Windows
Analysis Report
eMJ2QgQF4u.rtf
Overview
General Information
Sample name: | eMJ2QgQF4u.rtfrenamed because original name is a hash value |
Original sample name: | d805f910e1756735e34523281088f2ed.rtf |
Analysis ID: | 1520425 |
MD5: | d805f910e1756735e34523281088f2ed |
SHA1: | 243f7b70a0fde02f3afd3b7d2fe99a786cb505db |
SHA256: | d43cc5a3d193c33295a70f6861ee2d0ddbeeb165ab106018f06a38cc5297eb57 |
Tags: | rtfVIPKeyloggeruser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
- WINWORD.EXE (PID: 3260 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\WINWOR D.EXE" /Au tomation - Embedding MD5: 9EE74859D22DAE61F1750B3A1BACB6F5) - EQNEDT32.EXE (PID: 3340 cmdline:
"C:\Progra m Files\Co mmon Files \Microsoft Shared\EQ UATION\EQN EDT32.EXE" -Embeddin g MD5: A87236E214F6D42A65F5DEDAC816AEC8) - wscript.exe (PID: 3508 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\seeth edifferent ofpicture. vbs" MD5: 979D74799EA6C8B8167869A68DF5204A) - temp_executable.exe (PID: 3584 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\temp_e xecutable. exe" MD5: 3E01AC27E853080CA5C92470DF3F738C) - aspnet_compiler.exe (PID: 3664 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\asp net_compil er.exe" MD5: A1CC6D0A95AA5C113FA52BEA08847010) - EQNEDT32.EXE (PID: 3756 cmdline:
"C:\Progra m Files\Co mmon Files \Microsoft Shared\EQ UATION\EQN EDT32.EXE" -Embeddin g MD5: A87236E214F6D42A65F5DEDAC816AEC8)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Formbook, Formbo | FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware. |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_RTF_MalVer_Objects | Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents. | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
| |
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
| |
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
|
Exploits |
---|
Source: | Author: Joe Security: |
Source: | Author: Joe Security: |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: frack113: |
Source: | Author: Michael Haag: |
Source: | Author: frack113: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:57:07.632401+0200 | 2019696 | 1 | A Network Trojan was detected | 192.168.2.22 | 49166 | 185.18.213.20 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:57:07.632401+0200 | 2019714 | 2 | Potentially Bad Traffic | 192.168.2.22 | 49166 | 185.18.213.20 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:57:09.645046+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.22 | 49167 | 185.18.213.20 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: |
Exploits |
---|
Source: | Network connect: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process created: | ||
Source: | Process created: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Software Vulnerabilities |
---|
Source: | Process created: |
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Networking |
---|
Source: | Suricata IDS: |
Source: | Dropped file: | Jump to dropped file | ||
Source: | Dropped file: | Jump to dropped file |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | File created: | Jump to behavior |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 7_2_0042BDA3 | |
Source: | Code function: | 7_2_009107AC | |
Source: | Code function: | 7_2_0090F9F0 | |
Source: | Code function: | 7_2_0090FAE8 | |
Source: | Code function: | 7_2_0090FB68 | |
Source: | Code function: | 7_2_0090FDC0 | |
Source: | Code function: | 7_2_009100C4 | |
Source: | Code function: | 7_2_00910048 | |
Source: | Code function: | 7_2_00910078 | |
Source: | Code function: | 7_2_00910060 | |
Source: | Code function: | 7_2_009101D4 | |
Source: | Code function: | 7_2_0091010C | |
Source: | Code function: | 7_2_00910C40 | |
Source: | Code function: | 7_2_009110D0 | |
Source: | Code function: | 7_2_00911148 | |
Source: | Code function: | 7_2_0090F8CC | |
Source: | Code function: | 7_2_0090F900 | |
Source: | Code function: | 7_2_00911930 | |
Source: | Code function: | 7_2_0090F938 | |
Source: | Code function: | 7_2_0090FAB8 | |
Source: | Code function: | 7_2_0090FAD0 | |
Source: | Code function: | 7_2_0090FA20 | |
Source: | Code function: | 7_2_0090FA50 | |
Source: | Code function: | 7_2_0090FBB8 | |
Source: | Code function: | 7_2_0090FBE8 | |
Source: | Code function: | 7_2_0090FB50 | |
Source: | Code function: | 7_2_0090FC90 | |
Source: | Code function: | 7_2_0090FC30 | |
Source: | Code function: | 7_2_0090FC48 | |
Source: | Code function: | 7_2_0090FC60 | |
Source: | Code function: | 7_2_00911D80 | |
Source: | Code function: | 7_2_0090FD8C | |
Source: | Code function: | 7_2_0090FD5C | |
Source: | Code function: | 7_2_0090FEA0 | |
Source: | Code function: | 7_2_0090FED0 | |
Source: | Code function: | 7_2_0090FE24 | |
Source: | Code function: | 7_2_0090FFB4 | |
Source: | Code function: | 7_2_0090FFFC | |
Source: | Code function: | 7_2_0090FF34 |
Source: | Code function: | 6_2_00187020 | |
Source: | Code function: | 6_2_001828E0 | |
Source: | Code function: | 6_2_00182108 | |
Source: | Code function: | 6_2_00186721 | |
Source: | Code function: | 6_2_001820F8 | |
Source: | Code function: | 6_2_00180A78 | |
Source: | Code function: | 7_2_00401000 | |
Source: | Code function: | 7_2_0040F803 | |
Source: | Code function: | 7_2_004160B3 | |
Source: | Code function: | 7_2_00401260 | |
Source: | Code function: | 7_2_0040FA23 | |
Source: | Code function: | 7_2_00402ADD | |
Source: | Code function: | 7_2_00402AE0 | |
Source: | Code function: | 7_2_0040DAA3 | |
Source: | Code function: | 7_2_00402340 | |
Source: | Code function: | 7_2_0042E333 | |
Source: | Code function: | 7_2_00402334 | |
Source: | Code function: | 7_2_00402E70 | |
Source: | Code function: | 7_2_0040F7FA | |
Source: | Code function: | 7_2_0091E0C6 | |
Source: | Code function: | 7_2_0091E2E9 | |
Source: | Code function: | 7_2_009C63BF | |
Source: | Code function: | 7_2_009463DB | |
Source: | Code function: | 7_2_00922305 | |
Source: | Code function: | 7_2_0096A37B | |
