Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 7032 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 500904922500A6B286EBC7B6AA791E24) - conhost.exe (PID: 7060 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - MSBuild.exe (PID: 6324 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\MSB uild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
{"C2 url": "4.251.123.83:6677"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_RedLine_1 | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
Click to see the 7 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
| |
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
Click to see the 11 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T12:06:59.992193+0100 | 2046056 | 1 | A Network Trojan was detected | 4.251.123.83 | 6677 | 192.168.2.4 | 49730 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T12:06:59.338810+0100 | 2046045 | 1 | A Network Trojan was detected | 192.168.2.4 | 49730 | 4.251.123.83 | 6677 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Large array initialization: | ||
Source: | Large array initialization: |
Source: | Code function: | 0_2_6CF03950 | |
Source: | Code function: | 0_2_6CF03250 |
Source: | Code function: | 0_2_6CF03950 | |
Source: | Code function: | 0_2_6CF03250 | |
Source: | Code function: | 0_2_6CF01210 | |
Source: | Code function: | 0_2_6CF13595 | |
Source: | Code function: | 0_2_6CF02690 | |
Source: | Code function: | 0_2_6CF07A40 | |
Source: | Code function: | 0_2_6CF03750 | |
Source: | Code function: | 0_2_02701464 | |
Source: | Code function: | 0_2_0270245C | |
Source: | Code function: | 0_2_027058E1 | |
Source: | Code function: | 0_2_02705C98 | |
Source: | Code function: | 0_2_02705908 | |
Source: | Code function: | 0_2_02703B8D | |
Source: | Code function: | 0_2_02703830 | |
Source: | Code function: | 0_2_02703820 | |
Source: | Code function: | 0_2_027058F9 | |
Source: | Code function: | 0_2_027008AC | |
Source: | Code function: | 0_2_02704167 | |
Source: | Code function: | 0_2_02704B48 | |
Source: | Code function: | 0_2_02702D00 | |
Source: | Code function: | 2_2_00DD7660 | |
Source: | Code function: | 2_2_00DD0878 | |
Source: | Code function: | 2_2_00DD0869 | |
Source: | Code function: | 2_2_00DD7652 | |
Source: | Code function: | 2_2_00DD7660 | |
Source: | Code function: | 2_2_06EE3FF1 | |
Source: | Code function: | 2_2_06EE1BD8 | |
Source: | Code function: | 2_2_06EE3890 | |
Source: | Code function: | 2_2_06EF8770 | |
Source: | Code function: | 2_2_06EF9568 | |
Source: | Code function: | 2_2_06EF3E50 | |
Source: | Code function: | 2_2_06EFAF30 | |
Source: | Code function: | 2_2_06EF6A20 | |
Source: | Code function: | 2_2_06EF48B0 | |
Source: | Code function: | 2_2_06EF5600 | |
Source: | Code function: | 2_2_06EF9558 | |
Source: | Code function: | 2_2_06EFAF20 | |
Source: | Code function: | 2_2_06EFED23 | |
Source: | Code function: | 2_2_06EFED30 | |
Source: | Code function: | 2_2_06EF6A10 | |
Source: | Code function: | 2_2_06EF48A3 | |
Source: | Code function: | 2_2_06FB34E0 | |
Source: | Code function: | 2_2_06FB5568 | |
Source: | Code function: | 2_2_06FB0040 | |
Source: | Code function: | 2_2_06FBE1D8 | |
Source: | Code function: | 2_2_06FBC4F8 | |
Source: | Code function: | 2_2_06FBD060 | |
Source: | Code function: | 2_2_06FBB037 | |
Source: | Code function: | 2_2_06FD9DD0 | |
Source: | Code function: | 2_2_06FDDAE8 | |
Source: | Code function: | 2_2_06FD72A8 | |
Source: | Code function: | 2_2_06FD1A18 | |
Source: | Code function: | 2_2_06FDB3F8 | |
Source: | Code function: | 2_2_06FD6BA0 | |
Source: | Code function: | 2_2_06FD30D8 | |
Source: | Code function: | 2_2_06FDDAD8 | |
Source: | Code function: | 2_2_06FD80C8 | |
Source: | Code function: | 2_2_06FDB920 | |
Source: | Code function: | 2_2_06FDB910 | |
Source: | Code function: | 2_2_06FFD708 | |
Source: | Code function: | 2_2_06FF6A88 | |
Source: | Code function: | 2_2_06FF1E58 | |
Source: | Code function: | 2_2_06FF1E48 | |
Source: | Code function: | 2_2_06FF4CF0 | |
Source: | Code function: | 2_2_06FF1260 | |
Source: | Code function: | 2_2_06FF1250 | |
Source: | Code function: | 2_2_06FF5218 | |
Source: | Code function: | 2_2_06FF5209 | |
Source: | Code function: | 2_2_06FF9BD0 | |
Source: | Code function: | 2_2_073C57E8 | |
Source: | Code function: | 2_2_073C2408 | |
Source: | Code function: | 2_2_073C7318 | |
Source: | Code function: | 2_2_073CA360 | |
Source: | Code function: | 2_2_073CD2D8 | |
Source: | Code function: | 2_2_073C8100 | |
Source: | Code function: | 2_2_073C0E60 | |
Source: | Code function: | 2_2_073C2ED0 | |
Source: | Code function: | 2_2_073CAC18 | |
Source: | Code function: | 2_2_073CD928 | |
Source: | Code function: | 2_2_073C49F8 | |
Source: | Code function: | 2_2_073C730B | |
Source: | Code function: | 2_2_073C80F0 | |
Source: | Code function: | 2_2_073C49EB |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: |
Source: | .Net Code: |
Source: | Code function: | 0_2_6CF13CD7 | |
Source: | Code function: | 0_2_02705002 | |
Source: | Code function: | 0_2_02703F9E | |
Source: | Code function: | 2_2_06EEFC81 | |
Source: | Code function: | 2_2_06EE6D40 | |
Source: | Code function: | 2_2_06EF5465 | |
Source: | Code function: | 2_2_06EF1E89 | |
Source: | Code function: | 2_2_06FBF9B4 | |
Source: | Code function: | 2_2_06FBF9B4 | |
Source: | Code function: | 2_2_06FD0960 | |
Source: | Code function: | 2_2_073C0695 | |
Source: | Code function: | 2_2_073C0695 | |
Source: | Code function: | 2_2_073C0695 | |
Source: | Code function: | 2_2_073C0695 |
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 2_2_06FDE740 |
Source: | Code function: | 0_2_6CF0897A |
Source: | Code function: | 0_2_6CF0E70B |
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 0_2_6CF084A1 | |
Source: | Code function: | 0_2_6CF0897A | |
Source: | Code function: | 0_2_6CF0C937 |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_6CF08B38 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_6CF085C3 |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 221 Windows Management Instrumentation | 1 DLL Side-Loading | 311 Process Injection | 1 Masquerading | 1 OS Credential Dumping | 1 System Time Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Disable or Modify Tools | LSASS Memory | 341 Security Software Discovery | Remote Desktop Protocol | 3 Data from Local System | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 241 Virtualization/Sandbox Evasion | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | 1 Clipboard Data | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 311 Process Injection | NTDS | 241 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 3 Obfuscated Files or Information | Cached Domain Credentials | 124 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 22 Software Packing | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1311038 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
4.251.123.83 | unknown | United States | 3356 | LEVEL3US | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1546038 |
Start date and time: | 2024-10-31 12:06:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@4/3@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
07:07:00 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
LEVEL3US | Get hash | malicious | Stealc, Vidar | Browse |
| |
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2543 |
Entropy (8bit): | 5.331950323785858 |
Encrypted: | false |
SSDEEP: | 48:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HDfHKdHKLBHK7HKmTHQmHKtXoDHsLHqH5J:Pq5qHwCYqh3oPtI6eqzxTqdqlq7qqjqI |
MD5: | D1C706335BBF6ECA4BECB0CACD9231EB |
SHA1: | AC27DA2AC6FEC7C7F24C9796CB7BCECD5EF8F382 |
SHA-256: | 45449CD3FC0C10386A37510D13C883FEF94883D11D757FDD0FFE4EDAF0DAAD75 |
SHA-512: | D5A4D33B362C4EF19CD0E43F2F518258EE45A1A32DED992B851276DF3BC8A4559E7D1872B155E10DAF1FF6B38C65AF472AF429B8362EBBB12976B3454C1FE68B |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 42 |
Entropy (8bit): | 4.0050635535766075 |
Encrypted: | false |
SSDEEP: | 3:QHXMKa/xwwUy:Q3La/xwQ |
MD5: | 84CFDB4B995B1DBF543B26B86C863ADC |
SHA1: | D2F47764908BF30036CF8248B9FF5541E2711FA2 |
SHA-256: | D8988D672D6915B46946B28C06AD8066C50041F6152A91D37FFA5CF129CC146B |
SHA-512: | 485F0ED45E13F00A93762CBF15B4B8F996553BAA021152FAE5ABA051E3736BCD3CA8F4328F0E6D9E3E1F910C96C4A9AE055331123EE08E3C2CE3A99AC2E177CE |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 855040 |
Entropy (8bit): | 5.6181812603560655 |
Encrypted: | false |
SSDEEP: | 12288:UKRhdAJtGfliyDB6NcP/BzYhy7EVe6JVM926xir0l6G8tGxBFLs8HVTN3gLkW/Eb:UK5qk |
MD5: | 44CB7F156344FBA97C4C9DD485276C8A |
SHA1: | B508628B9163E236D9EF1BA95868AE128ABB05CD |
SHA-256: | 0F2BA82668B74F28DDB7B95233EE21FE32BFB1BD3ADB0C5B2F34D3001443ED3C |
