Windows
Analysis Report
taskhost.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- taskhost.exe (PID: 6504 cmdline:
"C:\Users\ user\Deskt op\taskhos t.exe" MD5: 3296704171FE01C0FC4FCDD02F2695CA) - powershell.exe (PID: 7456 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -Execution Policy Byp ass Add-Mp Preference -Exclusio nPath 'C:\ Users\user \Desktop\t askhost.ex e' MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 7464 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7816 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -Execution Policy Byp ass Add-Mp Preference -Exclusio nProcess ' taskhost.e xe' MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 7824 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: |
Source: | Author: frack113: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: vburov: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-13T11:50:02.449310+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49914 | 104.26.2.16 | 443 | TCP |
2024-12-13T11:50:11.197865+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49937 | 104.26.2.16 | 443 | TCP |
2024-12-13T11:50:15.492597+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49943 | 104.26.2.16 | 443 | TCP |
2024-12-13T11:50:26.711757+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49976 | 104.26.2.16 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | DNS query: |
Source: | File source: | ||
Source: | File source: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FFAAC911511 | |
Source: | Code function: | 0_2_00007FFAAC915656 | |
Source: | Code function: | 0_2_00007FFAAC916402 | |
Source: | Code function: | 12_2_00007FFAAC9D32A1 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: | ||
Source: | Base64 encoded string: | ||
Source: | Base64 encoded string: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 8_2_00007FFAAC7BD2A6 | |
Source: | Code function: | 8_2_00007FFAAC8D5D02 | |
Source: | Code function: | 8_2_00007FFAAC8D6CD2 | |
Source: | Code function: | 8_2_00007FFAAC8D00C1 | |
Source: | Code function: | 8_2_00007FFAAC8D5CA2 | |
Source: | Code function: | 8_2_00007FFAAC8D583A | |
Source: | Code function: | 8_2_00007FFAAC9A231B | |
Source: | Code function: | 12_2_00007FFAAC7ED2A6 | |
Source: | Code function: | 12_2_00007FFAAC901239 | |
Source: | Code function: | 12_2_00007FFAAC9D231B |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | HTTP traffic detected: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | Code function: | 0_2_00007FFAAC916C01 |
Source: | Process queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process created: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 DLL Side-Loading | 11 Process Injection | 11 Disable or Modify Tools | OS Credential Dumping | 321 Security Software Discovery | Remote Services | 11 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 PowerShell | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 51 Virtualization/Sandbox Evasion | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 51 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Obfuscated Files or Information | LSA Secrets | 1 System Network Configuration Discovery | SSH | Keylogging | 4 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 23 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
79% | ReversingLabs | Win32.Exploit.XWorm | ||
100% | Avira | TR/Spy.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
rentry.co | 104.26.2.16 | true | false | high | |
ip-api.com | 208.95.112.1 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
208.95.112.1 | ip-api.com | United States | 53334 | TUT-ASUS | false | |
104.26.2.16 | rentry.co | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1574512 |
Start date and time: | 2024-12-13 11:47:28 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | taskhost.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@7/9@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 13.107.246.63, 20.109.210.53
- Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target powershell.exe, PID 7456 because it is empty
- Execution Graph export aborted for target powershell.exe, PID 7816 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: taskhost.exe
Time | Type | Description |
---|---|---|
05:48:36 | API Interceptor | |
07:26:51 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
208.95.112.1 | Get hash | malicious | Blackshades | Browse |
| |
Get hash | malicious | Blackshades | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ip-api.com | Get hash | malicious | Blackshades | Browse |
| |
Get hash | malicious | Blackshades | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
| ||
rentry.co | Get hash | malicious | LummaC Stealer | Browse |
| |
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
TUT-ASUS | Get hash | malicious | Blackshades | Browse |
| |
Get hash | malicious | Blackshades | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Quasar | Browse |
| |
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 0.34726597513537405 |
Encrypted: | false |
SSDEEP: | 3:Nlll:Nll |
MD5: | 446DD1CF97EABA21CF14D03AEBC79F27 |
SHA1: | 36E4CC7367E0C7B40F4A8ACE272941EA46373799 |
SHA-256: | A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF |
SHA-512: | A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 5.903833440110244 |
TrID: |
|
File name: | taskhost.exe |
File size: | 63'488 bytes |
MD5: | 3296704171fe01c0fc4fcdd02f2695ca |
SHA1: | e0bd82f06d94c0e32d7f6bb9f80f57f8e73a84be |
SHA256: | b8c65f4588d2d9b76823e7ad22b71a3717792a505a4048314cb2ccba9a976e26 |
SHA512: | 8d1583be1930e1f819149a1a5b57ec5187b08eefe8dc306f6dc74506dd25c85a60b2b282c420060d1854c36fc8642f0754708fd87dd97ed19f2229c76334837b |
SSDEEP: | 1536:5Y+sUM6h2S7Uv/ecC4Q5tUWTbbIqml1gd6VOnuhQvxU5AZXep:Xh2S7qWckDTbsdmaOuhyeaOp |
TLSH: | B7536B2877A94529E1FFAFF25DF17216D73AB2271803976F34C9428A0613E89CE412F5 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......g............................~.... ... ....@.. .......................`............@................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x410d7e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x670BD8AB [Sun Oct 13 14:26:51 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x10d28 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x12000 | 0x4ce | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x14000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xed84 | 0xee00 | db3d87c7ddc80bab0c79875c04206eb4 | False | 0.6065848214285714 | data | 5.989469653584427 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x12000 | 0x4ce | 0x600 | d1e3bd86534ea351b898bcf1136c1c31 | False | 0.3743489583333333 | data | 3.7196984311115475 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x14000 | 0xc | 0x200 | 81ddd4dfdd39bd346d681772a91dbbdb | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x120a0 | 0x244 | data | 0.4724137931034483 | ||