Source: | Code function: | 7_2_009A443E | |
Source: | Code function: | 7_2_0093C5F0 | |
Source: | Code function: | 7_2_009A05E3 | |
Source: | Code function: | 7_2_00966540 | |
Source: | Code function: | 7_2_00924680 | |
Source: | Code function: | 7_2_0092E6C1 | |
Source: | Code function: | 7_2_0096A634 | |
Source: | Code function: | 7_2_009C2622 | |
Source: | Code function: | 7_2_0092C7BC | |
Source: | Code function: | 7_2_0092C85C | |
Source: | Code function: | 7_2_0094286D | |
Source: | Code function: | 7_2_009C098E | |
Source: | Code function: | 7_2_009229B2 | |
Source: | Code function: | 7_2_009369FE | |
Source: | Code function: | 7_2_009B49F5 | |
Source: | Code function: | 7_2_009CCBA4 | |
Source: | Code function: | 7_2_009A6BCB | |
Source: | Code function: | 7_2_009C2C9C | |
Source: | Code function: | 7_2_009AAC5E | |
Source: | Code function: | 7_2_00950D3B | |
Source: | Code function: | 7_2_0092CD5B | |
Source: | Code function: | 7_2_00952E2F | |
Source: | Code function: | 7_2_0093EE4C | |
Source: | Code function: | 7_2_009BCFB1 | |
Source: | Code function: | 7_2_00992FDC | |
Source: | Code function: | 7_2_00930F3F | |
Source: | Code function: | 7_2_0094D005 | |
Source: | Code function: | 7_2_0093905A | |
Source: | Code function: | 7_2_00923040 | |
Source: | Code function: | 7_2_0099D06D | |
Source: | Code function: | 7_2_009AD13F | |
Source: | Code function: | 7_2_009C1238 | |
Source: | Code function: | 7_2_0091F3CF | |
Source: | Code function: | 7_2_00927353 | |
Source: | Code function: | 7_2_00955485 | |
Source: | Code function: | 7_2_00931489 | |
Source: | Code function: | 7_2_0095D47D | |
Source: | Code function: | 7_2_009C35DA | |
Source: | Code function: | 7_2_0092351F | |
Source: | Code function: | 7_2_009A579A | |
Source: | Code function: | 7_2_009557C3 | |
Source: | Code function: | 7_2_009B771D | |
Source: | Code function: | 7_2_0099F8C4 | |
Source: | Code function: | 7_2_009BF8EE | |
Source: | Code function: | 7_2_009A5955 | |
Source: | Code function: | 7_2_009A394B | |
Source: | Code function: | 7_2_009D3A83 | |
Source: | Code function: | 7_2_009ADBDA | |
Source: | Code function: | 7_2_0091FBD7 | |
Source: | Code function: | 7_2_00947B00 | |
Source: | Code function: | 7_2_009BFDDD | |
Source: | Code function: | 7_2_009ABF14 | |
Source: | Code function: | 7_2_0094DF7C |
Source: | Dropped File: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 2_2_00588C1B | |
Source: | Code function: | 2_2_00588C13 | |
Source: | Code function: | 2_2_00578F61 | |
Source: | Code function: | 2_2_00588DEF | |
Source: | Code function: | 2_2_00588DE7 | |
Source: | Code function: | 2_2_00581001 | |
Source: | Code function: | 7_2_00407042 | |
Source: | Code function: | 7_2_00417060 | |
Source: | Code function: | 7_2_004030F2 | |
Source: | Code function: | 7_2_0041C8C9 | |
Source: | Code function: | 7_2_0040194E | |
Source: | Code function: | 7_2_0040214E | |
Source: | Code function: | 7_2_0040210D | |
Source: | Code function: | 7_2_0040214A | |
Source: | Code function: | 7_2_0040214A | |
Source: | Code function: | 7_2_0041125E | |
Source: | Code function: | 7_2_00424330 | |
Source: | Code function: | 7_2_00424330 | |
Source: | Code function: | 7_2_00401AE3 | |
Source: | Code function: | 7_2_00413417 | |
Source: | Code function: | 7_2_0041ECDD | |
Source: | Code function: | 7_2_00401DB2 | |
Source: | Code function: | 7_2_00401DB2 | |
Source: | Code function: | 7_2_00416EAB | |
Source: | Code function: | 7_2_00401F19 | |
Source: | Code function: | 7_2_00401FEC | |
Source: | Code function: | 7_2_00411000 | |
Source: | Code function: | 7_2_00411000 | |
Source: | Code function: | 7_2_00401FAD | |
Source: | Code function: | 7_2_00401FC6 | |
Source: | Code function: | 7_2_0091DFB4 |
Persistence and Installation Behavior |
---|
Source: | Registry value created: | Jump to behavior | ||
Source: | Registry value created: | Jump to behavior | ||
Source: | Registry value created: | Jump to behavior | ||
Source: | Registry value created: | Jump to behavior | ||
Source: | Registry value created: | Jump to behavior | ||
Source: | Registry value created: | Jump to behavior | ||
Source: | Registry value created: | Jump to behavior |
Source: | File created: | Jump to dropped file |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Key value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 7_2_00960101 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 7_2_00960101 |
Source: | Code function: | 7_2_009107AC |
Source: | Code function: | 7_2_00900080 | |
Source: | Code function: | 7_2_009000EA | |
Source: | Code function: | 7_2_009226F8 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 111 Scripting | Valid Accounts | 33 Exploitation for Client Execution | 111 Scripting | 311 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Query Registry | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Modify Registry | LSASS Memory | 12 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Disable or Modify Tools | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 41 Virtualization/Sandbox Evasion | NTDS | 41 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 311 Process Injection | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 11 Deobfuscate/Decode Files or Information | Cached Domain Credentials | 1 Remote System Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Obfuscated Files or Information | DCSync | 1 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 Install Root Certificate | Proc Filesystem | 13 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 DLL Side-Loading | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
47% | ReversingLabs | Document-RTF.Exploit.CVE-2017-11882 |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
21% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
dl.zerotheme.ir | 185.18.213.20 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.235.137.223 | unknown | Iran (ISLAMIC Republic Of) | 202391 | AFRARASAIR | true | |