SHA-512: | C79C538A0F6BC88017F3AAA5A551C8CE92B7E92786CCA5168BB5604F5B1AB9DE45B79681D06ADE2B10A7E002B7FE600FBE59991FA9B454999B5B207F88991F16 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.8122854091440574 |
TrID: |
|
File name: | file.exe |
File size: | 271'360 bytes |
MD5: | 500904922500a6b286ebc7b6aa791e24 |
SHA1: | b09695e46e35a433dc00c41508b6ff47745247a7 |
SHA256: | 8e08e9ad4ee4438acbb60b2922cf4578f93df6f4adcd01e1e8942a36bd5dc4d8 |
SHA512: | baa756bc44306c37774115fe0bd14f1e9735d25def4042a9035c8903e153aee3e1be8fcde286632609e96923256f8d69b0424ee0c30ab4a95de494462fc0e3e6 |
SSDEEP: | 6144:QVZd5702Ameiqqv6Hrs3LI6VRPob7QEAI1AeOPvNb:+exmeiqrHrN6VuX5AeOPvNb |
TLSH: | 9D44BF9CB65476CFC86BC971CEA82C64EA61B877430F9247A06716ED990CA97CF011F3 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....9#g.............................7... ...@....@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x4437ae |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6723391E [Thu Oct 31 08:00:30 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x4375c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x44000 | 0x6d8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x46000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x417b4 | 0x41800 | 3f0024870ed7d584f059c6cbddf13d62 | False | 0.8963725548664122 | data | 7.831361955004328 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x44000 | 0x6d8 | 0x800 | aaef290f02fed851a193f32434cc2dc0 | False | 0.38232421875 | data | 3.735234737511919 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x46000 | 0xc | 0x200 | 8658c1b1f347026cd1e3e838036b5a8c | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x440a0 | 0x448 | data | 0.4324817518248175 | ||
RT_MANIFEST | 0x444e8 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T12:06:59.338810+0100 | 2046045 | ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization) | 1 | 192.168.2.4 | 49730 | 4.251.123.83 | 6677 | TCP |
2024-10-31T12:06:59.992193+0100 | 2046056 | ET MALWARE Redline Stealer/MetaStealer Family Activity (Response) | 1 | 4.251.123.83 | 6677 | 192.168.2.4 | 49730 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 31, 2024 12:06:58.312254906 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:58.317732096 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:58.317804098 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:58.332364082 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:58.337269068 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.306874037 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.338809967 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:59.343698978 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.696351051 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.736031055 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:59.740917921 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991625071 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991638899 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991650105 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991661072 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991672039 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991683960 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991694927 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991705894 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991717100 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991728067 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.991729975 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:59.991821051 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:59.991821051 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:59.992192984 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.992273092 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:06:59.992331028 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:06:59.996680975 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.037889004 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:00.110941887 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.110960007 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.110975027 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.111015081 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:00.111061096 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.111073017 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.111083031 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.111119986 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:00.111119986 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:00.111426115 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:00.162856102 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.304802895 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.309880018 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309897900 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309915066 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309925079 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309932947 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309957981 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309967041 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.309979916 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.310004950 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.310015917 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.310081005 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.310223103 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.310286999 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.314860106 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314870119 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314904928 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314918995 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314928055 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314937115 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314953089 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.314959049 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.314996958 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.315021992 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.315026045 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.315061092 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.315071106 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.315083027 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.315105915 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.315141916 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.315179110 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.315193892 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.315254927 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.319950104 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.319993019 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320012093 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320066929 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320075989 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320077896 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320116997 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320168972 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320194006 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320266008 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320295095 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320343018 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320358038 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320413113 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320424080 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320425987 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320435047 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320481062 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.320506096 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320518017 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320527077 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320549965 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320559978 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320614100 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320624113 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320637941 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320647001 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320699930 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320708990 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320717096 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320724964 