RT_MANIFEST | 0x122e4 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-13T11:50:02.449310+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49914 | 104.26.2.16 | 443 | TCP |
2024-12-13T11:50:11.197865+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49937 | 104.26.2.16 | 443 | TCP |
2024-12-13T11:50:15.492597+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49943 | 104.26.2.16 | 443 | TCP |
2024-12-13T11:50:26.711757+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49976 | 104.26.2.16 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 13, 2024 11:48:28.908750057 CET | 49701 | 80 | 192.168.2.7 | 208.95.112.1 |
Dec 13, 2024 11:48:29.030231953 CET | 80 | 49701 | 208.95.112.1 | 192.168.2.7 |
Dec 13, 2024 11:48:29.030428886 CET | 49701 | 80 | 192.168.2.7 | 208.95.112.1 |
Dec 13, 2024 11:48:29.031506062 CET | 49701 | 80 | 192.168.2.7 | 208.95.112.1 |
Dec 13, 2024 11:48:29.151432991 CET | 80 | 49701 | 208.95.112.1 | 192.168.2.7 |
Dec 13, 2024 11:48:30.126492023 CET | 80 | 49701 | 208.95.112.1 | 192.168.2.7 |
Dec 13, 2024 11:48:30.173443079 CET | 49701 | 80 | 192.168.2.7 | 208.95.112.1 |
Dec 13, 2024 11:48:59.719141960 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:48:59.719197989 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:48:59.719279051 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:48:59.726917982 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:48:59.726955891 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:00.950634956 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:00.950762033 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:00.967297077 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:00.967323065 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:00.967683077 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:01.035345078 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:01.362351894 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:01.407339096 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.026838064 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.026875019 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.026911020 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.026949883 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.026963949 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:02.027023077 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.027043104 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:02.027045012 CET | 443 | 49762 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:02.027095079 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:02.040452957 CET | 49762 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:05.057068110 CET | 49701 | 80 | 192.168.2.7 | 208.95.112.1 |
Dec 13, 2024 11:49:05.058350086 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:05.058410883 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:05.058480024 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:05.059190989 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:05.059206009 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:05.177448034 CET | 80 | 49701 | 208.95.112.1 | 192.168.2.7 |
Dec 13, 2024 11:49:05.177546024 CET | 49701 | 80 | 192.168.2.7 | 208.95.112.1 |
Dec 13, 2024 11:49:06.270939112 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:06.272731066 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:06.272761106 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064346075 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064409971 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064449072 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064491987 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064497948 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:07.064573050 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064611912 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:07.064717054 CET | 443 | 49773 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:07.064791918 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:07.065160990 CET | 49773 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:10.085870981 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:10.085905075 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:10.085967064 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:10.086218119 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:10.086225986 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:11.302011967 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:11.303594112 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:11.303636074 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:12.104912996 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:12.104948044 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:12.105117083 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:12.105129957 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:12.105173111 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:12.105237007 CET | 443 | 49788 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:12.105292082 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:12.105415106 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:12.106971979 CET | 49788 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:15.112310886 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:15.112344980 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:15.112420082 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:15.112729073 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:15.112741947 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:16.417392969 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:16.418838978 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:16.418860912 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211350918 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211410999 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211436987 