185.18.213.20 | dl.zerotheme.ir | Iran (ISLAMIC Republic Of) | 44285 | SEFROYEKPARDAZENG-ASAS42043-BertinaTechnologyCompanyIR | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1520425 |
Start date and time: | 2024-09-27 10:56:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | eMJ2QgQF4u.rtfrenamed because original name is a hash value |
Original Sample Name: | d805f910e1756735e34523281088f2ed.rtf |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winRTF@9/10@1/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WerFault.exe, WMIADAP.exe, svchost.exe
- Execution Graph export aborted for target EQNEDT32.EXE, PID 3340 because there are no executed function
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: eMJ2QgQF4u.rtf
Time | Type | Description |
---|---|---|
04:56:59 | API Interceptor | |
04:57:02 | API Interceptor | |
04:57:04 | API Interceptor | |
04:57:11 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.235.137.223 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
185.18.213.20 | Get hash | malicious | FormBook | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
dl.zerotheme.ir | Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AFRARASAIR | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
SEFROYEKPARDAZENG-ASAS42043-BertinaTechnologyCompanyIR | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
36f7277af969a6947a61ae0b815907a1 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, RedLine | Browse |
| ||
Get hash | malicious | PXRECVOWEIWOEI Stealer, PureLog Stealer | Browse |
|
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\seethedifferentofpicture[1].vbs
Download File
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 92431 |
Entropy (8bit): | 4.8789339351328405 |
Encrypted: | false |
SSDEEP: | 1536:35VT1rG9XgL21xU47L2HiUYxd9jd4Qyxsyf4SgfAw2zXdcp2bF+Z:JPG9pxh7L2SxKsu4SU0u2bI |
MD5: | 7834CBAFCFAD72B1BDA091F3CCE8E997 |
SHA1: | 034AFCB22B254090084269FC8BCD68F64E4A85A8 |
SHA-256: | AAC62555CF55C081E503636CF2D696AB33A789B9D10DDC8A9EF2ED8014890913 |
SHA-512: | FA08EF7847F8F98A6E2442DB45935FBAA30D0C0CD26ABF457F8579FFDACE28D7851D5BBDC7630406C5FCFE74381241ACCD74B72E4DD79E194E1FD481BC06CFFF |
Malicious: | true |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{104C1C05-5B56-427D-9A18-F09CF519F5E8}.tmp
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | CE338FE6899778AACFC28414F2D9498B |
SHA1: | 897256B6709E1A4DA9DABA92B6BDE39CCFCCD8C1 |
SHA-256: | 4FE7B59AF6DE3B665B67788CC2F99892AB827EFAE3A467342B3BB4E3BC8E5BFE |
SHA-512: | 6EB7F16CF7AFCABE9BDEA88BDAB0469A7937EB715ADA9DFD8F428D9D38D86133945F5F2F2688DDD96062223A39B5D47F07AFC3C48D9DB1D5EE3F41C8D274DCCF |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{EB1C9D8C-3BA0-4F53-9B8A-301D31923000}.tmp
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16896 |
Entropy (8bit): | 3.5808522768349413 |
Encrypted: | false |
SSDEEP: | 384:Q/VXbEoRIdt1LMnoeC26GFYQuLJa18JRdZv8gk8J2+Dgrz:Q/VbIAnoeC26AUU18Fq58J2drz |
MD5: | C3900D55C838EED92A89FFA290B7C99B |
SHA1: | EA360506A8DB8C6872A1C2217B0E8F25B33D7DAC |
SHA-256: | 8CB86A7C206AA1D334651A47D3E817453EE8C9B78638E6D07BC22E3C03F9B037 |
SHA-512: | 5F903468D2A47C20F97D6D715DEE7B5827BE971A6CBF4CD37F74E4A03E808F931627C09CF136BE92DDAE879A374C82C5C852C53BF88B5BA8B31734BEE011ECAD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F96B07FF-ED02-4BEA-95F3-9B31FFA866FE}.tmp
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1024 |
Entropy (8bit): | 0.05390218305374581 |
Encrypted: | false |
SSDEEP: | 3:ol3lYdn:4Wn |
MD5: | 5D4D94EE7E06BBB0AF9584119797B23A |
SHA1: | DBB111419C704F116EFA8E72471DD83E86E49677 |
SHA-256: | 4826C0D860AF884D3343CA6460B0006A7A2CE7DBCCC4D743208585D997CC5FD1 |
SHA-512: | 95F83AE84CAFCCED5EAF504546725C34D5F9710E5CA2D11761486970F2FBECCB25F9CF50BBFC272BD75E1A66A18B7783F09E1C1454AFDA519624BC2BB2F28BA4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 49152 |
Entropy (8bit): | 6.632984721949493 |
Encrypted: | false |
SSDEEP: | 768:Ua9FDkXneHCBXyDMLNe9rotBMx251CBXWZBiGRO4TjPZcVP+LWcwTQ1qsL8:Ua92XeiBCd9/o+XWgGRO4HPmN7TQ1tL8 |
MD5: | 3E01AC27E853080CA5C92470DF3F738C |
SHA1: | 41B6C3DF03856DDF7A5BA505900A9499A6ABADA1 |
SHA-256: | E350330729257731AC3E4CB80CFCB243F8FD629A2AB5BC11D7A1E89B3945C716 |
SHA-512: | 2D4A0A638274A2A3B1B5E6A48E7BFC9A96C8FC113E49A6D89BD4ED3B63B3B3A9410258AA47DE79741C55ADAF24DE417D474CA5971784684870FA469F7C017DFF |
Malicious: | true |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1014 |
Entropy (8bit): | 4.5574923796151605 |
Encrypted: | false |
SSDEEP: | 12:8wZHae4FgXg/XAlCPCHaXEzBggB/5YXX+WZWIO2IOicvbsAp5A4K2IeDtZ3YilMQ:8wVjc/XTUzN4XBIteFTIeDv3qai57u |
MD5: | 0188A679B4E9A1EFD8BE440A7CC3F68D |
SHA1: | 5FFFC8D990B2577344ECB5D2BE8572E056E31DE4 |
SHA-256: | EB3DC5D5C31B9CD0B461D7D492F20D0A11A2827F5645B830E8735469AF6A2071 |
SHA-512: | 80DACE63F27099D2BC3F82194E6AB819D2AC824B7C707C8B33B8E983F5A5F037CC3A62A6B08765B9006D7749B09AE78B8852DA8D1E80FE4075443C53171A7062 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.676725395303504 |
Encrypted: | false |
SSDEEP: | 3:HLyXWRv4om4FPWRv4ov:HLrv41v4y |
MD5: | 0D49BA26A9D1E5B057B4526E99CF43AA |
SHA1: | 01A558006DBDB62C980C4323016F92BDE57B4AB2 |
SHA-256: | 639AD2BCE35E3B66571B386156B458BE22AEC66269181717458AA7C6A76EB06E |
SHA-512: | 68F10E111469235B5A4E0782B399C17EFE84FC56D7E86123A1D63D3172BC1BBCC931E9052FF00E65696DD691ABE19F3AA72169180EEB14347A4C8B8D5A3550DC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.5038355507075254 |
Encrypted: | false |
SSDEEP: | 3:vrJlaCkWtVyyAGlY5mWSyePAi/lln:vdsCkWtA9/idl |
MD5: | 782B772E21E6B8EFB11B235130F050A6 |
SHA1: | D841FB557392C38D7B7F5EF52F03D6FA77DAD0EC |
SHA-256: | F69766E15E5E7AFF3E540B8B098B618172F5350CBDFA757D4CFD9071A5DA37E8 |
SHA-512: | DAB38260CE9D0C9C11478D982B6672058BF07CCD28DB4CB36F8112252BEE9D34EA55F07364BCF2883A8CB211AA7701D877B7827CF0EB7BC8E19DA7249C456849 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 92431 |
Entropy (8bit): | 4.8789339351328405 |