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320734978 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320744038 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.320802927 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.324927092 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.324995041 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.325005054 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325088024 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.325131893 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325140953 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325324059 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325333118 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325366020 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.325429916 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.325453043 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325462103 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325478077 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325488091 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325519085 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.325550079 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325553894 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.325558901 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325575113 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325584888 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325620890 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325629950 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325655937 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325664997 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325701952 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325711012 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325752974 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325764894 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325786114 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325836897 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325875044 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325884104 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325915098 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.325923920 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326062918 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326071978 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326081991 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326128960 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326138020 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326169014 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326205015 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326214075 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326221943 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326236963 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326246023 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326318979 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326327085 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326334953 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326343060 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326359034 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326368093 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326375961 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326385021 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326447964 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326456070 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326463938 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326472044 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326483011 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326492071 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326500893 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.326535940 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326545000 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326608896 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326618910 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326656103 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.326692104 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326700926 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326708078 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326716900 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326733112 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326741934 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326750994 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326760054 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326797009 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326806068 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326832056 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326839924 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.326874971 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.329801083 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.329847097 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.329895020 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.329905033 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330135107 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330224991 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330233097 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330266953 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330388069 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330473900 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330524921 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330558062 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330612898 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330621004 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330630064 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330645084 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330684900 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330718040 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330728054 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330765009 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.330800056 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331058025 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.331196070 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.331463099 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331471920 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331480026 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331502914 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331511974 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331569910 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331578970 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331643105 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331650972 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331657887 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331667900 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331799030 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331808090 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331820965 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331830025 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331845999 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331854105 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331867933 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331938982 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331947088 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331955910 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331965923 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331979036 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.331995010 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332004070 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332012892 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332029104 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332037926 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332045078 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332082987 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332091093 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332098961 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332108974 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332169056 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332178116 