Source: unknown |
HTTPS traffic detected: 128.116.119.3:443 -> 192.168.2.4:49731 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.46.236:443 -> 192.168.2.4:49732 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.46.236:443 -> 192.168.2.4:49733 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.18.38.10:443 -> 192.168.2.4:49740 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.18.38.10:443 -> 192.168.2.4:49743 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.18.38.10:443 -> 192.168.2.4:49767 version: TLS 1.2 |
Source: |
Binary string: Swift.pdb source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2249307786.000001B2BBD0C000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
Source: |
Binary string: bunni_bootstrapper.pdb* source: swift-bootstrapper.exe |
Source: |
Binary string: C:\Users\matic\source\repos\Dll3\Dll3\x64\Release\Dll3.pdb source: swift-bootstrapper.exe, 00000000.00000003.2502561829.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2499011093.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
Source: |
Binary string: bunni_bootstrapper.pdb source: swift-bootstrapper.exe |
Source: |
Binary string: C:\Users\matic\source\repos\Dll3\Dll3\x64\Release\Dll3.pdb- source: swift-bootstrapper.exe, 00000000.00000003.2502561829.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2499011093.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
Source: global traffic |
HTTP traffic detected: GET /v2/client-version/WindowsPlayer/channel/Live HTTP/1.1accept: */*host: clientsettings.roblox.com |
Source: global traffic |
HTTP traffic detected: POST /api/status HTTP/1.1accept: */*host: bunni.lol |
Source: global traffic |
HTTP traffic detected: POST /api/files/downloadfiles HTTP/1.1accept: */*host: bunni.lolcontent-length: 36 |
Source: global traffic |
HTTP traffic detected: GET /storage/v1/object/public/swift-storage/ui/Swift.exe HTTP/1.1accept: */*host: fkajsebjpvqftdgzyitk.supabase.co |
Source: global traffic |
HTTP traffic detected: GET /storage/v1/object/public/swift-storage/injector/injector.exe HTTP/1.1accept: */*host: fkajsebjpvqftdgzyitk.supabase.co |
Source: global traffic |
HTTP traffic detected: GET /storage/v1/object/public/swift-storage/dlls/Dll3.dll HTTP/1.1accept: */*host: fkajsebjpvqftdgzyitk.supabase.co |
Source: global traffic |
HTTP traffic detected: GET /v2/client-version/WindowsPlayer/channel/Live HTTP/1.1accept: */*host: clientsettings.roblox.com |
Source: global traffic |
HTTP traffic detected: GET /storage/v1/object/public/swift-storage/ui/Swift.exe HTTP/1.1accept: */*host: fkajsebjpvqftdgzyitk.supabase.co |
Source: global traffic |
HTTP traffic detected: GET /storage/v1/object/public/swift-storage/injector/injector.exe HTTP/1.1accept: */*host: fkajsebjpvqftdgzyitk.supabase.co |
Source: global traffic |
HTTP traffic detected: GET /storage/v1/object/public/swift-storage/dlls/Dll3.dll HTTP/1.1accept: */*host: fkajsebjpvqftdgzyitk.supabase.co |
Source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2243850276.000001B2BBBB4000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: http://.css |
Source: swift-bootstrapper.exe, 00000000.00000003.2243850276.000001B2BBB88000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: http://.jpg |
Source: swift-bootstrapper.exe, 00000000.00000003.2243850276.000001B2BBBA8000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: http://html4/loose.dtd |
Source: Swift.exe.0.dr |
String found in binary or memory: https://bunni.lol/api/bauth/login |
Source: Swift.exe.0.dr |
String found in binary or memory: https://bunni.lol/api/bauth/register |
Source: Swift.exe.0.dr |
String found in binary or memory: https://bunni.lol/api/bauth/sessionBearer |
Source: Swift.exe.0.dr |
String found in binary or memory: https://bunni.lol/api/files/downloadfilesCouldn |
Source: swift-bootstrapper.exe |
String found in binary or memory: https://bunni.lol/api/files/downloadfilesSWIFT |
Source: Swift.exe.0.dr |
String found in binary or memory: https://bunni.lol/api/keys/link |
Source: Swift.exe.0.dr |
String found in binary or memory: https://bunni.lol/api/status |
Source: swift-bootstrapper.exe |
String found in binary or memory: https://bunni.lol/api/statusCouldn |
Source: swift-bootstrapper.exe |
String found in binary or memory: https://clientsettings.roblox.com/v2/client-version/WindowsPlayer/channel/LiveCoulnd |
Source: swift-bootstrapper.exe, 00000000.00000003.2488038515.000001B2BA692000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
String found in binary or memory: https://curl.se/docs/alt-svc.html |
Source: swift-bootstrapper.exe, 00000000.00000003.2488038515.000001B2BA692000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
String found in binary or memory: https://curl.se/docs/hsts.html |
Source: swift-bootstrapper.exe, 00000000.00000003.2488038515.000001B2BA686000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
String found in binary or memory: https://curl.se/docs/http-cookies.html |