Encrypted: | false |
SSDEEP: | 1536:35VT1rG9XgL21xU47L2HiUYxd9jd4Qyxsyf4SgfAw2zXdcp2bF+Z:JPG9pxh7L2SxKsu4SU0u2bI |
MD5: | 7834CBAFCFAD72B1BDA091F3CCE8E997 |
SHA1: | 034AFCB22B254090084269FC8BCD68F64E4A85A8 |
SHA-256: | AAC62555CF55C081E503636CF2D696AB33A789B9D10DDC8A9EF2ED8014890913 |
SHA-512: | FA08EF7847F8F98A6E2442DB45935FBAA30D0C0CD26ABF457F8579FFDACE28D7851D5BBDC7630406C5FCFE74381241ACCD74B72E4DD79E194E1FD481BC06CFFF |
Malicious: | true |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.5038355507075254 |
Encrypted: | false |
SSDEEP: | 3:vrJlaCkWtVyyAGlY5mWSyePAi/lln:vdsCkWtA9/idl |
MD5: | 782B772E21E6B8EFB11B235130F050A6 |
SHA1: | D841FB557392C38D7B7F5EF52F03D6FA77DAD0EC |
SHA-256: | F69766E15E5E7AFF3E540B8B098B618172F5350CBDFA757D4CFD9071A5DA37E8 |
SHA-512: | DAB38260CE9D0C9C11478D982B6672058BF07CCD28DB4CB36F8112252BEE9D34EA55F07364BCF2883A8CB211AA7701D877B7827CF0EB7BC8E19DA7249C456849 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 2.8471901685936154 |
TrID: |
|
File name: | eMJ2QgQF4u.rtf |
File size: | 108'966 bytes |
MD5: | d805f910e1756735e34523281088f2ed |
SHA1: | 243f7b70a0fde02f3afd3b7d2fe99a786cb505db |
SHA256: | d43cc5a3d193c33295a70f6861ee2d0ddbeeb165ab106018f06a38cc5297eb57 |
SHA512: | 37c6edc231148af4c65c77412f7672d12ec8504b3fb35bf6581e7a3405242a21d302af97c6b898312750d8938d8c4b83299dc746a284f5f90e2b8e5b7cba807f |
SSDEEP: | 768:DdO5Q5s3pz7p3S2b9dbk4bSI+GdepBlMNIbnq8dEK7wC5Sbcif4:DwaGj9BjjdepBCNIbnfEGMbn4 |
TLSH: | 82B3CDA9C78F01A5CF64A73B03679A0945F8B33EF21458A530AC977133EDD2E596187C |
File Content Preview: | {\rtf1..{\*\9tK3ug6SfiJBlo39Vt3WS6ar2vcROpN1MywcyDGhqQLa9xg1cP1BtfFg5Bc5eSCSPmbIvLuh2OtfipPq9uEL2LruDTpJQo4ySrisQ4yiN7MD7R9sFx}..{\44620688%=-)~61./$?$9;)?2.=&_-&~?@,+,^)'.~4&|?#6??~1;!=.+`@'1>!?7)?[5.?%|%.,28_^.*.4._?_1+0&%1%).$.~[[>&`??80'.*!.(-.|?~.?>` |
Icon Hash: | 2764a3aaaeb7bdbf |
Id | Start | Format ID | Format | Classname | Datasize | Filename | Sourcepath | Temppath | Exploit |
---|---|---|---|---|---|---|---|---|---|
0 | 00001FBEh | no |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:57:07.632401+0200 | 2019696 | ET MALWARE Possible MalDoc Payload Download Nov 11 2014 | 1 | 192.168.2.22 | 49166 | 185.18.213.20 | 443 | TCP |
2024-09-27T10:57:07.632401+0200 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | 2 | 192.168.2.22 | 49166 | 185.18.213.20 | 443 | TCP |
2024-09-27T10:57:09.645046+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.22 | 49167 | 185.18.213.20 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 27, 2024 10:57:02.180000067 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.184861898 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.184930086 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.185199976 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.189933062 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803174019 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803193092 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803203106 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803212881 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803224087 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803234100 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803244114 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803250074 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.803253889 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803271055 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803282976 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.803289890 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.803289890 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.803309917 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.803323984 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.808748960 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.809614897 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.809674978 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.809778929 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.809818983 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.890192032 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890212059 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890224934 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890235901 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890288115 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.890289068 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.890335083 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890347004 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890360117 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890396118 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890398026 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.890398026 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.890408993 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.890436888 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.891119003 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.891138077 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.891149044 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.891180038 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.891202927 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.891202927 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.891216040 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.891261101 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.892038107 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892050028 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892061949 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892097950 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.892103910 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892117977 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892118931 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.892160892 