | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, DCRat, XWorm | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\nsr10C0.tmp\BgImage.dll | Get hash | malicious | GuLoader | Browse | ||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
C:\Users\user\AppData\Local\Temp\nsr10C0.tmp\System.dll | Get hash | malicious | GuLoader | Browse | ||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | FormBook, GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | FormBook, GuLoader | Browse | |||
Get hash | malicious | GuLoader | Browse |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 49 |
Entropy (8bit): | 4.75216571132969 |
Encrypted: | false |
SSDEEP: | 3:a6QLQIfLBJXlFGfv:xQkIPeH |
MD5: | 797DA95245047A54F125FBF3B19FA295 |
SHA1: | 9E46F51C033836343C4099609F35B9B62C290A00 |
SHA-256: | A047914D1DB23829E36D3A2A908D83F4B51F5A8194AE090BB9F9AB9F8DDA9128 |
SHA-512: | 4755C72A469C7C816D7B4A08BFEABFC266AAD029156A301E2592E3AFD16C5DB5FCE44C4475CB83C43B859A06AD069370182FCA5CAFACF4A27D191F4C0AE34A03 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7680 |
Entropy (8bit): | 5.188410641489526 |
Encrypted: | false |
SSDEEP: | 96:8eQMA6z4f7TI20Y1wircawlkX1b3+LDfbAJ8uLzqkLnLiEQjJ3KxkP:tChfHv08wocw3+e8uLmyLpmP |
MD5: | 2D5F40DDC34E9DC8F43B5BF1F61301E3 |
SHA1: | 5ED3CD47AFFC4D55750E738581FCE2B40158C825 |
SHA-256: | 785944E57E8E4971F46F84A07D82DEE2AB4E14A68543D83BFE7BE7D5CDA83143 |
SHA-512: | 605CEBCC480CB71BA8241782D89E030A5C01E1359ACCBDE174CB6BDAF249167347ECB06E3781CB9B1CC4B465CEF95F1663F0D9766ED84EBADE87AA3970765B3E |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 5.744994954995265 |
Encrypted: | false |
SSDEEP: | 192:gFiQJ77pJp17C8F1A5xjGNxrgFOgb7lrT/nC93:E7pJp48F2exrg5F/C |
MD5: | 12B140583E3273EE1F65016BECEA58C4 |
SHA1: | 92DF24D11797FEFD2E1F8D29BE9DFD67C56C1ADA |
SHA-256: | 014F1DFEB842CF7265A3644BC6903C592ABE9049BFC7396829172D3D72C4D042 |
SHA-512: | 49FFDFA1941361430B6ACB3555FD3AA05E4120F28CBDF7CEAA2AF5937D0B8CCCD84471CF63F06F97CF203B4AA20F226BDAD082E9421B8E6B62AB6E1E9FC1E68A |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4096 |
Entropy (8bit): | 3.327532764383977 |
Encrypted: | false |
SSDEEP: | 48:qKNKyd+Z46pHT1wHsl9rEGbgPgVZShMmj3OPRYBA:5JSRzuHsxE4VH6O+i |
MD5: | 90228DD140188EC0CA02F7F52E4C9A30 |
SHA1: | 6880D9AEEC4C97C4B7718044C9C59B92379FEACA |
SHA-256: | 54BCF3D018734B884BD33A74A05EEA0AC3C83501ACBDB71EA8EC56EC9402A263 |
SHA-512: | 1A38B1EBB9E2440DD240C8CD2406261E21B544ED392F808D36F78590075F854D89E624589BFDDABCACE96B33A7F3084C7686351BD66AE07EC035BBEF94EF8DA2 |
Malicious: | false |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6656 |
Entropy (8bit): | 5.178709395875687 |
Encrypted: | false |
SSDEEP: | 96:z0OBtYZKtPsrqBApt1JHpb9XWk7Qe06iE6mE6YNFyVOHd0+uPHwEX:4tZKtrAJJJbP7iEHEbN8Ved0Ph |
MD5: | 4A2F4FE4A3AD1DE56EE6BF7DD4923963 |
SHA1: | 7CC68B94448C964FD99904E5784B059AED4D5DAA |
SHA-256: | 89B1E6509A1B45B32933E9D785A9C8C5B9CE7C616E1112DCF7FC3FA5CA27EBDE |
SHA-512: | 4B6BBE75BEAFAE9A29932FF5DDD3940AADFAE62C157836E6CDAB755955782DD5354D5EB389B4B8C16BF59F4CE7A099A0161D915C1CF2968F28E195DC8E3997EA |
Malicious: | false |
Antivirus: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 4.163856189774724 |
Encrypted: | false |
SSDEEP: | 3:+gMn:8 |
MD5: | ECB33F100E1FCA0EB01B36757EF3CAC8 |
SHA1: | 61DC848DD725DB72746E332D040A032C726C9816 |
SHA-256: | 8734652A2A9E57B56D6CBD22FA9F305FC4691510606BCD2DFCA248D1BF9E79C7 |
SHA-512: | D56951AC8D3EB88020E79F4581CB9282CA40FAA8ADC4D2F5B8864779E28E5229F5DFE13096CF4B373BBC9BC2AC4BFC58955D9420136FB13537F11C137D633C18 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3011 |
Entropy (8bit): | 4.875614577841428 |
Encrypted: | false |
SSDEEP: | 48:Sl+lWlUMDNbr6641SO9Agz4x2qEtyTgz0gWP5CZ9sam0uxKKhY7SDEf:W+lLMDNbr6641S0z4xFEITggV+9zXa3Q |
MD5: | 6103DF2AF52F53D95AF61664D1866FFE |
SHA1: | 6AD99D4586667B497725EEC01AE0A772C441C1D4 |
SHA-256: | 6AA446B014371D8DD9EF43D2A103E9CA8A0F61A3AFC4676BFC63AD07C1977C7E |
SHA-512: | 2AFA117DD3ACB8B695FFBC0F236E8B87F1DD4A7EAFD79A26CB4F191EED76DEBA7CBB106F3E78218769581C014840D039A4E173340CA0D6C2D2DFF0B5C5138096 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3794 |
Entropy (8bit): | 4.876163305802233 |
Encrypted: | false |
SSDEEP: | 96:LnmpgKl8MI0hs4Qnu6lgB+EQFO+trNMgUIkR:7UpaMI34iu6eBdwO+8rIkR |
MD5: | 0629DF955F60990975A3C8EF199B57E9 |
SHA1: | FE57FA7FDF44B6E789A760C5292FD8DAE221187B |
SHA-256: | 499908BD96C7F2D9BC0F94433CC14C482C002C07A09DF0D73AF45BC17C4DA70B |
SHA-512: | 753EB2360926F32A6ED70E034FEAA57D6274756C3CE60914A4A1EC12DC07ACAC92C7906E3FE48A76F74BBEFBE8EAC023D352D11A087F47DEE9BD0ACBB59331F8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\semes\Dispurse\chokoladeforretning.mar
Download File
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3861 |
Entropy (8bit): | 4.8950653795254695 |
Encrypted: | false |
SSDEEP: | 96:GKEfl8Ry/OyCvfcyh5ph9whBJQRaTYbEVr1wbd:MfObXc2h9iQUDZ1y |
MD5: | 2B5A33F2637CE6016495BE603413514E |
SHA1: | 571279989D47FF42C2974CDEDEA4C872CB9424CF |
SHA-256: | 46F41A0D8B9B891702F9ED2FB60FF737A2275011882501155B710EF9BA8577C7 |
SHA-512: | F55FE759C0DF2E8B9E38962E386BEB468FD4442714233F5A5DD13CA10647411FD62D966D8363FE50568F15525EEE815493AEDEF112A6FA6FA0B506A97AF21CF6 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3435 |
Entropy (8bit): | 4.910328234136937 |
Encrypted: | false |
SSDEEP: | 48:P/sA7KBdAWdry+HEnrwU7j9mS/QwZ/kQMlzuVm+aAIBzx396upw/QAa/rl0:sA70/BEwy9D/XDVtIBzx3oupIa/6 |
MD5: | 4A27BE5B33E9690FFCC4087DE6B78DE1 |
SHA1: | 808A634035F94A20441F52F413777897DFD7D3E0 |
SHA-256: | CA6742E9E11A6E3008BAE84674451A7228E0E79F53A34235269984EFAE996C72 |
SHA-512: | 6D4114A7DCF410C531465AEE6802A3A0A965864DD4AE65E304188931D17C394B3A700DA6558CCB2BF37AA99906D34A1E38E7CF62E655A6E2EAC3E5CDC38449E9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\semes\Dispurse\hmoriderne.ner
Download File
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1618 |
Entropy (8bit): | 4.660461986408 |
Encrypted: | false |
SSDEEP: | 48:mV2wmwMfFEXBaoCpI1sCEVHQTtlgJtScnbhH7D:maNK/0IOQjgJhx |
MD5: | 5A5EB5C7789F88A3DCC3F79DB0AA1A49 |
SHA1: | E67C28DEF4C59F267095C50C6A571AB5B65A9D04 |
SHA-256: | 3A7318B3E11D39D783BA8BCCCAD3541B6896A03B1533E4F189DFD1CCC2FF40CE |
SHA-512: | 9762CD2524E971CF672D8DD8F46F4E7EE3F0FF5D91D11801AECB135DF9FBA6FC93D5FCC131879C1D3A81F2734AC5D6E07016E6CEC131A5F51C54CFE0664D0238 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2322 |
Entropy (8bit): | 4.685927571910316 |
Encrypted: | false |
SSDEEP: | 48:hKk/USLt/YV/KNG2/Jddel368ugS8jMMccq3mtjzlrNiNviupW9:hb/USL1YV/K/TdeQ8jMMcYn3Opq |
MD5: | C4A322BD2B1B0FD5130E2119EBE14A09 |
SHA1: | 4C0F0F8AAC954E9D599F8C89B340F5C3C4742A6B |
SHA-256: | 063D6E2970210F7A4C74FE744AD76E71650AB5CB974EE4A9AF2BF446D6B2B3BF |
SHA-512: | 64FCE5DC8E510DCCAEA30E2BDB0671C706CECFB4AEC19ECD5B6326E4EE4B1B33A422E917A522F0CFCA184007ABE2B9D89EA401757A637D8D3DFA4B156E58A04A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\semes\Dispurse\materialiter.sig
Download File
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2438 |
Entropy (8bit): | 4.834166284053989 |
