Windows
Analysis Report
imagelogger.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- imagelogger.exe (PID: 3820 cmdline:
"C:\Users\ user\Deskt op\imagelo gger.exe" MD5: 9655B8120C0D0469EE87EEBDEECA3B4D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
{"C2 url": ["among-publication.at.ply.gg"], "Port": 42209, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.0"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Click to see the 3 entries |
System Summary |
---|
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T08:39:03.103686+0100 | 2853193 | 1 | Malware Command and Control Activity Detected | 192.168.2.9 | 49897 | 147.185.221.229 | 42209 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | DNS query: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Window created: | Jump to behavior |
Operating System Destruction |
---|
Source: | Process information set: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00007FF887B01C11 | |
Source: | Code function: | 0_2_00007FF887B06B02 | |
Source: | Code function: | 0_2_00007FF887B010FA | |
Source: | Code function: | 0_2_00007FF887B05D56 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: | ||
Source: | Base64 encoded string: | ||
Source: | Base64 encoded string: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00007FF887B024CA |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | HTTP traffic detected: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Anti Debugging |
---|
Source: | Code function: | 0_2_00007FF887B07301 |
Source: | Process queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 12 Windows Management Instrumentation | 2 Registry Run Keys / Startup Folder | 2 Registry Run Keys / Startup Folder | 11 Masquerading | OS Credential Dumping | 541 Security Software Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | LSASS Memory | 151 Virtualization/Sandbox Evasion | Remote Desktop Protocol | 1 Clipboard Data | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 151 Virtualization/Sandbox Evasion | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 1 System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | 12 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Software Packing | Cached Domain Credentials | 23 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
75% | Virustotal | Browse | ||
76% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT | ||
100% | Avira | HEUR/AGEN.1311620 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1311620 | ||
100% | Joe Sandbox ML | |||
76% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
4% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
among-publication.at.ply.gg | 147.185.221.229 | true | true |
| unknown |
ip-api.com | 208.95.112.1 | true | false | high | |
s-part-0035.t-0009.t-msedge.net | 13.107.246.63 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
208.95.112.1 | ip-api.com | United States | 53334 | TUT-ASUS | false | |
147.185.221.229 | among-publication.at.ply.gg | United States | 12087 | SALSGIVERUS | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1575694 |
Start date and time: | 2024-12-16 08:36:28 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 14s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | imagelogger.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@1/2@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 13.107.246.63, 52.149.20.212
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, azureedge-t-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
02:37:26 | API Interceptor | |
07:37:28 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
208.95.112.1 | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | Blackshades | Browse |
| ||
Get hash | malicious | ScreenConnect Tool, Amadey, LummaC Stealer, Vidar, XWorm, Xmrig | Browse |
| ||
Get hash | malicious | 77Rootkit, XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Discord Token Stealer, DotStealer | Browse |
| ||
Get hash | malicious | Discord Token Stealer, Millenuim RAT | Browse |
| ||
Get hash | malicious | Discord Token Stealer, DotStealer | Browse |
| ||
Get hash | malicious | AsyncRAT, Babadeda, XWorm | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
147.185.221.229 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Orcus | Browse | |||
Get hash | malicious | Orcus | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ip-api.com | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | Blackshades | Browse |
| ||
Get hash | malicious | ScreenConnect Tool, Amadey, LummaC Stealer, Vidar, XWorm, Xmrig | Browse |
| ||
Get hash | malicious | 77Rootkit, XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Discord Token Stealer, DotStealer | Browse |
| ||
Get hash | malicious | Discord Token Stealer, Millenuim RAT | Browse |
| ||
Get hash | malicious | Discord Token Stealer, DotStealer | Browse |
| ||
Get hash | malicious | AsyncRAT, Babadeda, XWorm | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
s-part-0035.t-0009.t-msedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Metasploit | Browse |
| ||
Get hash | malicious | Metasploit | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
SALSGIVERUS | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
TUT-ASUS | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | Blackshades | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | ScreenConnect Tool, Amadey, LummaC Stealer, Vidar, XWorm, Xmrig | Browse |
| ||
Get hash | malicious | 77Rootkit, XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Discord Token Stealer, DotStealer | Browse |
| ||
Get hash | malicious | Discord Token Stealer, Millenuim RAT | Browse |
| ||
Get hash | malicious | Discord Token Stealer, DotStealer | Browse |
| ||
Get hash | malicious | AsyncRAT, Babadeda, XWorm | Browse |
|
Process: | C:\Users\user\Desktop\imagelogger.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327680 |
Entropy (8bit): | 3.402515961281467 |
Encrypted: | false |
SSDEEP: | 3072:Bm4cvA/SDhVUYbg1Sc0dBYOzY4Xy0tv4L9witTOs/sh/A:oVTbGSldBSf0tvg3xs/ |
MD5: | 9655B8120C0D0469EE87EEBDEECA3B4D |
SHA1: | 88694919A39988857213BDE785B5C591E1525A35 |
SHA-256: | D5355284B6411903AB344C3DA20178FF2891B7C14B2CECF27943C9331E6FE652 |
SHA-512: | AA418C5AB153B3FAD305D6556990C2BB89ED59E8AC11F84D5CEBEA547032387CCB9211FB4D35486534D205194884ABFCC5CFB84417196C3A9FF886E97346B306 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\imagelogger.lnk
Download File
Process: | C:\Users\user\Desktop\imagelogger.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1049 |
Entropy (8bit): | 4.992986568846722 |
Encrypted: | false |
SSDEEP: | 24:8RRHDHo73qKRSgK3RerGAcwZlEI4iAOqygm:8RVrK3qKR/cwZLCLyg |
MD5: | 53E4E9CF775219938FB216846D3D501F |
SHA1: | 5921A8E57E160DB4268546A76ABD9E55DD7C9582 |
SHA-256: | 422DB0468F90AE3C204883D75B64000328547BF9903840AB8863B471D9222EA2 |