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.892906904 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892920017 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892930984 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.892967939 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.893019915 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.974231958 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.974267960 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.974278927 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.974288940 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.974292040 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.974330902 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.974340916 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.977443933 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977463007 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977472067 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977488995 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977499008 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977507114 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.977520943 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.977525949 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977531910 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.977782011 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.977978945 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.977991104 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978001118 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978018999 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978030920 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978055954 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978068113 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978089094 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978099108 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978607893 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978619099 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978631020 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978650093 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978669882 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978672981 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978683949 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978694916 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978702068 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978705883 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.978719950 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.978734016 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.979541063 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979551077 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979561090 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979583979 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.979598045 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.979613066 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979624033 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979633093 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979641914 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.979645014 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.979660034 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.979675055 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.980432987 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980444908 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980454922 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980477095 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.980488062 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.980515957 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980525970 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980535984 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980546951 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.980551004 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.980562925 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.980577946 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:02.981384993 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:02.981429100 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.060085058 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060112953 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060126066 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060137033 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060148954 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060161114 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060163021 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.060205936 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.060205936 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.060216904 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060229063 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060240030 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060251951 CEST | 80 | 49165 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:57:03.060261011 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.060275078 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.060290098 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:03.584847927 CEST | 49165 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:57:05.859360933 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:05.859419107 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:05.859504938 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:05.865971088 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:05.865994930 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:06.673691988 