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332185030 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332222939 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332231998 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332238913 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332273006 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332282066 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332288980 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332319975 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332329035 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332335949 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332350969 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332360983 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332370043 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332376957 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332389116 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332391977 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332396984 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.332463026 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.335966110 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.335982084 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336042881 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336050987 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336102009 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336111069 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336117983 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336133003 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336149931 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336159945 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336169004 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336198092 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336206913 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336215973 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336224079 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336240053 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336247921 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336256027 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336265087 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336293936 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336302996 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336309910 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336317062 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336332083 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336339951 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336349010 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336359024 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336420059 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336427927 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336436033 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336451054 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336460114 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336468935 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336488008 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.336505890 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336514950 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336524010 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336543083 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336551905 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336561918 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336572886 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336581945 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336595058 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.336607933 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336616993 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336654902 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336663008 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336672068 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336692095 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336699963 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336709023 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336736917 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336745977 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336783886 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.336792946 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341470003 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341478109 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341526031 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341535091 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341569901 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341578960 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341588974 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341604948 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341690063 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341698885 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341706038 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341715097 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341732025 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341741085 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341756105 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341763973 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341814995 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341824055 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341836929 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.341871977 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341881990 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341906071 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341914892 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341926098 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.341969967 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.341978073 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342010975 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342020988 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342027903 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342036009 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342058897 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342068911 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342102051 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342154980 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342164040 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342171907 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342189074 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342197895 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342231989 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342241049 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342281103 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342293978 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342348099 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342392921 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342442036 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342506886 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342515945 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342557907 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342566967 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342573881 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342591047 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342600107 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342653036 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342662096 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.342670918 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346827984 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346837044 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346890926 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346899986 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346908092 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346915960 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346925974 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346935987 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346952915 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346961021 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346988916 