Encrypted: | false |
SSDEEP: | 48:QMQ2WErZ2pGC24S3HorZ9JAGA8jkcrbs1DHkkkIq/iSlcHKMVi:X59ys3HorNAGArcr2c/WKWi |
MD5: | 6C88CA43B6FA2E51F1BE781CDF1A7C3E |
SHA1: | 85E53052FFFD4D9AB7FD255A39628FB9D9A4C57D |
SHA-256: | 87747776DBB97E3892F3B4FE2507A907737E3E01F94F88B0D0ED7D849EFD31CF |
SHA-512: | 4B12F969637C61A8F6E1EF79DB3D54DC076672E35B1F67B9742F3B99A38F933298E2DB262A5DB487E281B85BF37FF74FB036E5C5AA3D6844B2D8AC0937B0F483 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\semes\Dispurse\preinvest.pri
Download File
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3194 |
Entropy (8bit): | 4.87998401204962 |
Encrypted: | false |
SSDEEP: | 48:rpEyDeY5QtYx201GaEtVnQvy5Dv6Z3JIV50tFh1FrDopL0AHmEMAaovQIS+GO/m+:fDeATGaETkd5J8e51xMYOey/mgRbP |
MD5: | 73DC0D944FBB5219CEDD966AF6EBB2C8 |
SHA1: | 24D17D23C94CFC76FEF577CAF82C6D45B6125591 |
SHA-256: | 3C2F20CCCBB8EEC2F5B2A70E44EC1631BFC8070C2F5A9198F1096563A8D0FA52 |
SHA-512: | 72FE2BEEAFE7F5296FA346947E0BE3824B934545A299BFCB4AEBA9BD095AA7A2756E42C9D88E5DDDD072C931D35075AED7C7D4E3B641F74A62C96E150C573E4F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\semes\Fremlejerettigheders.Obs
Download File
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 19688 |
Entropy (8bit): | 4.57419794786777 |
Encrypted: | false |
SSDEEP: | 384:9mEn22k3XHa6wRTaW/Xm0FWEvUa/l30tg1QLaQ5C5oqfAYCbMxR6+qXC:Bn2EhIWfmeWEv710tu4aQU5PAbURNqXC |
MD5: | 273CDC09B4C6F6FC62AEED137F930215 |
SHA1: | A0827F97608DD238378B778E78856702ED0D10DD |
SHA-256: | 956F72DE5BA50373A0874BC6E1C0A384F577717A714AB2DFB7E8BBF92ED17948 |
SHA-512: | AB719201B05FEAF1CDF80CF7401881BEF7B3CA10099F3CEC56564AC138646F7F18F4E2168B7A126A7D1D17B13A5A2364DF40E9803C2BE45AD6BD6B68282AAE48 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285616 |
Entropy (8bit): | 7.475859044066169 |
Encrypted: | false |
SSDEEP: | 6144:69KjF+6cBI3TtysXA/6esHSNP0hhOcAC7MCUIR/TSyZE64Rs6h:F+23TtysXAyesyChaC4CUq/ewE6as6h |
MD5: | CEFA658707E7A791B2B511C9EA49B3D4 |
SHA1: | E11BCC2D8C7420ABA072F8D1A621C42E0F7C57D6 |
SHA-256: | BEEDB3FC08045986A4DFEBCD65167B07DF7F0F457647CC02EF186E0A865198FF |
SHA-512: | A30EA178CEA14E837F52ACC2A966C77FB78B2D9090CE981A58943CABF5E72C0899BAABBF8B05E08A858A9D3034B7C63F87288CEDEC8378C862002EBF6735E0E2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\semes\Storfyrstindes\ridningen.txt
Download File
Process: | C:\Users\user\Desktop\004552024107.bat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 434 |
Entropy (8bit): | 4.287029634434794 |
Encrypted: | false |
SSDEEP: | 12:THnAEO/X/lz5Qxq70QPiETlsieWr5hmhAZYOua3Jy6:kt5CqtPT7rUk3f |
MD5: | D831A4A6C7B8B672C51DC73C42BF1B99 |
SHA1: | 2EFA4039C5CBBE38D45B65CFCD8CB283B0B00F6F |
SHA-256: | 57B3854CDF7B15EB58BFD24E92F41E8B4A513F9A413E7981891B71F5BD56F4B8 |
SHA-512: | D5920BC02B61C18C83CE48D41AE1777F50685766A60CCB6C53161B25E3AFB34A1DDB0E8710C37E3B8B050F772E3EAB3A65FB4ACB093AEFD55AA2FDA74EC6C8F7 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.479739164331005 |
TrID: |
|
File name: | 004552024107.bat.exe |
File size: | 530'814 bytes |
MD5: | 2d40c2aefef620e7fb177f0cf24d8ea5 |
SHA1: | d4b00320d6be1ecac0fc016f1ad85a9774c14f47 |
SHA256: | 576421830912fcb3f31f2721cb30607a7c07887a1558a80b626e0d9527467399 |
SHA512: | 64e27276ffd6c44ac9572f0aed7367a004b8ee83e528518c607a39934329f54fac797b7c45e0dcc6c25c64b11fcb8b2f1ad21078ed4e3714ac61c0ba1e17fc70 |
SSDEEP: | 12288:c19+dlfwYKZWegejzeusXEBS/PKPU6E0nn7+nJiPP:PdloYK7geveN0fPRnqnJi |
TLSH: | 0BB4DF13F723C8EBDA7D13F1A992C67B2EE415195DB1D0DDE3E5AE473000A262B09369 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........(...F...F...F.*.....F...G.w.F.*.....F...v...F...@...F.Rich..F.........PE..L....C.f.................h...x.......3............@ |
Icon Hash: | eb9b9b2bbb9be371 |
Entrypoint: | 0x4033d8 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x660843F9 [Sat Mar 30 16:55:21 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 671f2a1f8aee14d336bab98fea93d734 |
Instruction |
---|
push ebp |
mov ebp, esp |
sub esp, 00000224h |
push esi |
push edi |
xor edi, edi |
push 00008001h |
mov dword ptr [ebp-14h], edi |
mov dword ptr [ebp-0Ch], 0040A188h |
mov dword ptr [ebp-08h], edi |
mov byte ptr [ebp-04h], 00000020h |
call dword ptr [0040809Ch] |
mov esi, dword ptr [004080A0h] |
lea eax, dword ptr [ebp-000000C4h] |
push eax |
mov dword ptr [ebp-000000B0h], edi |
mov dword ptr [ebp-30h], edi |
mov dword ptr [ebp-2Ch], edi |
mov dword ptr [ebp-000000C4h], 0000009Ch |
call esi |
test eax, eax |
jne 00007FC21864A071h |
lea eax, dword ptr [ebp-000000C4h] |
mov dword ptr [ebp-000000C4h], 00000094h |
push eax |
call esi |
cmp dword ptr [ebp-000000B4h], 02h |
jne 00007FC21864A05Ch |
movsx cx, byte ptr [ebp-000000A3h] |
mov al, byte ptr [ebp-000000B0h] |
sub ecx, 30h |
sub al, 53h |
mov byte ptr [ebp-2Ah], 00000004h |
neg al |
sbb eax, eax |
not eax |
and eax, ecx |
mov word ptr [ebp-30h], ax |
cmp dword ptr [ebp-000000B4h], 02h |
jnc 00007FC21864A054h |
and byte ptr [ebp-2Ah], 00000000h |
cmp byte ptr [ebp-000000AFh], 00000041h |
jl 00007FC21864A043h |
movsx ax, byte ptr [ebp-000000AFh] |
sub eax, 40h |
mov word ptr [ebp-30h], ax |
jmp 00007FC21864A036h |
mov word ptr [ebp-30h], di |
cmp dword ptr [ebp-000000C0h], 0Ah |
jnc 00007FC21864A03Ah |
and word ptr [ebp+00000000h], 0000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x853c | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x43000 | 0x33c30 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8000 | 0x294 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x660c | 0x6800 | 3b90adcd2f1248db844446cb2ef15486 | False | 0.6663912259615384 | data | 6.411908920093797 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8000 | 0x1340 | 0x1400 | b3bd9ad1bd1020c5cf4d51a4d7b61e07 | False | 0.4576171875 | data | 5.237673976044139 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x25138 | 0x600 | c4e774255fea540ed5efa114edfa6420 | False | 0.4635416666666667 | data | 4.1635686587741 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x30000 | 0x13000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x43000 | 0x33c30 | 0x33e00 | 7fa7729fe4a0557bfedd7b90570ef402 | False | 0.497632718373494 | data | 6.34541536700329 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x43388 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 65536 | English | United States | 0.30904708387554714 |
RT_ICON | 0x53bb0 | 0xb761 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States | 0.9867930557034827 |
RT_ICON | 0x5f318 | 0x94a8 | Device independent bitmap graphic, 96 x 192 x 32, image size 36864 | English | United States | 0.3459112886272861 |
RT_ICON | 0x687c0 | 0x5488 | Device independent bitmap graphic, 72 x 144 x 32, image size 20736 | English | United States | 0.391913123844732 |
RT_ICON | 0x6dc48 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16384 | English | United States | 0.4092465753424658 |
RT_ICON | 0x71e70 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | English | United States | 0.4437759336099585 |