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211458921 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:17.211483002 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211519957 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:17.211528063 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211615086 CET | 443 | 49800 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:17.211658955 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:17.212008953 CET | 49800 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:20.221699953 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:20.221755028 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:20.221811056 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:20.222090006 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:20.222100973 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:21.441873074 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:21.443259001 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:21.443300962 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255238056 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255281925 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255412102 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255414009 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:22.255435944 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255474091 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:22.255480051 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255532026 CET | 443 | 49811 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:22.255574942 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:22.256032944 CET | 49811 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:25.268548012 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:25.268596888 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:25.268671036 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:25.268856049 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:25.268873930 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:26.485707045 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:26.487339973 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:26.487361908 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277333021 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277457952 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277559042 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:27.277575016 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277602911 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277645111 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:27.277688026 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277872086 CET | 443 | 49823 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:27.277921915 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:27.278254986 CET | 49823 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:30.284550905 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:30.284607887 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:30.284730911 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:30.285099983 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:30.285110950 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:31.507860899 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:31.509243965 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:31.509275913 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306035995 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306144953 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306190014 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306200027 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:32.306210041 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306247950 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:32.306252956 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306279898 CET | 443 | 49839 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:32.306314945 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:32.306802988 CET | 49839 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:35.315500021 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:35.315541029 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:35.315651894 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:35.315897942 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:35.315911055 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:36.528944016 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:36.563114882 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:36.563163042 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335514069 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335589886 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335621119 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335650921 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335678101 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:37.335716963 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335731983 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:37.335767031 CET | 443 | 49850 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:37.335809946 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:37.336395025 CET | 49850 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:40.519474983 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:40.519531965 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:40.519587994 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:40.520133972 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:40.520155907 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:41.731360912 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:41.732682943 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:41.732717991 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.529625893 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.529721022 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.529743910 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.529813051 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:42.529841900 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.530009985 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:42.530018091 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.530092001 CET | 443 | 49861 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:42.530136108 