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.346997976 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347012997 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347022057 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347032070 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347040892 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347057104 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347064972 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347080946 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347090006 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347131014 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347141027 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347153902 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347162962 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347217083 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347229004 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347238064 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347248077 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347255945 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347273111 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347281933 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347290039 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347369909 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347379923 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347387075 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347394943 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347402096 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347402096 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.347409964 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347419024 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347435951 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347445011 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347455025 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347472906 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347482920 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347491980 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347503901 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347510099 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.347512960 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347523928 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347539902 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347548962 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347552061 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347569942 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.347578049 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352405071 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352413893 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352421999 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352431059 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352509022 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352519035 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352526903 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352535963 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352545023 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352554083 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352569103 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352576971 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352591991 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352601051 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352610111 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352618933 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352629900 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352638960 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352648020 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352657080 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352696896 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352705002 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352713108 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352721930 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352730989 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352740049 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352747917 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352763891 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352772951 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352790117 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352798939 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352813959 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352818012 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352864981 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.352876902 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352886915 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352894068 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352904081 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352919102 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352927923 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352936983 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352946997 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352956057 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352971077 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352987051 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.352989912 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.352997065 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.365987062 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.370781898 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.382971048 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.383111954 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.383112907 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.383218050 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.387897015 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.387908936 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.387936115 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.387945890 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.387994051 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388003111 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388070107 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388078928 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388093948 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388102055 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388117075 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388127089 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388164043 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388211012 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.388266087 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.412858963 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.417808056 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.418004990 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Oct 31, 2024 12:07:02.422846079 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:02.422925949 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:06.168561935 CET | 6677 | 49730 | 4.251.123.83 | 192.168.2.4 |
Oct 31, 2024 12:07:06.182425976 CET | 49730 | 6677 | 192.168.2.4 | 4.251.123.83 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:06:55 |
Start date: | 31/10/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x390000 |
File size: | 271'360 bytes |
MD5 hash: | 500904922500A6B286EBC7B6AA791E24 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 07:06:56 |
Start date: | 31/10/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 07:06:56 |
Start date: | 31/10/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6a0000 |
File size: | 262'432 bytes |
MD5 hash: | 8FDF47E0FF70C40ED3A17014AEEA4232 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 13.2% |
Dynamic/Decrypted Code Coverage: | 1.5% |
Signature Coverage: | 4.3% |
Total number of Nodes: | 1899 |
Total number of Limit Nodes: | 8 |
Graph