RT_ICON | 0x74418 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | English | United States | 0.5302532833020638 |
RT_ICON | 0x754c0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | English | United States | 0.6196721311475409 |
RT_ICON | 0x75e48 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | English | United States | 0.6524822695035462 |
RT_DIALOG | 0x762b0 | 0x100 | data | English | United States | 0.5234375 |
RT_DIALOG | 0x763b0 | 0x11c | data | English | United States | 0.6056338028169014 |
RT_DIALOG | 0x764d0 | 0xc4 | data | English | United States | 0.5918367346938775 |
RT_DIALOG | 0x76598 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0x765f8 | 0x84 | data | English | United States | 0.9242424242424242 |
RT_VERSION | 0x76680 | 0x270 | data | English | United States | 0.5016025641025641 |
RT_MANIFEST | 0x768f0 | 0x33e | XML 1.0 document, ASCII text, with very long lines (830), with no line terminators | English | United States | 0.5542168674698795 |
DLL | Import |
---|---|
ADVAPI32.dll | RegEnumValueA, RegEnumKeyA, RegQueryValueExA, RegSetValueExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA, AdjustTokenPrivileges, LookupPrivilegeValueA, OpenProcessToken, RegOpenKeyExA, RegCreateKeyExA |
SHELL32.dll | SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, SHFileOperationA, ShellExecuteExA |
ole32.dll | OleUninitialize, OleInitialize, IIDFromString, CoCreateInstance, CoTaskMemFree |
COMCTL32.dll | ImageList_Destroy, ImageList_AddMasked, ImageList_Create |
USER32.dll | SetDlgItemTextA, GetSystemMetrics, CreatePopupMenu, AppendMenuA, OpenClipboard, EmptyClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcA, GetMessagePos, CheckDlgButton, LoadCursorA, SetCursor, GetSysColor, SetWindowPos, GetWindowLongA, IsWindowEnabled, SetClassLongA, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassA, SystemParametersInfoA, CreateWindowExA, GetDlgItemTextA, DialogBoxParamA, CharNextA, ExitWindowsEx, DestroyWindow, CreateDialogParamA, SetTimer, SetWindowTextA, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfA, SendMessageTimeoutA, FindWindowExA, IsWindow, GetDlgItem, SetWindowLongA, LoadImageA, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndPaint, MessageBoxIndirectA, CharPrevA, PeekMessageA, GetClassInfoA, DispatchMessageA, TrackPopupMenu |
GDI32.dll | GetDeviceCaps, SetBkColor, SelectObject, DeleteObject, CreateBrushIndirect, CreateFontIndirectA, SetBkMode, SetTextColor |
KERNEL32.dll | CreateFileA, GetTempFileNameA, ReadFile, RemoveDirectoryA, CreateProcessA, CreateDirectoryA, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceA, lstrcpynA, SetErrorMode, GetVersionExA, lstrlenA, GetCommandLineA, GetTempPathA, GetWindowsDirectoryA, WriteFile, ExitProcess, CopyFileA, GetCurrentProcess, GetModuleFileNameA, GetFileSize, GetTickCount, Sleep, SetFileAttributesA, GetFileAttributesA, SetCurrentDirectoryA, MoveFileA, GetFullPathNameA, GetShortPathNameA, SearchPathA, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiA, lstrcmpA, ExpandEnvironmentStringsA, GlobalFree, GlobalAlloc, GetModuleHandleA, LoadLibraryExA, FreeLibrary, MultiByteToWideChar, WritePrivateProfileStringA, GetPrivateProfileStringA, SetFilePointer, FindClose, FindNextFileA, FindFirstFileA, DeleteFileA, MulDiv, lstrcpyA, MoveFileExA, lstrcatA, WideCharToMultiByte, GetSystemDirectoryA, GetProcAddress, GetExitCodeProcess, WaitForSingleObject, SetEnvironmentVariableA |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 1, 2024 12:09:16.106811047 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.328394890 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.328717947 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.329804897 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.551577091 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.551656008 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.551717997 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.551749945 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.551808119 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.551832914 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.551881075 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.551981926 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.773330927 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773405075 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773461103 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773525953 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773576975 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.773653984 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.773699999 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773722887 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.773785114 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773840904 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773897886 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.773902893 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.773942947 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.773977995 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.774008036 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.774100065 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.995491982 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.995583057 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.995642900 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.995697021 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.995742083 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.995748043 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.995809078 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.995843887 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.995887995 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.995908976 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.995964050 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996018887 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996052027 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996095896 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996151924 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996247053 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996287107 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996328115 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996382952 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996392965 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996457100 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996480942 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996534109 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996545076 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996607065 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996623993 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996685028 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996793032 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:16.996803045 