SHA-512: | B27B50B24D5C79F20E1A4F1BF5ABC801EB249371242BBD81F0771B887503693C3F11AD886E0473FA4097F8FF87A9C19F2AB3F2C2A78C44DEECA4F00811E05CAA |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 3.402515961281467 |
TrID: |
|
File name: | imagelogger.exe |
File size: | 327'680 bytes |
MD5: | 9655b8120c0d0469ee87eebdeeca3b4d |
SHA1: | 88694919a39988857213bde785b5c591e1525a35 |
SHA256: | d5355284b6411903ab344c3da20178ff2891b7c14b2cecf27943c9331e6fe652 |
SHA512: | aa418c5ab153b3fad305d6556990c2bb89ed59e8ac11f84d5cebea547032387ccb9211fb4d35486534d205194884abfcc5cfb84417196c3a9ff886e97346b306 |
SSDEEP: | 3072:Bm4cvA/SDhVUYbg1Sc0dBYOzY4Xy0tv4L9witTOs/sh/A:oVTbGSldBSf0tvg3xs/ |
TLSH: | 936408D63B4043EFC05ABF798965D631A2BA5F46FA46E346C074F051AFB71C28E41AC2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...F..d.....................(......N.... ........@.. .......................`............@................................ |
Icon Hash: | 17137171652d0303 |
Entrypoint: | 0x40f54e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64F7BE46 [Tue Sep 5 23:48:22 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xf4f8 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x10000 | 0x425aa | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x54000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xd554 | 0xd600 | 7f0e7e46e5770e2d36f35037f62679b0 | False | 0.5971086448598131 | data | 6.1236544264430695 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x10000 | 0x425aa | 0x42600 | 9883ae93da2a2082c3c7fe7f8ae676ad | False | 0.1864811381826742 | data | 2.3894491698434708 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x54000 | 0xc | 0x200 | 7ee00025a62cea4fff5885e1822b5ff8 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x10130 | 0x42028 | Device independent bitmap graphic, 256 x 512 x 32, image size 262144, resolution 11811 x 11811 px/m | 0.18493875196023316 | ||
RT_GROUP_ICON | 0x52158 | 0x14 | data | 0.9 | ||
RT_VERSION | 0x5216c | 0x254 | data | 0.4664429530201342 | ||
RT_MANIFEST | 0x523c0 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T08:37:38.443741+0100 | 2855924 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.9 | 49723 | 147.185.221.229 | 42209 | TCP |
2024-12-16T08:39:03.103686+0100 | 2853193 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.9 | 49897 | 147.185.221.229 | 42209 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 08:37:24.558048964 CET | 49717 | 80 | 192.168.2.9 | 208.95.112.1 |
Dec 16, 2024 08:37:24.677905083 CET | 80 | 49717 | 208.95.112.1 | 192.168.2.9 |
Dec 16, 2024 08:37:24.678037882 CET | 49717 | 80 | 192.168.2.9 | 208.95.112.1 |
Dec 16, 2024 08:37:24.679280996 CET | 49717 | 80 | 192.168.2.9 | 208.95.112.1 |
Dec 16, 2024 08:37:24.799031019 CET | 80 | 49717 | 208.95.112.1 | 192.168.2.9 |
Dec 16, 2024 08:37:25.830826998 CET | 80 | 49717 | 208.95.112.1 | 192.168.2.9 |
Dec 16, 2024 08:37:25.876678944 CET | 49717 | 80 | 192.168.2.9 | 208.95.112.1 |
Dec 16, 2024 08:37:27.491365910 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:27.611377001 CET | 42209 | 49723 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:27.615473986 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:27.689527035 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:27.809324026 CET | 42209 | 49723 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:38.443741083 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:38.563544989 CET | 42209 | 49723 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:49.190136909 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:49.310051918 CET | 42209 | 49723 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:49.506159067 CET | 42209 | 49723 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:49.506239891 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:51.596060991 CET | 49723 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:51.597423077 CET | 49781 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:51.715868950 CET | 42209 | 49723 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:51.717488050 CET | 42209 | 49781 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:37:51.717596054 CET | 49781 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:52.072165966 CET | 49781 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:37:52.192792892 CET | 42209 | 49781 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:06.142893076 CET | 49781 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:06.262756109 CET | 42209 | 49781 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:13.601051092 CET | 42209 | 49781 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:13.601176977 CET | 49781 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:14.033478975 CET | 49781 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:14.034941912 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:14.153239012 CET | 42209 | 49781 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:14.154623032 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:14.154712915 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:14.193061113 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:14.312966108 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:17.542336941 CET | 80 | 49717 | 208.95.112.1 | 192.168.2.9 |
Dec 16, 2024 08:38:17.542484045 CET | 49717 | 80 | 192.168.2.9 | 208.95.112.1 |
Dec 16, 2024 08:38:26.783673048 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:26.903461933 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:32.642879009 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:32.762799025 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:32.799338102 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:32.919294119 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:33.236546040 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:33.356230974 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:34.935174942 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:35.054971933 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:36.056226969 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:36.056363106 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.064493895 CET | 49831 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.067009926 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.184241056 CET | 42209 | 49831 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:41.186774969 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:41.186842918 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.225881100 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.347587109 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:41.347651005 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.467551947 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:41.611836910 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:41.731656075 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:43.049915075 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:43.169678926 