Function 6CF03950 Relevance: 67.1, APIs: 24, Strings: 12, Instructions: 4057nativememorythreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF01210 Relevance: 45.1, APIs: 18, Strings: 7, Instructions: 1311filememoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 027008AC Relevance: 2.8, Strings: 2, Instructions: 295COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02703B8D Relevance: 1.5, Strings: 1, Instructions: 257COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0270245C Relevance: 1.4, Strings: 1, Instructions: 197COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02705C98 Relevance: 1.4, Strings: 1, Instructions: 153COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02704167 Relevance: 1.4, Strings: 1, Instructions: 141COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02705908 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 027058F9 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 027058E1 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02701464 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF08191 Relevance: 3.1, APIs: 2, Instructions: 76COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0E7DC Relevance: 3.1, APIs: 2, Instructions: 65COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0270537C Relevance: 1.6, APIs: 1, Instructions: 56libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 027061B9 Relevance: 1.6, APIs: 1, Instructions: 56libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02705364 Relevance: 1.3, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02706549 Relevance: 1.3, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF02690 Relevance: 4.6, Strings: 3, Instructions: 828COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF08B38 Relevance: 1.6, APIs: 1, Instructions: 147COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02703820 Relevance: 1.4, Strings: 1, Instructions: 115COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02703830 Relevance: 1.4, Strings: 1, Instructions: 109COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02702D00 Relevance: 1.4, Strings: 1, Instructions: 102COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6CF0E70B Relevance: 1.3, APIs: 1, Instructions: 5memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02704B48 Relevance: .4, Instructions: 425COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6CF03750 Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0A3CA Relevance: 12.6, APIs: 4, Strings: 3, Instructions: 303COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0E33A Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 74COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0B57E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0FFF8 Relevance: 7.7, APIs: 5, Instructions: 197COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF09FF2 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 27libraryCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0CD88 Relevance: 6.1, APIs: 4, Instructions: 82COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0E1DF Relevance: 6.1, APIs: 4, Instructions: 74COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 6CF0A76F Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 112COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Execution Graph
Execution Coverage: | 16.3% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0.8% |
Total number of Nodes: | 355 |
Total number of Limit Nodes: | 26 |
Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE3FF1 Relevance: .6, Instructions: 642COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE3890 Relevance: .5, Instructions: 464COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE1BD8 Relevance: .4, Instructions: 407COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073C949C Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 117fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073C94A8 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 110fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE89A0 Relevance: 3.4, Instructions: 3443COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE6EC0 Relevance: 2.6, Strings: 2, Instructions: 116COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDC5D9 Relevance: 1.7, APIs: 1, Instructions: 198COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE5698 Relevance: 1.6, Strings: 1, Instructions: 360COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD5F7D Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DD48A0 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073CBA25 Relevance: 1.6, APIs: 1, Instructions: 89fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073CBA30 Relevance: 1.6, APIs: 1, Instructions: 82fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDD370 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDEEC8 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06FB8DA9 Relevance: 1.6, APIs: 1, Instructions: 55libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06FB8DB0 Relevance: 1.6, APIs: 1, Instructions: 50libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06FFC074 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDC7D8 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06FFCA53 Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EF0548 Relevance: 1.5, APIs: 1, Instructions: 44comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EF0550 Relevance: 1.5, APIs: 1, Instructions: 43comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE3E48 Relevance: 1.4, Strings: 1, Instructions: 149COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE6659 Relevance: 1.4, Strings: 1, Instructions: 140COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE3E37 Relevance: 1.3, Strings: 1, Instructions: 79COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE31D8 Relevance: .5, Instructions: 460COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE4D10 Relevance: .4, Instructions: 450COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE0040 Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE85FA Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE0E28 Relevance: .2, Instructions: 213COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EECA88 Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE1BC8 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE2E20 Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEDC30 Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEEB90 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE88CA Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEDDE8 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE11E8 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEEB82 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D6D210 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE31C9 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEE932 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE11D9 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EED550 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EED541 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE387C Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE0006 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEE7A8 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEDB78 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7D005 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEE798 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE3861 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE65B9 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7AC8 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEE940 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D6D20B Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE4AA9 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EED619 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EED628 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7668 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEFC00 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE65C8 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE2FA0 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D6D5D9 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE6EB1 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE75F8 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE8932 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D6D5D8 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEEB32 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEDB68 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE88F0 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE8900 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7658 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEEB40 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EEE0F0 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE81B2 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7C04 Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7E6C Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7DCA Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE7D28 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06EE88D8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|