Click to jump to signature section
Source: 7GfciIf7ys.exe | ReversingLabs: Detection: 21% |
Source: 7GfciIf7ys.exe | Virustotal: Detection: 26% | Perma Link |
Source: Submited Sample | Integrated Neural Analysis Model: Matched 96.8% probability |
Source: 7GfciIf7ys.exe, 00000001.00000000.1393314666.00007FF7CD8FD000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: -----BEGIN PUBLIC KEY----- | memstr_f2f8fd3d-6 |
Source: 7GfciIf7ys.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: C:\Users\Eva01\source\repos\Stage3v1\x64\Release\Stage3v1.pdb source: 7GfciIf7ys.exe |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D8A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://i3p36b7sdw2gelz3jidvo6ekpzspux3susa6edaemn3gwknenmh7ofad.onion:6969/$77install.exe |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D8A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://i3p36b7sdw2gelz3jidvo6ekpzspux3susa6edaemn3gwknenmh7ofad.onion:6969/$77install.exeindows\INetCookies |
Source: 7GfciIf7ys.exe, 00000001.00000000.1393359091.00007FF7CD92E000.00000002.00000001.01000000.00000003.sdmp | String found in binary or memory: HiddenServiceDirHiddenServiceDirGroupReadable0HiddenServicePortHiddenServiceVersion-1HiddenServiceAllowUnknownPortsHiddenServiceMaxStreamsHiddenServiceMaxStreamsCloseCircuitHiddenServiceNumIntroductionPoints3HiddenServiceExportCircuitIDHiddenServiceEnableIntroDoSDefenseHiddenServiceEnableIntroDoSRatePerSec25HiddenServiceEnableIntroDoSBurstPerSec200HiddenServiceOnionBalanceInstanceHiddenServicePoWDefensesEnabledHiddenServicePoWQueueRate250HiddenServicePoWQueueBurst2500config_generic_servicehs_optsservicehs_opts->HiddenServiceDir%s=%s. Configuring...Onion services version 2 are obsolete. Please see https://blog.torproject.org/v2-deprecation-timeline for more details and for instructions on how to transition to version 3. %s!err_msgHiddenServicePort=%s for %scheck_value_oob%s must be %d, not %d.%s must be between %d and %d, not %d.config_learn_service_versionconfig_has_invalid_optionsHiddenServiceAuthorizeClientd |
Source: $77tor.exe, 00000007.00000002.2649807568.000000000081F000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: HiddenServiceDirHiddenServiceDirGroupReadable0HiddenServicePortHiddenServiceVersion-1HiddenServiceAllowUnknownPortsHiddenServiceMaxStreamsHiddenServiceMaxStreamsCloseCircuitHiddenServiceNumIntroductionPoints3HiddenServiceExportCircuitIDHiddenServiceEnableIntroDoSDefenseHiddenServiceEnableIntroDoSRatePerSec25HiddenServiceEnableIntroDoSBurstPerSec200HiddenServiceOnionBalanceInstanceHiddenServicePoWDefensesEnabledHiddenServicePoWQueueRate250HiddenServicePoWQueueBurst2500config_generic_servicehs_optsservicehs_opts->HiddenServiceDir%s=%s. Configuring...Onion services version 2 are obsolete. Please see https://blog.torproject.org/v2-deprecation-timeline for more details and for instructions on how to transition to version 3. %s!err_msgHiddenServicePort=%s for %scheck_value_oob%s must be %d, not %d.%s must be between %d and %d, not %d.config_learn_service_versionconfig_has_invalid_optionsHiddenServiceAuthorizeClientd |
Source: $77tor.exe, 00000007.00000000.1516091838.000000000081F000.00000002.00000001.01000000.00000006.sdmp | String found in binary or memory: HiddenServiceDirHiddenServiceDirGroupReadable0HiddenServicePortHiddenServiceVersion-1HiddenServiceAllowUnknownPortsHiddenServiceMaxStreamsHiddenServiceMaxStreamsCloseCircuitHiddenServiceNumIntroductionPoints3HiddenServiceExportCircuitIDHiddenServiceEnableIntroDoSDefenseHiddenServiceEnableIntroDoSRatePerSec25HiddenServiceEnableIntroDoSBurstPerSec200HiddenServiceOnionBalanceInstanceHiddenServicePoWDefensesEnabledHiddenServicePoWQueueRate250HiddenServicePoWQueueBurst2500config_generic_servicehs_optsservicehs_opts->HiddenServiceDir%s=%s. Configuring...Onion services version 2 are obsolete. Please see https://blog.torproject.org/v2-deprecation-timeline for more details and for instructions on how to transition to version 3. %s!err_msgHiddenServicePort=%s for %scheck_value_oob%s must be %d, not %d.%s must be between %d and %d, not %d.config_learn_service_versionconfig_has_invalid_optionsHiddenServiceAuthorizeClientd |