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:45.221295118 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:45.340990067 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:49.658552885 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:49.778362989 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:51.768091917 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:51.888159037 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:51.889703035 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:52.009682894 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:52.066692114 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:52.186394930 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:38:57.533638954 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:38:57.653347015 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:02.863879919 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:02.983685017 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:02.983747959 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:03.103636026 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:03.103686094 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:03.117934942 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:03.118036985 CET | 49897 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:03.223421097 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:03.237713099 CET | 42209 | 49897 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:05.848567009 CET | 49717 | 80 | 192.168.2.9 | 208.95.112.1 |
Dec 16, 2024 08:39:05.968352079 CET | 80 | 49717 | 208.95.112.1 | 192.168.2.9 |
Dec 16, 2024 08:39:08.010214090 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:08.129966974 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:08.130168915 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:08.231005907 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:08.350754976 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:08.814901114 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:08.934542894 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:08.935065031 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:09.054797888 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:09.441689968 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:09.561634064 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:15.521704912 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:15.641444921 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:19.221657038 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:19.341397047 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:24.627876043 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:24.747582912 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:27.799350023 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:27.919087887 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:29.801759005 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:29.921528101 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:30.025727987 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:30.025810003 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:34.820108891 CET | 49958 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:34.855384111 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:34.940001965 CET | 42209 | 49958 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:34.977869034 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:34.984981060 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:35.256619930 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:35.378602028 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:40.393264055 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:40.513750076 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:40.513823032 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:40.633606911 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:40.633660078 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:40.753469944 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:47.565356970 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:47.685133934 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:47.986881971 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:48.106875896 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:52.989836931 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:53.109888077 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.080990076 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:56.201327085 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.201395035 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:56.321185112 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.321266890 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:56.443036079 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.443123102 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:56.563020945 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.563093901 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:39:56.683120012 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.902080059 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:39:56.902151108 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:01.549258947 CET | 49982 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:01.552069902 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:01.669336081 CET | 42209 | 49982 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:01.671950102 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:01.672137976 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:01.880186081 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:01.999938965 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:05.519886971 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:05.639708042 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:06.971414089 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:07.091229916 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:07.092050076 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:07.211896896 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:12.038858891 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:12.347939014 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:12.437491894 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:12.467814922 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:12.846978903 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:12.967247009 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:12.967310905 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:13.087390900 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:13.087567091 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:13.207426071 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:17.409210920 