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:42.530577898 CET | 49861 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:45.535621881 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:45.535667896 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:45.539796114 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:45.540132046 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:45.540148973 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:46.751369953 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:46.753117085 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:46.753148079 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562103033 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562380075 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562408924 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562417984 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:47.562431097 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562474966 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:47.562536955 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562609911 CET | 443 | 49877 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:47.562658072 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:47.562997103 CET | 49877 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:50.565785885 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:50.565846920 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:50.565968037 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:50.566250086 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:50.566270113 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:51.777836084 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:51.779067993 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:51.779082060 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:52.347959995 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:52.348018885 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:52.348131895 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:52.348148108 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:52.348236084 CET | 443 | 49888 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:52.348301888 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:52.348889112 CET | 49888 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:55.363840103 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:55.363903999 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:55.363984108 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:55.364238024 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:55.364253998 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:56.581825018 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:56.583106041 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:56.583138943 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388350964 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388495922 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388571978 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:57.388592958 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388643980 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388704062 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:57.388725996 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388936996 CET | 443 | 49899 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:49:57.388991117 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:49:57.395432949 CET | 49899 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:00.410906076 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:00.410917997 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:00.411248922 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:00.411250114 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:00.411266088 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:01.624932051 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:01.655777931 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:01.655793905 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449294090 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449330091 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449352980 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449381113 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449414015 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:02.449414015 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:02.449436903 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449455976 CET | 443 | 49914 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:02.449707031 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:02.449995995 CET | 49914 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:05.159599066 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:05.159656048 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:05.159765005 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:05.160063028 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:05.160073042 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.371035099 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.372124910 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:06.372155905 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958297968 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958343029 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958431005 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:06.958453894 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958466053 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958513021 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:06.958518982 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958538055 CET | 443 | 49926 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:06.958585978 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:06.966924906 CET | 49926 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:09.410356998 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:09.410422087 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:09.410520077 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:09.410799980 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:09.410820007 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:10.622625113 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:10.638628960 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:10.638669014 