Source: 7GfciIf7ys.exe | String found in binary or memory: HiddenServiceDirHiddenServiceDirGroupReadable0HiddenServicePortHiddenServiceVersion-1HiddenServiceAllowUnknownPortsHiddenServiceMaxStreamsHiddenServiceMaxStreamsCloseCircuitHiddenServiceNumIntroductionPoints3HiddenServiceExportCircuitIDHiddenServiceEnableIntroDoSDefenseHiddenServiceEnableIntroDoSRatePerSec25HiddenServiceEnableIntroDoSBurstPerSec200HiddenServiceOnionBalanceInstanceHiddenServicePoWDefensesEnabledHiddenServicePoWQueueRate250HiddenServicePoWQueueBurst2500config_generic_servicehs_optsservicehs_opts->HiddenServiceDir%s=%s. Configuring...Onion services version 2 are obsolete. Please see https://blog.torproject.org/v2-deprecation-timeline for more details and for instructions on how to transition to version 3. %s!err_msgHiddenServicePort=%s for %scheck_value_oob%s must be %d, not %d.%s must be between %d and %d, not %d.config_learn_service_versionconfig_has_invalid_optionsHiddenServiceAuthorizeClientd |
Source: global traffic | TCP traffic: 192.168.2.8:49710 -> 45.141.215.88:143 |
Source: global traffic | TCP traffic: 192.168.2.8:49711 -> 185.112.144.198:9001 |
Source: unknown | DNS traffic detected: query: thisshouldnotexist12345.com replaycode: Name error (3) |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.112.144.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.112.144.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.112.144.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.112.144.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.112.144.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.141.215.88 |
Source: 7GfciIf7ys.exe | String found in binary or memory: www.google.com,www.mit.edu,www.yahoo.com,www.slashdot.org equals www.yahoo.com (Yahoo) |
Source: $77tor.exe, 00000007.00000002.2650424241.000000000116E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: www.yahoo.com equals www.yahoo.com (Yahoo) |
Source: $77tor.exe, 00000007.00000002.2650424241.000000000116E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: www.yahoo.com0 equals www.yahoo.com (Yahoo) |
Source: global traffic | DNS traffic detected: DNS query: thisshouldnotexist12345.com |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D8A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://i3p36b7sdw2gelz3jidvo6ekpzspux3susa6edaemn3gwknenmh7ofad.onion:6969/$77install.exe |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D8A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://i3p36b7sdw2gelz3jidvo6ekpzspux3susa6edaemn3gwknenmh7ofad.onion:6969/$77install.exeindows |
Source: 7GfciIf7ys.exe | String found in binary or memory: http://thisshouldnotexist12345.com |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D2C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://thisshouldnotexist12345.com/ |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D8A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://thisshouldnotexist12345.com/$X |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D67000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://thisshouldnotexist12345.com/% |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D67000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://thisshouldnotexist12345.com/A |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D67000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://thisshouldnotexist12345.com/U |
Source: 7GfciIf7ys.exe, 00000001.00000002.2649212176.00000196B6D67000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://thisshouldnotexist12345.com/b |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://2019.www.torproject.org/docs/faq.html.en#WarningsAboutSOCKSandDNSInformationLeaks.%s |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://blog.torproject.org/lifecycle-of-a-new-relay |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://blog.torproject.org/lifecycle-of-a-new-relayset |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://blog.torproject.org/v2-deprecation-timeline |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://bridges.torproject.org/status?id=%s |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://bridges.torproject.org/status?id=%suninitialized |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://bugs.torproject.org/tpo/core/tor/14917. |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://bugs.torproject.org/tpo/core/tor/21155. |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://bugs.torproject.org/tpo/core/tor/8742. |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://curl.se/docs/alt-svc.html |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://curl.se/docs/hsts.html |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://curl.se/docs/http-cookies.html |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://freehaven.net/anonbib/#hs-attack06 |