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:17.528978109 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:18.206034899 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:18.325894117 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:18.325956106 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:18.445769072 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:18.445971012 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:18.565788031 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:18.565849066 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:18.685570955 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:18.685628891 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:18.805362940 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:23.577688932 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:23.582071066 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:23.585140944 CET | 49983 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:23.588009119 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:23.705022097 CET | 42209 | 49983 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:23.707845926 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:23.708292007 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:23.866831064 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:23.986601114 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:35.161978006 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:35.281685114 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:36.815787077 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:36.936012030 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:38.675096989 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:38.794795990 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:45.625212908 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:45.625310898 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:49.033998013 CET | 49984 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:49.036628008 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:49.153773069 CET | 42209 | 49984 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:49.156349897 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:49.157160044 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:49.437100887 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:49.556936979 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:54.534167051 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:54.654119015 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:40:54.654190063 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:40:54.774199009 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:05.518482924 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:05.638283014 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:07.409130096 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:07.529082060 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:11.047552109 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:11.047631979 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:14.940289021 CET | 49985 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:14.942884922 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:15.060118914 CET | 42209 | 49985 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:15.062978029 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:15.063090086 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:15.099416018 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:15.222165108 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:18.596782923 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:18.716449022 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:20.018579006 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:20.138335943 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:26.815496922 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:26.935457945 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:36.970113039 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:36.970267057 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:40.643378973 CET | 49986 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:40.644553900 CET | 49987 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:40.763128996 CET | 42209 | 49986 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:40.764360905 CET | 42209 | 49987 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:40.768491030 CET | 49987 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:40.793423891 CET | 49987 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:40.913333893 CET | 42209 | 49987 | 147.185.221.229 | 192.168.2.9 |
Dec 16, 2024 08:41:54.362462044 CET | 49987 | 42209 | 192.168.2.9 | 147.185.221.229 |
Dec 16, 2024 08:41:54.482134104 CET | 42209 | 49987 | 147.185.221.229 | 192.168.2.9 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 08:37:24.411652088 CET | 49513 | 53 | 192.168.2.9 | 1.1.1.1 |
Dec 16, 2024 08:37:24.551023960 CET | 53 | 49513 | 1.1.1.1 | 192.168.2.9 |
Dec 16, 2024 08:37:27.197638035 CET | 62036 | 53 | 192.168.2.9 | 1.1.1.1 |
Dec 16, 2024 08:37:27.472388029 CET | 53 | 62036 | 1.1.1.1 | 192.168.2.9 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 16, 2024 08:37:24.411652088 CET | 192.168.2.9 | 1.1.1.1 | 0x5022 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 08:37:27.197638035 CET | 192.168.2.9 | 1.1.1.1 | 0xf24c | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 16, 2024 08:37:19.105788946 CET | 1.1.1.1 | 192.168.2.9 | 0xe188 | No error (0) | s-part-0035.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 16, 2024 08:37:19.105788946 CET | 1.1.1.1 | 192.168.2.9 | 0xe188 | No error (0) | 13.107.246.63 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 08:37:24.551023960 CET | 1.1.1.1 | 192.168.2.9 | 0x5022 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 08:37:27.472388029 CET | 1.1.1.1 | 192.168.2.9 | 0xf24c | No error (0) | 147.185.221.229 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.9 | 49717 | 208.95.112.1 | 80 | 3820 | C:\Users\user\Desktop\imagelogger.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 08:37:24.679280996 CET | 80 | OUT | |
Dec 16, 2024 08:37:25.830826998 CET | 175 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 02:37:19 |
Start date: | 16/12/2024 |
Path: | C:\Users\user\Desktop\imagelogger.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x780000 |
File size: | 327'680 bytes |
MD5 hash: | 9655B8120C0D0469EE87EEBDEECA3B4D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 18.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 50% |
Total number of Nodes: | 6 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF887B05D56 Relevance: .5, Instructions: 469COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF887B06B02 Relevance: .5, Instructions: 454COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|