Click to jump to signature section
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9C680Q69\apt66ext[1].log | ReversingLabs: Detection: 18% |
Source: C:\Users\user\AppData\Local\Temp\apt66ext.exe | ReversingLabs: Detection: 18% |
Source: rkn.log.exe | Virustotal: Detection: 44% | Perma Link |
Source: rkn.log.exe | ReversingLabs: Detection: 83% |
Source: Submited Sample | Integrated Neural Analysis Model: Matched 100.0% probability |
Source: rkn.log.exe | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: rkn.log.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: C:\Users\narut\source\repos\shellcoderunner\Release\shellcoderunner.pdb source: rkn.log.exe, 00000000.00000002.2749449442.0000000000632000.00000002.00000001.01000000.00000003.sdmp, rkn.log.exe, 00000000.00000000.2090265697.0000000000632000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: T.pdb source: rkn.log.exe, 00000000.00000002.2749863604.00000000008D0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtdeclarative\lib\Qt5Quick.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtdeclarative\lib\Qt5QmlModels.pdb11 source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtwebsockets\lib\Qt5WebSockets.pdb00 source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Initial commands are read from .pdbrc files in your home directory source: staged_out.exe, 0000000C.00000002.2724820955.000002B459143000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2700896494.000002B4590A2000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2701094411.000002B459142000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp, staged_out.exe, 0000000C.00000003.2698860803.000002B4590A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ~/.pdbrcz source: staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: D:\a\opencv-python\opencv-python\_skbuild\win-amd64-3.7\cmake-build\lib\python3\Release\cv2.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C77F9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\narut\source\repos\fromshellcode\Release\fromshellcode.pdb source: rkn.log.exe, 00000000.00000002.2749981961.00000000008F3000.00000002.10000000.00040000.00000000.sdmp, rkn.log.exe, 00000000.00000002.2749883616.00000000008E0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\narut\source\repos\shellcoderunner\Release\shellcoderunner.pdb source: rkn.log.exe, 00000000.00000002.2749449442.0000000000632000.00000002.00000001.01000000.00000003.sdmp, rkn.log.exe, 00000000.00000000.2090265697.0000000000632000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtwebsockets\lib\Qt5WebSockets.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pdbrc) source: staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtdeclarative\lib\Qt5QmlModels.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: placed in the .pdbrc file): source: staged_out.exe, 0000000C.00000003.2699184004.000002B459518000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2697982942.000002B4595DD000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2696172992.000002B4594D1000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000002.2725961295.000002B4595DD000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2697034014.000002B4595DD000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtdeclarative\lib\Qt5Qml.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtsvg\lib\Qt5Svg.pdb** source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\narut\source\repos\fromshellcode\Release\fromshellcode.pdb source: rkn.log.exe, 00000000.00000002.2749981961.00000000008F3000.00000002.10000000.00040000.00000000.sdmp, rkn.log.exe, 00000000.00000002.2749883616.00000000008E0000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Widgets.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: -c are executed after commands from .pdbrc files. source: staged_out.exe, 0000000C.00000002.2724820955.000002B459143000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2700896494.000002B4590A2000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2701094411.000002B459142000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp, staged_out.exe, 0000000C.00000003.2698860803.000002B4590A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: If a file ".pdbrc" exists in your home directory or in the current source: staged_out.exe, 0000000C.00000003.2700637480.000002B45950E000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000002.2725784030.000002B4594E9000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2696172992.000002B4594D1000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2701150244.000002B4594E8000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp, staged_out.exe, 0000000C.00000002.2725812305.000002B459511000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: The standard debugger class (pdb.Pdb) is an example. source: staged_out.exe, 0000000C.00000003.2699338705.000002B4596DD000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000002.2725784030.000002B4594E9000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2698132853.000002B4596DD000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2696172992.000002B4594D1000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000003.2701150244.000002B4594E8000.00000004.00000020.00020000.00000000.sdmp, staged_out.exe, 0000000C.00000000.2687815140.00007FF76F4A7000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: C:\Users\qt\work\qt\qtsvg\lib\Qt5Svg.pdb source: apt66ext.exe, 00000007.00000003.2667985193.000001E4C8AB5000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Users\user\AppData\Local\Temp\apt66ext.exe | Code function: 7_2_00007FF679D18370 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, | 7_2_00007FF679D18370 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 05 Jul 2024 04:48:09 GMTServer: Apache/2.4.52 (Ubuntu)Last-Modified: Sat, 15 Jun 2024 22:50:22 GMTETag: "35188d0-61af58ea4068b"Accept-Ranges: bytesContent-Length: 55675088Data Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 3c b8 eb 8d 78 d9 85 de 78 d9 85 de 78 d9 85 de 33 a1 86 df 7e d9 85 de 33 a1 80 df e9 d9 85 de 33 a1 81 df 72 d9 85 de 6d a6 78 de 79 d9 85 de 6d a6 80 df 50 d9 85 de 6d a6 81 df 68 d9 85 de 6d a6 86 df 71 d9 85 de 33 a1 84 df 7f d9 85 de 78 d9 84 de 1f d9 85 de 4e 59 8c df 79 d9 85 de 4e 59 87 df 79 d9 85 de 52 69 63 68 78 d9 85 de 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 64 86 07 00 c3 fe 6d 66 00 00 00 00 00 00 00 00 f0 00 22 00 0b 02 0e 25 00 f4 01 00 00 f8 00 00 00 00 00 00 d4 b9 00 00 00 10 00 00 00 00 00 40 01 00 00 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 40 04 00 00 04 00 00 00 00 00 00 02 00 60 81 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 d4 c6 02 00 50 00 00 00 00 20 04 00 50 06 00 00 00 f0 03 00 ac 17 00 00 00 00 00 00 00 00 00 00 00 30 04 00 88 06 00 00 e0 a6 02 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 a0 a5 02 00 40 01 00 00 00 00 00 00 00 00 00 00 00 10 02 00 e0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 c0 f3 01 00 00 10 00 00 00 f4 01 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 a2 c0 00 00 00 10 02 00 00 c2 00 00 00 f8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 20 0e 01 00 00 e0 02 00 00 0c 00 00 00 ba 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 70 64 61 74 61 00 00 ac 17 00 00 00 f0 03 00 00 18 00 00 00 c6 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 5f 52 44 41 54 41 00 00 5c 01 00 00 00 10 04 00 00 02 00 00 00 de 02 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 50 06 00 00 00 20 04 00 00 08 00 00 00 e0 02 00 00 00 00 00 00 00 00 00 00 00 0 |