Source: $77tor.exe, 00000007.00000003.1571421348.0000000003888000.00000004.00000020.00020000.00000000.sdmp, cached-microdesc-consensus.tmp.7.dr, unverified-microdesc-consensus.tmp.7.dr | String found in binary or memory: https://sabotage.net |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://support.torproject.org/faq/staying-anonymous/ |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://support.torproject.org/faq/staying-anonymous/alphabetaThis |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://www.gnu.org/licenses/gpl-3.0.en.html) |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://www.torproject.org/ |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://www.torproject.org/docs/faq.html#BestOSForRelay |
Source: 7GfciIf7ys.exe | String found in binary or memory: https://www.torproject.org/documentation.html |
Source: unknown | Network traffic detected: HTTP traffic on port 49716 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49714 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49716 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49714 |
Source: C:\Users\user\Desktop\7GfciIf7ys.exe | File created: C:\windows\$77driver | Jump to behavior |
Source: C:\Users\user\Desktop\7GfciIf7ys.exe | File created: C:\windows\$77driver\$77tor.exe | Jump to behavior |
Source: C:\Users\user\Desktop\7GfciIf7ys.exe | File created: C:\windows\$77driver\$77install.exe | Jump to behavior |
Source: 7GfciIf7ys.exe | Static PE information: Resource name: RT_RCDATA type: PE32 executable (console) Intel 80386, for MS Windows |
Source: classification engine | Classification label: mal76.evad.winEXE@10/17@1/6 |
Source: C:\Windows\$77driver\$77tor.exe | File created: C:\Users\user\AppData\Roaming\tor | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8144:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7728:120:WilError_03 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_nerre3i1.2zc.ps1 | Jump to behavior |
Source: 7GfciIf7ys.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Windows\$77driver\$77tor.exe | File read: C:\Users\desktop.ini | Jump to behavior |
Source: C:\Users\user\Desktop\7GfciIf7ys.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: 7GfciIf7ys.exe | ReversingLabs: Detection: 21% |
Source: 7GfciIf7ys.exe | Virustotal: Detection: 26% |
Source: 7GfciIf7ys.exe | String found in binary or memory: dir-address |
Source: 7GfciIf7ys.exe | String found in binary or memory: iphlpapi.dllif_nametoindexws2_32FreeAddrInfoExWGetAddrInfoExCancelGetAddrInfoExWkernel32LoadLibraryExA\/AddDllDirectoryh1h2h3%10s %512s %u %10s %512s %u "%64[^"]" %u %urt%s %s%s%s %u %s %s%s%s %u "%d%02d%02d %02d:%02d:%02d" %u %d |
Source: 7GfciIf7ys.exe | String found in binary or memory: --help |
Source: 7GfciIf7ys.exe | String found in binary or memory: --help |
Source: 7GfciIf7ys.exe | String found in binary or memory: config_parse_commandlineCommand-line option '%s' with no value. Failing.command line: parsed keyword '%s', value '%s'options_initUnable to set default options: %sline should be unreachedoptions_dumpBogus value for how_to_dump==%d%s (%llu) must be at most %d-h--help--list-torrc-options--list-deprecated-options--dbg-dump-subsystem-list--versionTor version %s. |
Source: 7GfciIf7ys.exe | String found in binary or memory: config_parse_commandlineCommand-line option '%s' with no value. Failing.command line: parsed keyword '%s', value '%s'options_initUnable to set default options: %sline should be unreachedoptions_dumpBogus value for how_to_dump==%d%s (%llu) must be at most %d-h--help--list-torrc-options--list-deprecated-options--dbg-dump-subsystem-list--versionTor version %s. |
Source: 7GfciIf7ys.exe | String found in binary or memory: Can't start/stop being a server while Sandbox is active |
Source: 7GfciIf7ys.exe | String found in binary or memory: Can't start/stop being a server while Sandbox is active |