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:06.673825979 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:06.706881046 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:06.706907988 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:06.707344055 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:06.911413908 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:06.911509991 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.314166069 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.359417915 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.632471085 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.749442101 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.749494076 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.749593973 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.749634981 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.749646902 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.749682903 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.751624107 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.751631021 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.751672029 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.751677036 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.751683950 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.751699924 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.751724005 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.789282084 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.919734955 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.919748068 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.919807911 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.919815063 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.919879913 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.919907093 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.919935942 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.920615911 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.920625925 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.920661926 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.920674086 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.920694113 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.920702934 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.920706987 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.920773029 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.921375036 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.921421051 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.921452045 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.921458960 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.921483040 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.924225092 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.924268961 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.924277067 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.924287081 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:07.924316883 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:07.949064016 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.090574980 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.090626955 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.090729952 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.090758085 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.090790033 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.090908051 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.090945005 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.090954065 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.090964079 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.090993881 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.091861010 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.091903925 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.091907024 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.091926098 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.091939926 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.095237017 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.095285892 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.095290899 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.095314026 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.095329046 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.095603943 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.095648050 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.101526022 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.101548910 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.101562977 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.101644039 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.102834940 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.178327084 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.178385973 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.178442001 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.178442001 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.178468943 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.200781107 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.260687113 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.260756969 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.260834932 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.260867119 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.260895014 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.261339903 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.261388063 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.261394024 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.261406898 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.261441946 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.261719942 