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:16.996848106 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.218313932 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.218493938 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.218616962 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.218689919 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.218748093 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.218772888 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.218828917 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.218862057 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.218908072 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.218940020 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.218986988 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219043970 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219099998 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219147921 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219173908 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219199896 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219239950 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219264984 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219316959 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219342947 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219396114 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219451904 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219506979 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219515085 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219563961 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219599962 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219660044 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219665051 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219719887 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219749928 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219805956 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219861984 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219888926 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.219939947 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.219944954 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220010042 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220017910 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220083952 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220096111 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220156908 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220251083 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220268011 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220316887 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220347881 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220395088 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220421076 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220478058 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220489025 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220554113 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220609903 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220654964 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220680952 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220707893 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220757008 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220786095 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220833063 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.220871925 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.220905066 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.221009970 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.442384958 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442461014 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442595005 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442652941 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442704916 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.442740917 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442751884 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.442820072 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442831039 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.442884922 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.442908049 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.442962885 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443017960 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443038940 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443094969 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443116903 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443182945 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443193913 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443259001 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443314075 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443361998 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443384886 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443414927 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443461895 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443492889 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443537951 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443571091 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443614006 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443667889 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443701029 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443746090 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443756104 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443821907 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443831921 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443897009 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.443907976 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.443970919 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444011927 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444042921 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444098949 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444144011 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444191933 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444212914 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444258928 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444313049 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444369078 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444417953 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444447994 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444468021 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444523096 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444549084 