Source: http://185.215.113.43/Zu7JuNko/index.php5763001 |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpa |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpm |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpu |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpn(S |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.43/Zu7JuNko/index.phpsdX |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/68b591d6548ec281/freebl3.dll3 |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpK% |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.43/Zu7JuNko/index.php3 |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/68b591d6548ec281/softokn3.dllz/; |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.php%/ |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpSession |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.16/steam/random.exe:2 |
Avira URL Cloud: Label: phishing |
Source: http://185.215.113.16/steam/random.exe?3 |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.16/steam/random.exeZ |
Avira URL Cloud: Label: phishing |
Source: http://185.215.113.16/steam/random.exe61395d7fC_ |
Avira URL Cloud: Label: phishing |
Source: http://185.215.113.16/mine/random.exe;R |
Avira URL Cloud: Label: phishing |
Source: http://185.215.113.206/68b591d6548ec281/nss3.dllG |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.16/off/random.exek3; |
Avira URL Cloud: Label: phishing |
Source: http://185.215.113.206/c4becf79229cb002.php7Z |
Avira URL Cloud: Label: malware |
Source: http://185.215.113.206/c4becf79229cb002.phpQ |
Avira URL Cloud: Label: malware |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C71A9A0 PK11SDR_Decrypt,PORT_NewArena_Util,SEC_QuickDERDecodeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_GetInternalKeySlot,PK11_Authenticate,PORT_FreeArena_Util,PK11_ListFixedKeysInSlot,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_FreeSymKey,PORT_FreeArena_Util,PK11_FreeSymKey,SECITEM_ZfreeItem_Util, |
0_2_6C71A9A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C714440 PK11_PrivDecrypt, |
0_2_6C714440 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6E4420 SECKEY_DestroyEncryptedPrivateKeyInfo,memset,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,SECITEM_ZfreeItem_Util,free, |
0_2_6C6E4420 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C7144C0 PK11_PubEncrypt, |
0_2_6C7144C0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C7625B0 PK11_Encrypt,memcpy,PR_SetError,PK11_Encrypt, |
0_2_6C7625B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6F8670 PK11_ExportEncryptedPrivKeyInfo, |
0_2_6C6F8670 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C71A650 PK11SDR_Encrypt,PORT_NewArena_Util,PK11_GetInternalKeySlot,PK11_Authenticate,SECITEM_ZfreeItem_Util,TlsGetValue,EnterCriticalSection,PR_Unlock,PK11_CreateContextBySymKey,PK11_GetBlockSize,PORT_Alloc_Util,memcpy,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PORT_ArenaAlloc_Util,PK11_CipherOp,SEC_ASN1EncodeItem_Util,SECITEM_ZfreeItem_Util,PORT_FreeArena_Util,PK11_DestroyContext, |
0_2_6C71A650 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6FE6E0 PK11_AEADOp,TlsGetValue,EnterCriticalSection,PORT_Alloc_Util,PK11_Encrypt,PORT_Alloc_Util,memcpy,memcpy,PR_SetError,PR_SetError,PR_Unlock,PR_SetError,PR_Unlock,PK11_Decrypt,PR_GetCurrentThread,PK11_Decrypt,PK11_Encrypt,memcpy,memcpy,PR_SetError,free, |
0_2_6C6FE6E0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C73A730 SEC_PKCS12AddCertAndKey,PORT_ArenaMark_Util,PORT_ArenaMark_Util,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,PK11_GetInternalKeySlot,PK11_FindKeyByAnyCert,SECKEY_DestroyPrivateKey,PORT_ArenaAlloc_Util,SECKEY_DestroyEncryptedPrivateKeyInfo,strlen,PR_SetError,PORT_FreeArena_Util,PORT_FreeArena_Util,PORT_ArenaAlloc_Util,PR_SetError, |