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.261765957 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.261766911 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.261775970 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.261810064 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.262058020 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.262104034 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.262104988 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.262113094 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.262147903 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.262254953 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.262299061 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.262303114 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.262331009 CEST | 443 | 49166 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.262366056 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.264333010 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.354645967 CEST | 49166 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.358833075 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.358886003 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:08.358946085 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.360899925 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:08.360924959 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.167964935 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.177370071 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:09.177413940 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.645096064 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.818219900 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.818236113 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.818341970 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:09.818375111 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.818387032 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.818432093 CEST | 443 | 49167 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:57:09.818453074 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:09.818453074 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:09.818484068 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:09.818770885 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:57:09.819777012 CEST | 49167 | 443 | 192.168.2.22 | 185.18.213.20 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 27, 2024 10:57:05.844036102 CEST | 54562 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:57:05.851135969 CEST | 53 | 54562 | 8.8.8.8 | 192.168.2.22 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 27, 2024 10:57:05.844036102 CEST | 192.168.2.22 | 8.8.8.8 | 0x4506 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 27, 2024 10:57:05.851135969 CEST | 8.8.8.8 | 192.168.2.22 | 0x4506 | No error (0) | 185.18.213.20 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.22 | 49165 | 185.235.137.223 | 80 | 3340 | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 27, 2024 10:57:02.185199976 CEST | 333 | OUT | |
Sep 27, 2024 10:57:02.803174019 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803193092 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803203106 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803212881 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803224087 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803234100 CEST | 1120 | IN | |
Sep 27, 2024 10:57:02.803244114 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803253889 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803271055 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.803282976 CEST | 1236 | IN | |
Sep 27, 2024 10:57:02.809614897 CEST | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.22 | 49166 | 185.18.213.20 | 443 | 3584 | C:\Users\user\AppData\Local\Temp\temp_executable.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:57:07 UTC | 89 | OUT | |
2024-09-27 08:57:07 UTC | 207 | IN | |
2024-09-27 08:57:07 UTC | 16384 | IN | |
2024-09-27 08:57:07 UTC | 16384 | IN | |
2024-09-27 08:57:07 UTC | 16384 | IN | |
2024-09-27 08:57:07 UTC | 16384 | IN | |
2024-09-27 08:57:07 UTC | 16384 | IN | |
2024-09-27 08:57:07 UTC | 16384 | IN | |
2024-09-27 08:57:08 UTC | 16384 | IN | |
2024-09-27 08:57:08 UTC | 16384 | IN | |
2024-09-27 08:57:08 UTC | 16384 | IN | |
2024-09-27 08:57:08 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.22 | 49167 | 185.18.213.20 | 443 | 3584 | C:\Users\user\AppData\Local\Temp\temp_executable.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:57:09 UTC | 66 | OUT | |
2024-09-27 08:57:09 UTC | 206 | IN | |
2024-09-27 08:57:09 UTC | 1162 | IN | |
2024-09-27 08:57:09 UTC | 14198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:56:57 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13f280000 |
File size: | 1'423'704 bytes |
MD5 hash: | 9EE74859D22DAE61F1750B3A1BACB6F5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 2 |
Start time: | 04:56:59 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 543'304 bytes |
MD5 hash: | A87236E214F6D42A65F5DEDAC816AEC8 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 04:57:02 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\wscript.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x450000 |
File size: | 141'824 bytes |
MD5 hash: | 979D74799EA6C8B8167869A68DF5204A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 04:57:04 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Local\Temp\temp_executable.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa80000 |
File size: | 49'152 bytes |
MD5 hash: | 3E01AC27E853080CA5C92470DF3F738C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 04:57:09 |
Start date: | 27/09/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x20000 |
File size: | 55'384 bytes |
MD5 hash: | A1CC6D0A95AA5C113FA52BEA08847010 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