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444611073 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444622993 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444685936 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444726944 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444757938 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444792032 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444833994 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444870949 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444910049 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.444948912 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.444987059 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445043087 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445079088 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445133924 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445157051 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445213079 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445223093 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445288897 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445300102 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445364952 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445420027 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445430994 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445477962 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445513964 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445533991 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445590019 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445625067 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445666075 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445722103 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445755005 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445796967 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445807934 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445872068 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445883989 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.445945978 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.445962906 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446021080 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446062088 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446079016 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446139097 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446145058 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446208954 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446224928 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446288109 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446300030 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446362019 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446403980 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446434975 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446469069 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446511030 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446547985 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446587086 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446625948 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446662903 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446718931 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446755886 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446794987 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446806908 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446867943 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446887970 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.446943998 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.446964979 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.447020054 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.447074890 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.447083950 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.447149038 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.447160006 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.447223902 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.447236061 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.447284937 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.447314978 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.447432995 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668533087 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668549061 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668590069 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668616056 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668646097 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668675900 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668680906 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668680906 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668699026 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668709040 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668718100 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668824911 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668824911 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668859959 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668873072 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668884993 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668911934 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668939114 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668988943 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668992043 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.668992996 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.668992996 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669161081 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669161081 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669162035 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669162035 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669162989 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669162989 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669207096 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.669354916 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.669416904 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669416904 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669418097 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669418097 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669419050 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669419050 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669420004 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669420004 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669420958 