Source: 7GfciIf7ys.exe | String found in binary or memory: src/feature/client/addressmap.c |
Source: 7GfciIf7ys.exe | String found in binary or memory: ./src/lib/net/address.h |
Source: 7GfciIf7ys.exe | String found in binary or memory: 2D{1D/2D.%s.exit.exit.addressmap_rewriteUnknown addrmap source value %d. Ignoring it.Addressmap: rewriting %s to %sLoop detected: we've rewritten %s 16 times! Using it as-is.REVERSE[%s]addressmap_rewrite_reverseRewrote reverse lookup %s -> %ssrc/feature/client/addressmap.caddressmap_registerwildcard_addrTemporary addressmap ('%s' to '%s') not performed, since it's already mapped to '%s'Addressmap: (re)mapped '%s' to '%s'client_dns_incr_failuresAddress %s now has %d resolve failures.client_dns_set_addressmapaddressvalValue not present (%s) after VirtualAddressNetwork%sEmptyNULLIPv6Error parsing VirtualAddressNetwork%s %sIncorrect address type for VirtualAddressNetwork%sVirtualAddressNetwork%s expects a /%d network or largeraddress_is_in_virtual_range.virtualaddressmap_register_virtual_addressnew_addressaddressmapvirtaddress_reversemap!vent_needs_to_be_addedInternal confusion: I thought that '%s' was mapped to by '%s', but '%s' really maps to '%s'. This is a harmless bug.(nothing)Registering map from %s to %s*.%s%s %s%s NEVER%s%s %s%s "%s"%s%s %s%sclient_dns_set_addressmap_implname%s.%s.exit%saddressmap_get_virtual_address%s wasn't in the addressmap, but %s was.Ran out of virtual addresses!Called with unsupported address type (%d)get_random_virtual_addrconf->bits <= total_bytes * 8tor_addr_compare_masked(addr_out, &conf->addr, conf->bits, CMP_EXACT)==0./src/lib/net/address.htor_addr_to_in6_asserta->family == 238 |
Source: 7GfciIf7ys.exe | String found in binary or memory: or-address |
Source: 7GfciIf7ys.exe | String found in binary or memory: >0C0E0C0E0C0C0Ccc_xoff_clientcc_xoff_exitcc_xon_change_pctcc_xon_ratecc_xon_ewma_cntsrc/core/or/congestion_control_flow.ccircuit_process_stream_xoff!(!conn)Got XOFF on invalid stream?Got XOFF from wrong hop.Got XOFF for non-congestion control circuitGot multiple XOFF on connectionScaling down for XOFF count: %d %d %dGot extra XOFF for bytes sent. Got %d, expected max %dGot XOFF!circuit_process_stream_xonGot XON on invalid stream?Got XON from wrong hop.Got XON for non-congestion control circuitReceived malformed XON cell.Scaling down for XON count: %d %d %dGot extra XON for bytes sent. Got %d, expected max %dGot XON: %dflow_control_decide_xoff!(!edge_uses_flow_control(stream))Flow control called for non-congestion control circuitSending XOFF: %u %dflow_control_decide_xonBegan edge buffering: %d %d %uUpdating drain rate: %d %d %uSending rate-change XON: %d %d %uSending XON: %d %d %uQueue empty for xon_rate_limit bytes: %d %dflow_control_note_sent_dataScaling down for flow control xmit bytes:: %d %d %dcircuit_send_stream_xoffFailed to encode xon cellcompute_drain_rate!(!is_monotime_clock_reliable())Computing drain rate with stalled monotime clockComputing stream drain rate with zero time deltacircuit_send_stream_xonsrc/feature/hs/hs_dos.chs_dos_setup_default_intro2_defensescirchs_dos_can_send_intro2s_intro_circ!(TO_CIRCUIT(s_intro_circ)->purpose != CIRCUIT_PURPOSE_INTRO_POINT)HiddenServiceEnableIntroDoSRatePerSecHiddenServiceEnableIntroDoSBurstPerSecHiddenServiceEnableIntroDoSDefensesrc/feature/stats/predict_ports.cpredicted_ports_prediction_time_remaining!(seconds_left == TIME_MAX)rep_hist_note_used_portpredicted_ports_listNew port prediction added. Will continue predictive circ building for %d more seconds.rep_hist_get_predicted_portsExpiring predicted port %drep_hist_note_used_internaladd_predicted_portrejectacceptreject6accept6routeripv6-policysigning-keyonion-keyntor-onion-keyrouter-signaturepublisheduptimefingerprinthibernatingplatformprotocontactread-historywrite-historyextra-info-digesthidden-service-diridentity-ed25519master-key-ed25519router-sig-ed25519onion-key-crosscertntor-onion-key-crosscertallow-single-hop-exitsfamilycaches-extra-infoor-addressoptbandwidth@purposetunnelled-dir-server0 |
Source: 7GfciIf7ys.exe | String found in binary or memory: signed_body+(end-start_of_annotations) == router->cache_info.signed_descriptor_body+len |