Has exited: | true |
Target ID: | 8 |
Start time: | 04:57:21 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 543'304 bytes |
MD5 hash: | A87236E214F6D42A65F5DEDAC816AEC8 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Function 00579718 Relevance: 21.6, Strings: 17, Instructions: 392COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 21.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 17 |
Total number of Limit Nodes: | 2 |
Graph
Function 00182108 Relevance: 1.6, Strings: 1, Instructions: 377COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00187020 Relevance: 1.4, Instructions: 1433COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00186721 Relevance: .6, Instructions: 567COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001828E0 Relevance: .5, Instructions: 514COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00188D48 Relevance: 1.6, APIs: 1, Instructions: 105COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00188D50 Relevance: 1.6, APIs: 1, Instructions: 100COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00188E61 Relevance: 1.6, APIs: 1, Instructions: 98memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00188E68 Relevance: 1.6, APIs: 1, Instructions: 95memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00188C38 Relevance: 1.6, APIs: 1, Instructions: 92threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00188C40 Relevance: 1.6, APIs: 1, Instructions: 88threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001890A9 Relevance: 1.6, APIs: 1, Instructions: 67threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001890B0 Relevance: 1.6, APIs: 1, Instructions: 66threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0418 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C021C Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0564 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0A08 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C03C8 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C09B8 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0430 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0B68 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0238 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0A20 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C0580 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C09D0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001C03E0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00180A78 Relevance: 1.8, Strings: 1, Instructions: 521COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001820F8 Relevance: .1, Instructions: 131COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 1.1% |
Dynamic/Decrypted Code Coverage: | 4.4% |
Signature Coverage: | 7% |
Total number of Nodes: | 114 |
Total number of Limit Nodes: | 11 |
Graph
Function 0042BDA3 Relevance: 1.5, APIs: 1, Instructions: 25nativeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 009107AC Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090F9F0 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FAE8 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FB68 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FDC0 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042C0E3 Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042C0A3 Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042C123 Relevance: 1.5, APIs: 1, Instructions: 25COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00900080 Relevance: 1.3, Strings: 1, Instructions: 35COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009226F8 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00960101 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009000EA Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009100C4 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00910048 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00910078 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00910060 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009101D4 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0091010C Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00910C40 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009110D0 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00911148 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090F8CC Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090F900 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00911930 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090F938 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FAB8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FAD0 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FA20 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FA50 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FBB8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FBE8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FB50 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FC90 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FC30 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FC48 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FC60 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00911D80 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FD8C Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FD5C Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FEA0 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FED0 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FE24 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FFB4 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FFFC Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090FF34 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094FCC9 Relevance: 6.3, APIs: 4, Instructions: 257COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009C5CFA Relevance: 5.5, APIs: 1, Strings: 2, Instructions: 237COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|