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669420958 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669421911 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669421911 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669423103 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669423103 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669428110 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669575930 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.669584990 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669660091 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.669735909 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.669758081 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669758081 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669759035 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669759035 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669759989 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669760942 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669760942 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669761896 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669761896 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669763088 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669763088 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669764042 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669764042 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669764042 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669765949 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669778109 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669789076 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669836044 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.669926882 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669929028 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669929981 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669929981 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669930935 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669930935 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669931889 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669931889 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669933081 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669933081 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669934034 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669934034 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.669934988 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:09:17.670003891 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.670121908 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:17.670226097 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:09:20.686219931 CEST | 49778 | 80 | 192.168.11.20 | 208.95.112.1 |
Jul 1, 2024 12:09:20.820122957 CEST | 80 | 49778 | 208.95.112.1 | 192.168.11.20 |
Jul 1, 2024 12:09:20.820403099 CEST | 49778 | 80 | 192.168.11.20 | 208.95.112.1 |
Jul 1, 2024 12:09:20.820651054 CEST | 49778 | 80 | 192.168.11.20 | 208.95.112.1 |
Jul 1, 2024 12:09:21.012829065 CEST | 80 | 49778 | 208.95.112.1 | 192.168.11.20 |
Jul 1, 2024 12:09:21.068262100 CEST | 49778 | 80 | 192.168.11.20 | 208.95.112.1 |
Jul 1, 2024 12:09:52.595114946 CEST | 80 | 49778 | 208.95.112.1 | 192.168.11.20 |
Jul 1, 2024 12:09:52.595479012 CEST | 49778 | 80 | 192.168.11.20 | 208.95.112.1 |
Jul 1, 2024 12:10:26.591917038 CEST | 80 | 49778 | 208.95.112.1 | 192.168.11.20 |
Jul 1, 2024 12:11:06.092231989 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Jul 1, 2024 12:11:06.313710928 CEST | 80 | 49777 | 185.222.58.113 | 192.168.11.20 |
Jul 1, 2024 12:11:06.313909054 CEST | 49777 | 80 | 192.168.11.20 | 185.222.58.113 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 1, 2024 12:09:20.512279987 CEST | 53095 | 53 | 192.168.11.20 | 1.1.1.1 |
Jul 1, 2024 12:09:20.631547928 CEST | 53 | 53095 | 1.1.1.1 | 192.168.11.20 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jul 1, 2024 12:09:20.512279987 CEST | 192.168.11.20 | 1.1.1.1 | 0x5101 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 1, 2024 12:09:20.631547928 CEST | 1.1.1.1 | 192.168.11.20 | 0x5101 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.11.20 | 49777 | 185.222.58.113 | 80 | 7736 | C:\Users\user\Desktop\004552024107.bat.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jul 1, 2024 12:09:16.329804897 CEST | 178 | OUT | |
Jul 1, 2024 12:09:16.551577091 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.551656008 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.551717997 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.551832914 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773330927 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773405075 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773461103 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773525953 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773699999 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773785114 CEST | 1289 | IN | |
Jul 1, 2024 12:09:16.773840904 CEST | 1289 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.11.20 | 49778 | 208.95.112.1 | 80 | 7736 | C:\Users\user\Desktop\004552024107.bat.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jul 1, 2024 12:09:20.820651054 CEST | 80 | OUT | |
Jul 1, 2024 12:09:21.012829065 CEST | 174 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 06:08:57 |
Start date: | 01/07/2024 |
Path: | C:\Users\user\Desktop\004552024107.bat.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 530'814 bytes |
MD5 hash: | 2D40C2AEFEF620E7FB177F0CF24D8EA5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 06:09:08 |
Start date: | 01/07/2024 |
Path: | C:\Users\user\Desktop\004552024107.bat.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 530'814 bytes |
MD5 hash: | 2D40C2AEFEF620E7FB177F0CF24D8EA5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 20.9% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 16.2% |
Total number of Nodes: | 1546 |
Total number of Limit Nodes: | 39 |
Graph