Source: 7GfciIf7ys.exe | String found in binary or memory: proto Found an obsolete router descriptor. Rejecting quietly.Couldn't compute router hash.Error tokenizing router descriptor.Impossibly short router descriptor.K_ROUTERtok->n_args >= 5signed_body+(end-start_of_annotations) == router->cache_info.signed_descriptor_body+lenstrlen(router->cache_info.signed_descriptor_body) == lenRouter nickname is invalidRouter address is not an IP address.Invalid OR port %sInvalid dir port %sK_BANDWIDTHtok->n_args >= 3bandwidthrate %s unreadable or 0. Failing.Invalid bandwidthburst %sInvalid bandwidthcapacity %stok->n_argstok->n_args >= 1Invalid uptime %sK_PUBLISHEDtok->n_args == 1K_ONION_KEYRelay's onion key had invalid exponent.Bogus ntor-onion-key in routerinfoK_SIGNING_KEYCouldn't calculate key digestRouter descriptor with only partial ed25519/cross-certification supportRouter descriptor has ed25519 master key but no certificateed_cert_tok && cc_tap_tok && cc_ntor_tokEd25519 certificate in wrong positionEd25519 signature in wrong positionED25519 CERTWrong object type on identity-ed25519 in descriptorWrong object type on ntor-onion-key-crosscert in descriptorCROSSCERTWrong object type on onion-key-crosscert in descriptor01Bad sign bit on ntor-onion-key-crosscertCouldn't parse ed25519 certInvalid form for ed25519 certmaster_key_tok->n_args >= 1Can't parse ed25519 master keyEd25519 master key does not match key in certificateCouldn't parse ntor-onion-key-crosscert certInvalid contents for ntor-onion-key-crosscert certError converting onion key to ed25519 |
Source: 7GfciIf7ys.exe | String found in binary or memory: or-address %s:%d |
Source: 7GfciIf7ys.exe | String found in binary or memory: My or-address line is <%s> |
Source: 7GfciIf7ys.exe | String found in binary or memory: My or-address line is <%s>proto %s |
Source: 7GfciIf7ys.exe | String found in binary or memory: connection_socks4_proxy_connectSOCKS4 client is incompatible with IPv6Sending out '%s' as our SOCKS argument string.buf_size >= (1 + 1 + 2 + 4 + 1) + strlen(socks_args_string)connection_socks5_proxy_connect???PROXY_NONEPROXY_INFANTPROXY_HTTPS_WANT_CONNECT_OKPROXY_SOCKS4_WANT_CONNECT_OKPROXY_SOCKS5_WANT_AUTH_METHOD_NONEPROXY_SOCKS5_WANT_AUTH_METHOD_RFC1929PROXY_SOCKS5_WANT_AUTH_RFC1929_OKPROXY_SOCKS5_WANT_CONNECT_OKPROXY_HAPROXY_WAIT_FOR_FLUSHPROXY_CONNECTEDconnection_read_https_proxy_responseYour https proxy sent back an oversized response. Closing.https proxy response not all here yet. Waiting.Unparseable headers from proxy (%s). Closing.[no reason given]HTTPS connect for %s successful! (200 %s) Starting TLS.The https proxy refused to allow connection to %s (status code %d, %s). Closing.The https proxy sent back an unexpected status code %d (%s). Closing../src/lib/net/address.htor_addr_to_in6_asserta->family == 23conn_get_proxy_typeconnection_listener_new_for_portreal_port <= 65535create_unix_sockaddrUnix domain sockets not supported, yet we tried to create one.connection_listener_newOpening %s on %sSocket creation failed: %sError setting SO_REUSEADDR flag on %s: %sError setting SO_EXCLUSIVEADDRUSE flag on %s: %sError setting IPV6_V6ONLY flag: %s. Is Tor already running?Could not bind to %s:%u: %s%sCould not listen on %s:%u: %sgetsockname() couldn't learn address for %s: %sGot unexpected address family %d.connection_add for listener failed. Giving up.%s listening on port %u.type == 15Opened %stor_listenSetting listen backlog to INT_MAX connections didn't work, but SOMAXCONN did. Lowering backlog limit.reenable_blocked_connection_schedule!(reenable_blocked_connections_ev == NULL)connection_handle_read_impl!conn->marked_for_close(unknown, errno was 0)connection_handle_listener_read(size_t)remotelen >= sizeof(struct sockaddr_in)accept() failed: %s. Closing listener.Connection accepted on socket %d (child of fd %d).make_socket_reuseable returned EINVALaccept() returned a strange address; closing connection.Denying socks connection from untrusted address %s.Denying dir connection from address %s.New SOCKS connection opened from %s.New SOCKS AF_UNIX connection openedNew control connection opened from %s.New metrics connection opened from %s.conn->type == 11new_type == 12New control connection opened.check_sockaddr_family_matchA listener connection returned a socket with a mismatched family. %s for addr_family %d gave us a socket wi |