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:11.197565079 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:11.197611094 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:11.197637081 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:11.197658062 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:11.197717905 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:11.197727919 CET | 443 | 49937 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:11.197745085 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:11.197767019 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:11.221839905 CET | 49937 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:13.430208921 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:13.430246115 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:13.430310011 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:13.430689096 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:13.430701971 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:14.654103041 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:14.655392885 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:14.655422926 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.492623091 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.492759943 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.492852926 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.492883921 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:15.492927074 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.492978096 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:15.492988110 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.493123055 CET | 443 | 49943 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:15.493175030 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:15.493506908 CET | 49943 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:17.471966028 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:17.472016096 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:17.472100019 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:17.472313881 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:17.472327948 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:18.703306913 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:18.704793930 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:18.704827070 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270010948 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270142078 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270194054 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:19.270207882 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270287037 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270332098 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:19.270337105 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270493031 CET | 443 | 49954 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:19.270548105 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:19.270812035 CET | 49954 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:21.050040007 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:21.050086975 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:21.050183058 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:21.050494909 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:21.050504923 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:22.264451027 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:22.266036034 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:22.266077042 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074033022 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074081898 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074146986 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:23.074187040 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074361086 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074395895 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:23.074403048 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074455976 CET | 443 | 49965 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:23.074500084 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:23.074815989 CET | 49965 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:24.684806108 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:24.684864998 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:24.684983969 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:24.685247898 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:24.685261965 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:25.909727097 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:25.957062960 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:25.978838921 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:25.978877068 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.711767912 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.711822987 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.711973906 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.712006092 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.712033033 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:26.712054014 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.712095022 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:26.712114096 CET | 443 | 49976 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:26.715708017 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:26.716751099 CET | 49976 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:28.159333944 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:28.159444094 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:28.159727097 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:28.160027981 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:28.160059929 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:29.518069983 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:29.564532042 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:29.564856052 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:29.564870119 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307090044 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307167053 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307203054 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307229042 