Function 004033D8 Relevance: 91.4, APIs: 32, Strings: 20, Instructions: 430stringfilecomCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040550F Relevance: 54.3, APIs: 36, Instructions: 282windowclipboardmemoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405A4F Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 159filestringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A43 Relevance: 3.0, APIs: 2, Instructions: 30stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403A96 Relevance: 45.7, APIs: 13, Strings: 13, Instructions: 215stringregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402F31 Relevance: 26.4, APIs: 5, Strings: 10, Instructions: 181memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406320 Relevance: 19.5, APIs: 6, Strings: 5, Instructions: 208stringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040177E Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 147stringtimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004053D1 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 73stringwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406647 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 36libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004024A3 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 64registrystringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406174 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 44registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BAC Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 72memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402318 Relevance: 4.6, APIs: 3, Instructions: 51stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405897 Relevance: 3.0, APIs: 2, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401EEA Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405926 Relevance: 3.0, APIs: 2, Instructions: 24processCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405E20 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004058F1 Relevance: 3.0, APIs: 2, Instructions: 9COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6C602AC8 Relevance: 1.6, APIs: 1, Instructions: 143COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040269A Relevance: 1.6, APIs: 1, Instructions: 76COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040168F Relevance: 1.5, APIs: 1, Instructions: 38fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402758 Relevance: 1.5, APIs: 1, Instructions: 28COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004023C9 Relevance: 1.5, APIs: 1, Instructions: 26COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405EC7 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405E98 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6C6029B1 Relevance: 1.5, APIs: 1, Instructions: 21memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040240D Relevance: 1.5, APIs: 1, Instructions: 20COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004015C2 Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404379 Relevance: 1.5, APIs: 1, Instructions: 9windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404362 Relevance: 1.5, APIs: 1, Instructions: 6windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405969 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403390 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040434F Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401FA0 Relevance: 1.3, APIs: 1, Instructions: 37COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004014D6 Relevance: 1.3, APIs: 1, Instructions: 19sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C4A Relevance: 1.3, APIs: 1, Instructions: 10COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004047BF Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 274stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6C601B28 Relevance: 20.1, APIs: 13, Instructions: 591stringlibrarymemoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406AFA Relevance: .3, Instructions: 334COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004072D1 Relevance: .3, Instructions: 300COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404D32 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 491windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404498 Relevance: 38.7, APIs: 19, Strings: 3, Instructions: 202windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405EF6 Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 129memorystringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404394 Relevance: 12.1, APIs: 8, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6C602568 Relevance: 10.6, APIs: 7, Instructions: 111COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404C80 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402E4A Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 40timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401D8A Relevance: 7.6, APIs: 5, Instructions: 75windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401C53 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowtimeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404B76 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405D0D Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 46stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C1F Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402ECD Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C66 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6C6010E0 Relevance: 5.1, APIs: 4, Instructions: 144memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405D85 Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB1AE8 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015F15B Relevance: 4.0, Strings: 3, Instructions: 284COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB5DA8 Relevance: 3.0, Strings: 2, Instructions: 474COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001588F8 Relevance: 2.8, Instructions: 2828COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015EA08 Relevance: 2.7, Strings: 2, Instructions: 213COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001589B0 Relevance: 2.4, Instructions: 2415COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015BB68 Relevance: 2.4, Instructions: 2385COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015BF10 Relevance: 2.0, Instructions: 1953COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB3C20 Relevance: 1.8, Strings: 1, Instructions: 590COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB4610 Relevance: .8, Instructions: 808COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BBA5E0 Relevance: .6, Instructions: 636COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB9270 Relevance: .6, Instructions: 569COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00154910 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001538F8 Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB8D18 Relevance: 10.4, Strings: 8, Instructions: 387COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BBB398 Relevance: 7.0, Strings: 5, Instructions: 796COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB7188 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB31F0 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015F470 Relevance: 2.7, Strings: 2, Instructions: 172COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB7178 Relevance: 2.7, Strings: 2, Instructions: 167COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB31E0 Relevance: 2.6, Strings: 2, Instructions: 139COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015E068 Relevance: 1.6, Strings: 1, Instructions: 305COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015F770 Relevance: 1.4, Strings: 1, Instructions: 191COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00155080 Relevance: 1.4, Strings: 1, Instructions: 184COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB0858 