0_2_6C73A730 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C740180 SECMIME_DecryptionAllowed,SECOID_GetAlgorithmTag_Util, |
0_2_6C740180 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C7143B0 PK11_PubEncryptPKCS1,PR_SetError, |
0_2_6C7143B0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C737C00 SEC_PKCS12DecoderImportBags,PR_SetError,NSS_OptionGet,CERT_DestroyCertificate,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECKEY_DestroyPublicKey,SECITEM_ZfreeItem_Util,PR_SetError,SECOID_FindOID_Util,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,SECOID_GetAlgorithmTag_Util,SECITEM_CopyItem_Util,PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECITEM_ZfreeItem_Util,SECKEY_DestroyPublicKey,PK11_ImportPublicKey,SECOID_FindOID_Util, |
0_2_6C737C00 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C6F7D60 PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,SECOID_FindOID_Util,SECOID_FindOIDByTag_Util,PK11_PBEKeyGen,PK11_GetPadMechanism,PK11_UnwrapPrivKey,PK11_FreeSymKey,SECITEM_ZfreeItem_Util,PK11_PBEKeyGen,SECITEM_ZfreeItem_Util,PK11_FreeSymKey,PK11_ImportPublicKey,SECKEY_DestroyPublicKey, |
0_2_6C6F7D60 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C73BD30 SEC_PKCS12IsEncryptionAllowed,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy,NSS_GetAlgorithmPolicy, |
0_2_6C73BD30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C739EC0 SEC_PKCS12CreateUnencryptedSafe,PORT_ArenaMark_Util,PORT_ArenaAlloc_Util,PR_SetError,PR_SetError,SEC_PKCS7DestroyContentInfo, |
0_2_6C739EC0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C713FF0 PK11_PrivDecryptPKCS1, |
0_2_6C713FF0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C713850 PK11_Encrypt,TlsGetValue,EnterCriticalSection,SEC_PKCS12SetPreferredCipher,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_SetError, |
0_2_6C713850 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C719840 NSS_Get_SECKEY_EncryptedPrivateKeyInfoTemplate, |
0_2_6C719840 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C73DA40 SEC_PKCS7ContentIsEncrypted, |
0_2_6C73DA40 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C747410 NSS_SecureMemcmp,PR_SetError,PK11_Decrypt, |
0_2_6C747410 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C713560 PK11_Decrypt,TlsGetValue,EnterCriticalSection,SEC_PKCS12SetPreferredCipher,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_Unlock,TlsGetValue,EnterCriticalSection,PR_Unlock,PR_SetError, |
0_2_6C713560 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_6C70F050 PR_smprintf,SEC_CertNicknameConflict,strlen,realloc,memset,realloc,strlen,free,PR_smprintf,memcpy,PORT_NewArena_Util,PR_SetError,PORT_FreeArena_Util,PR_SetError,PORT_NewArena_Util,PR_SetError,PORT_FreeArena_Util,PORT_NewArena_Util,PR_SetError,PORT_FreeArena_Util,memcpy,PORT_NewArena_Util,PR_SetError,PORT_FreeArena_Util,PR_SetError,PR_SetError,PR_GetCurrentThread,PK11_ImportPublicKey,SECKEY_DestroyPublicKey,PK11_GenerateRandom,SECKEY_DestroyPrivateKey,PR_SetError,free,free,free,free,PK11_FindCertInSlot,PORT_NewArena_Util,free,PK11_ImportCert,PR_SetError,free,CERT_DestroyCertificate,PORT_FreeArena_Util,PR_GetCurrentThread,PORT_ArenaAlloc_Util,PORT_ArenaAlloc_Util,PR_SetError,PR_GetCurrentThread,strlen,PR_SetError,PR_GetCurrentThread,PK11_HasAttributeSet,PK11_HasAttributeSet,PK11_HasAttributeSet,PK11_HasAttributeSet,PK11_HasAttributeSet,PK11_ImportEncryptedPrivateKeyInfoAndReturnKey,PR_SetError,free,SECKEY_DestroyPrivateKey,SECKEY_DestroyEncryptedPrivateKeyInfo,PR_SetError, |
0_2_6C70F050 |
Source: |
Binary string: mozglue.pdbP source: file.exe, 00000000.00000002.2016890475.000000006F8ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr |
Source: |
Binary string: freebl3.pdb source: freebl3[1].dll.0.dr, freebl3.dll.0.dr |
Source: |
Binary string: freebl3.pdbp source: freebl3[1].dll.0.dr, freebl3.dll.0.dr |
Source: |
Binary string: nss3.pdb@ source: file.exe, 00000000.00000002.2016681151.000000006C7EF000.00000002.00000001.01000000.00000009.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr |
Source: |
Binary string: softokn3.pdb@ source: softokn3[1].dll.0.dr, softokn3.dll.0.dr |
Source: |
Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.0.dr, vcruntime140[1].dll.0.dr |
Source: |
Binary string: d:\agent\_work\1\s\binaries\x86ret\bin\i386\\msvcp140.i386.pdb source: msvcp140[1].dll.0.dr, msvcp140.dll.0.dr |
Source: |
Binary string: nss3.pdb source: file.exe, 00000000.00000002.2016681151.000000006C7EF000.00000002.00000001.01000000.00000009.sdmp, nss3.dll.0.dr, nss3[1].dll.0.dr |
Source: |
Binary string: E:\defOff\defOff\defOff\obj\Release\defOff.pdb source: b617b009b1.exe, 00000010.00000002.2764523690.0000000000232000.00000040.00000001.01000000.00000010.sdmp, b617b009b1.exe, 00000010.00000003.2630021781.0000000004C30000.00000004.00001000.00020000.00000000.sdmp, b617b009b1.exe, 00000011.00000003.2764593003.0000000004860000.00000004.00001000.00020000.00000000.sdmp, b617b009b1.exe, 00000011.00000002.2805536891.0000000000232000.00000040.00000001.01000000.00000010.sdmp, b617b009b1.exe, 00000012.00000002.2882259694.0000000000232000.00000040.00000001.01000000.00000010.sdmp, b617b009b1.exe, 00000012.00000003.2842125475.0000000005090000.00000004.00001000.00020000.00000000.sdmp |
Source: |
Binary string: mozglue.pdb source: file.exe, 00000000.00000002.2016890475.000000006F8ED000.00000002.00000001.01000000.0000000A.sdmp, mozglue[1].dll.0.dr, mozglue.dll.0.dr |
Source: |
Binary string: softokn3.pdb source: softokn3[1].dll.0.dr, softokn3.dll.0.dr |
Source: Network traffic |
Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.4:49730 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044244 - Severity 1 - ET MALWARE Win32/Stealc Requesting browsers Config from C2 : 192.168.2.4:49730 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044245 - Severity 1 - ET MALWARE Win32/Stealc Active C2 Responding with browsers Config : 185.215.113.206:80 -> 192.168.2.4:49730 |
Source: Network traffic |
Suricata IDS: 2044246 - Severity 1 - ET MALWARE Win32/Stealc Requesting plugins Config from C2 : 192.168.2.4:49730 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044247 - Severity 1 - ET MALWARE Win32/Stealc/Vidar Stealer Active C2 Responding with plugins Config : 185.215.113.206:80 -> 192.168.2.4:49730 |
Source: Network traffic |
Suricata IDS: 2044248 - Severity 1 - ET MALWARE Win32/Stealc Submitting System Information to C2 : 192.168.2.4:49730 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2856147 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M3 : 192.168.2.4:49782 -> 185.215.113.43:80 |
Source: Network traffic |
Suricata IDS: 2856121 - Severity 1 - ETPRO MALWARE Amadey CnC Activity M2 : 192.168.2.4:49801 -> 185.215.113.43:80 |
Source: Network traffic |
Suricata IDS: 2044243 - Severity 1 - ET MALWARE [SEKOIA.IO] Win32/Stealc C2 Check-in : 192.168.2.4:49802 -> 185.215.113.206:80 |
Source: Network traffic |
Suricata IDS: 2044696 - Severity 1 - ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 : 192.168.2.4:49804 -> 185.215.113.43:80 |
Source: Network traffic |
Suricata IDS: 2044696 - Severity 1 - ET MALWARE Win32/Amadey Host Fingerprint Exfil (POST) M2 : 192.168.2.4:49806 -> 185.215.113.43:80 |
Source: Network traffic |
Suricata IDS: 2856122 - Severity 1 - ETPRO MALWARE Amadey CnC Response M1 : 185.215.113.43:80 -> 192.168.2.4:49788 |