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307251930 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:30.307329893 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307368040 CET | 443 | 49982 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:30.307388067 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:30.307418108 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:30.311434984 CET | 49982 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:31.612425089 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:31.612495899 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:31.612646103 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:31.612910032 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:31.612924099 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:32.823206902 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:32.824558973 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:32.824585915 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392554998 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392605066 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392679930 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:33.392734051 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392767906 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392817020 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:33.392823935 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392848015 CET | 443 | 49992 | 104.26.2.16 | 192.168.2.7 |
Dec 13, 2024 11:50:33.392891884 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Dec 13, 2024 11:50:34.552671909 CET | 49992 | 443 | 192.168.2.7 | 104.26.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 13, 2024 11:48:28.755964994 CET | 55809 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 13, 2024 11:48:28.896393061 CET | 53 | 55809 | 1.1.1.1 | 192.168.2.7 |
Dec 13, 2024 11:48:59.502892971 CET | 54297 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 13, 2024 11:48:59.718101978 CET | 53 | 54297 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 13, 2024 11:48:28.755964994 CET | 192.168.2.7 | 1.1.1.1 | 0xe416 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 13, 2024 11:48:59.502892971 CET | 192.168.2.7 | 1.1.1.1 | 0xd2 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 13, 2024 11:48:28.896393061 CET | 1.1.1.1 | 192.168.2.7 | 0xe416 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Dec 13, 2024 11:48:59.718101978 CET | 1.1.1.1 | 192.168.2.7 | 0xd2 | No error (0) | 104.26.2.16 | A (IP address) | IN (0x0001) | false | ||
Dec 13, 2024 11:48:59.718101978 CET | 1.1.1.1 | 192.168.2.7 | 0xd2 | No error (0) | 172.67.75.40 | A (IP address) | IN (0x0001) | false | ||
Dec 13, 2024 11:48:59.718101978 CET | 1.1.1.1 | 192.168.2.7 | 0xd2 | No error (0) | 104.26.3.16 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49701 | 208.95.112.1 | 80 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 13, 2024 11:48:29.031506062 CET | 80 | OUT | |
Dec 13, 2024 11:48:30.126492023 CET | 175 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49762 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:01 UTC | 71 | OUT | |
2024-12-13 10:49:02 UTC | 874 | IN | |
2024-12-13 10:49:02 UTC | 495 | IN | |
2024-12-13 10:49:02 UTC | 1369 | IN | |
2024-12-13 10:49:02 UTC | 1369 | IN | |
2024-12-13 10:49:02 UTC | 1227 | IN | |
2024-12-13 10:49:02 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49773 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:06 UTC | 71 | OUT | |
2024-12-13 10:49:07 UTC | 869 | IN | |
2024-12-13 10:49:07 UTC | 500 | IN | |
2024-12-13 10:49:07 UTC | 1369 | IN | |
2024-12-13 10:49:07 UTC | 1369 | IN | |
2024-12-13 10:49:07 UTC | 1222 | IN | |
2024-12-13 10:49:07 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49788 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:11 UTC | 71 | OUT | |
2024-12-13 10:49:12 UTC | 867 | IN | |
2024-12-13 10:49:12 UTC | 502 | IN | |
2024-12-13 10:49:12 UTC | 1369 | IN | |
2024-12-13 10:49:12 UTC | 1369 | IN | |
2024-12-13 10:49:12 UTC | 1220 | IN | |
2024-12-13 10:49:12 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49800 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:16 UTC | 71 | OUT | |
2024-12-13 10:49:17 UTC | 865 | IN | |
2024-12-13 10:49:17 UTC | 504 | IN | |
2024-12-13 10:49:17 UTC | 1369 | IN | |
2024-12-13 10:49:17 UTC | 1369 | IN | |
2024-12-13 10:49:17 UTC | 1218 | IN | |
2024-12-13 10:49:17 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49811 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:21 UTC | 71 | OUT | |
2024-12-13 10:49:22 UTC | 873 | IN | |
2024-12-13 10:49:22 UTC | 496 | IN | |
2024-12-13 10:49:22 UTC | 1369 | IN | |
2024-12-13 10:49:22 UTC | 1369 | IN | |
2024-12-13 10:49:22 UTC | 1226 | IN | |
2024-12-13 10:49:22 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49823 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:26 UTC | 71 | OUT | |
2024-12-13 10:49:27 UTC | 871 | IN | |
2024-12-13 10:49:27 UTC | 498 | IN | |
2024-12-13 10:49:27 UTC | 1369 | IN | |
2024-12-13 10:49:27 UTC | 1369 | IN | |
2024-12-13 10:49:27 UTC | 1224 | IN | |
2024-12-13 10:49:27 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49839 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:31 UTC | 71 | OUT | |
2024-12-13 10:49:32 UTC | 874 | IN | |
2024-12-13 10:49:32 UTC | 495 | IN | |
2024-12-13 10:49:32 UTC | 1369 | IN | |
2024-12-13 10:49:32 UTC | 1369 | IN | |
2024-12-13 10:49:32 UTC | 1227 | IN | |
2024-12-13 10:49:32 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49850 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:36 UTC | 71 | OUT | |
2024-12-13 10:49:37 UTC | 873 | IN | |
2024-12-13 10:49:37 UTC | 496 | IN | |
2024-12-13 10:49:37 UTC | 1369 | IN | |
2024-12-13 10:49:37 UTC | 1369 | IN | |
2024-12-13 10:49:37 UTC | 1225 | IN | |
2024-12-13 10:49:37 UTC | 6 | IN | |
2024-12-13 10:49:37 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49861 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:41 UTC | 71 | OUT | |
2024-12-13 10:49:42 UTC | 875 | IN | |
2024-12-13 10:49:42 UTC | 494 | IN | |
2024-12-13 10:49:42 UTC | 1369 | IN | |
2024-12-13 10:49:42 UTC | 1369 | IN | |
2024-12-13 10:49:42 UTC | 1228 | IN | |
2024-12-13 10:49:42 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49877 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:46 UTC | 71 | OUT | |
2024-12-13 10:49:47 UTC | 871 | IN | |
2024-12-13 10:49:47 UTC | 498 | IN | |