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB0849 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00155C68 Relevance: 1.4, Strings: 1, Instructions: 102COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00155C88 Relevance: 1.3, Strings: 1, Instructions: 97COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB6327 Relevance: 1.3, Strings: 1, Instructions: 30COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB30D9 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001562C8 Relevance: .6, Instructions: 559COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB184D Relevance: .4, Instructions: 392COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015812C Relevance: .4, Instructions: 376COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001584A8 Relevance: .4, Instructions: 359COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151168 Relevance: .3, Instructions: 282COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00154905 Relevance: .3, Instructions: 262COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001538ED Relevance: .2, Instructions: 235COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2920 Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2C40 Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2C58 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB3A98 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015EF4F Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015EF60 Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015F761 Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB3C11 Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00152154 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB0708 Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB0718 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00152160 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00158019 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2529 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151520 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2538 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00158028 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001516F8 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00157B10 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00154E04 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000AD01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00157B20 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151708 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151530 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB4D30 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00154E10 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015E888 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015EBF9 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00150839 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00150848 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2648 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151480 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151640 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2883 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015EEA0 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015E750 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000AD017 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2300 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151490 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BBD1DF Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2308 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2890 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB2639 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB834F Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BBD1F0 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB8360 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BBAC28 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001553E1 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015E37D Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015EC68 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB8F68 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015E479 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015E488 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004033D8 Relevance: 77.4, APIs: 32, Strings: 12, Instructions: 430stringfilecomCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405A4F Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 159filestringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB56C0 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404D32 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 491windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040550F Relevance: 54.3, APIs: 36, Instructions: 282windowclipboardmemoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403A96 Relevance: 37.0, APIs: 13, Strings: 8, Instructions: 215stringregistryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404498 Relevance: 37.0, APIs: 19, Strings: 2, Instructions: 202windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405EF6 Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 129memorystringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004047BF Relevance: 19.5, APIs: 10, Strings: 1, Instructions: 274stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402F31 Relevance: 19.4, APIs: 5, Strings: 6, Instructions: 181memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406320 Relevance: 14.2, APIs: 6, Strings: 2, Instructions: 208stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404394 Relevance: 12.1, APIs: 8, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404C80 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402E4A Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 40timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406647 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 36libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB8980 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB50B8 Relevance: 7.9, Strings: 6, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB9E60 Relevance: 7.7, Strings: 6, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401D8A Relevance: 7.6, APIs: 5, Instructions: 75windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401E5A Relevance: 7.5, APIs: 5, Instructions: 43COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401C53 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowtimeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404B76 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402ECD Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB6408 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB6820 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 37BB8D08 Relevance: 5.2, Strings: 4, Instructions: 160COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405D85 Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|