2024-12-13 10:49:47 UTC | 1369 | IN | |
2024-12-13 10:49:47 UTC | 1369 | IN | |
2024-12-13 10:49:47 UTC | 1224 | IN | |
2024-12-13 10:49:47 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49888 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:51 UTC | 71 | OUT | |
2024-12-13 10:49:52 UTC | 873 | IN | |
2024-12-13 10:49:52 UTC | 496 | IN | |
2024-12-13 10:49:52 UTC | 1369 | IN | |
2024-12-13 10:49:52 UTC | 1369 | IN | |
2024-12-13 10:49:52 UTC | 1226 | IN | |
2024-12-13 10:49:52 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.7 | 49899 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:49:56 UTC | 71 | OUT | |
2024-12-13 10:49:57 UTC | 867 | IN | |
2024-12-13 10:49:57 UTC | 502 | IN | |
2024-12-13 10:49:57 UTC | 1369 | IN | |
2024-12-13 10:49:57 UTC | 1369 | IN | |
2024-12-13 10:49:57 UTC | 1219 | IN | |
2024-12-13 10:49:57 UTC | 6 | IN | |
2024-12-13 10:49:57 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49914 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:01 UTC | 47 | OUT | |
2024-12-13 10:50:02 UTC | 867 | IN | |
2024-12-13 10:50:02 UTC | 502 | IN | |
2024-12-13 10:50:02 UTC | 1369 | IN | |
2024-12-13 10:50:02 UTC | 1369 | IN | |
2024-12-13 10:50:02 UTC | 1220 | IN | |
2024-12-13 10:50:02 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49926 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:06 UTC | 71 | OUT | |
2024-12-13 10:50:06 UTC | 867 | IN | |
2024-12-13 10:50:06 UTC | 502 | IN | |
2024-12-13 10:50:06 UTC | 1369 | IN | |
2024-12-13 10:50:06 UTC | 1369 | IN | |
2024-12-13 10:50:06 UTC | 1220 | IN | |
2024-12-13 10:50:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.7 | 49937 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:10 UTC | 47 | OUT | |
2024-12-13 10:50:11 UTC | 871 | IN | |
2024-12-13 10:50:11 UTC | 498 | IN | |
2024-12-13 10:50:11 UTC | 1369 | IN | |
2024-12-13 10:50:11 UTC | 1369 | IN | |
2024-12-13 10:50:11 UTC | 1224 | IN | |
2024-12-13 10:50:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.7 | 49943 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:14 UTC | 47 | OUT | |
2024-12-13 10:50:15 UTC | 875 | IN | |
2024-12-13 10:50:15 UTC | 494 | IN | |
2024-12-13 10:50:15 UTC | 1369 | IN | |
2024-12-13 10:50:15 UTC | 1369 | IN | |
2024-12-13 10:50:15 UTC | 1228 | IN | |
2024-12-13 10:50:15 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.7 | 49954 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:18 UTC | 71 | OUT | |
2024-12-13 10:50:19 UTC | 874 | IN | |
2024-12-13 10:50:19 UTC | 495 | IN | |
2024-12-13 10:50:19 UTC | 1369 | IN | |
2024-12-13 10:50:19 UTC | 1369 | IN | |
2024-12-13 10:50:19 UTC | 1227 | IN | |
2024-12-13 10:50:19 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.7 | 49965 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:22 UTC | 71 | OUT | |
2024-12-13 10:50:23 UTC | 867 | IN | |
2024-12-13 10:50:23 UTC | 502 | IN | |
2024-12-13 10:50:23 UTC | 1369 | IN | |
2024-12-13 10:50:23 UTC | 1369 | IN | |
2024-12-13 10:50:23 UTC | 1219 | IN | |
2024-12-13 10:50:23 UTC | 6 | IN | |
2024-12-13 10:50:23 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.7 | 49976 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:25 UTC | 47 | OUT | |
2024-12-13 10:50:26 UTC | 873 | IN | |
2024-12-13 10:50:26 UTC | 496 | IN | |
2024-12-13 10:50:26 UTC | 1369 | IN | |
2024-12-13 10:50:26 UTC | 1369 | IN | |
2024-12-13 10:50:26 UTC | 1226 | IN | |
2024-12-13 10:50:26 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.7 | 49982 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:29 UTC | 71 | OUT | |
2024-12-13 10:50:30 UTC | 867 | IN | |
2024-12-13 10:50:30 UTC | 502 | IN | |
2024-12-13 10:50:30 UTC | 1369 | IN | |
2024-12-13 10:50:30 UTC | 1369 | IN | |
2024-12-13 10:50:30 UTC | 1220 | IN | |
2024-12-13 10:50:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.7 | 49992 | 104.26.2.16 | 443 | 6504 | C:\Users\user\Desktop\taskhost.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-13 10:50:32 UTC | 71 | OUT | |
2024-12-13 10:50:33 UTC | 869 | IN | |
2024-12-13 10:50:33 UTC | 500 | IN | |
2024-12-13 10:50:33 UTC | 1369 | IN | |
2024-12-13 10:50:33 UTC | 1369 | IN | |
2024-12-13 10:50:33 UTC | 1222 | IN | |
2024-12-13 10:50:33 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 05:48:23 |
Start date: | 13/12/2024 |
Path: | C:\Users\user\Desktop\taskhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xb00000 |
File size: | 63'488 bytes |
MD5 hash: | 3296704171FE01C0FC4FCDD02F2695CA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 8 |
Start time: | 05:48:29 |
Start date: | 13/12/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7c0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 05:48:29 |
Start date: | 13/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 05:48:44 |
Start date: | 13/12/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 05:48:44 |
Start date: | 13/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 16% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 100% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC915656 Relevance: .5, Instructions: 475COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC916402 Relevance: .5, Instructions: 461COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9A6605 Relevance: .4, Instructions: 428COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC8D9EFB Relevance: .2, Instructions: 248COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC8D9758 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC7BE383 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC8DA47C Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC8D33B5 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9A414D Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9A4400 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9A41D1 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC8D6620 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9D3F6C Relevance: .7, Instructions: 684COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9D6605 Relevance: .4, Instructions: 435COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC90A900 Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC909760 Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC7EED40 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9D40BF Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9D43BC Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC9033B5 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|