Source: Swift.exe.0.dr |
String found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support |
Source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2242425465.000001B2BBB1C000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: https://docs.rs/tauri/1/tauri/scope/struct.IpcScope.html#method.configure_remote_access |
Source: swift-bootstrapper.exe, 00000000.00000002.2945495102.000001B2B9FFB000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2192147602.000001B2BA050000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000002.2945495102.000001B2BA052000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2469343510.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2350127326.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fkajsebjpvqftdgzyitk.supabase.co/storage/v1/object/public/swift-storage/dlls/Dll3.dll |
Source: swift-bootstrapper.exe, 00000000.00000003.2469343510.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fkajsebjpvqftdgzyitk.supabase.co/storage/v1/object/public/swift-storage/dlls/Dll3.dllctor.ex |
Source: swift-bootstrapper.exe, 00000000.00000003.2350127326.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fkajsebjpvqftdgzyitk.supabase.co/storage/v1/object/public/swift-storage/injector/injector.ex |
Source: swift-bootstrapper.exe, 00000000.00000002.2945495102.000001B2B9FFB000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2192147602.000001B2BA050000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000002.2945495102.000001B2BA052000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2469343510.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2350127326.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fkajsebjpvqftdgzyitk.supabase.co/storage/v1/object/public/swift-storage/ui/Swift.exe |
Source: swift-bootstrapper.exe, 00000000.00000003.2253397530.000001B2BA051000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2192147602.000001B2BA050000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fkajsebjpvqftdgzyitk.supabase.co/storage/v1/object/public/swift-storage/ui/Swift.exe# |
Source: swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2497284770.000001B2BC276000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
String found in binary or memory: https://github.com/dharma |
Source: Swift.exe.0.dr |
String found in binary or memory: https://github.com/rust-windowing/taoC: |
Source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2236534316.000001B2BBA20000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: https://github.com/tauri-apps/tauri/issues/2549#issuecomment-1250036908 |
Source: swift-bootstrapper.exe, 00000000.00000003.2236534316.000001B2BBA1C000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: https://github.com/tauri-apps/tauri/issues/8306) |
Source: swift-bootstrapper.exe, 00000000.00000003.1817877682.000001B2BA06E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ncs.roblox.com/upload |
Source: Swift.exe.0.dr |
String found in binary or memory: https://scriptblox.com/api/script/search?q=&max=&mode=free |
Source: swift-bootstrapper.exe, 00000000.00000003.2242425465.000001B2BBB00000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: https://tauri.app/docs/api/config#tauri.allowlist) |
Source: Swift.exe.0.dr |
String found in binary or memory: https://tauri.app/docs/api/config#tauri.allowlist)C: |
Source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2236534316.000001B2BBA24000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: https://tauri.app/docs/api/config#tauri.allowlist)GetAppVersionGetAppNameGetTauriVersionCouldn |
Source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2242425465.000001B2BBB1C000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
String found in binary or memory: https://tauri.app/v1/api/config/#securityconfig.dangerousremotedomainipcaccess |
Source: unknown |
Network traffic detected: HTTP traffic on port 49733 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49733 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49743 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49740 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49740 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49743 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49767 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49767 |
Source: unknown |
HTTPS traffic detected: 128.116.119.3:443 -> 192.168.2.4:49731 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.46.236:443 -> 192.168.2.4:49732 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.46.236:443 -> 192.168.2.4:49733 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.18.38.10:443 -> 192.168.2.4:49740 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.18.38.10:443 -> 192.168.2.4:49743 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.18.38.10:443 -> 192.168.2.4:49767 version: TLS 1.2 |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: Section: ZLIB complexity 1.000343780222437 |
Source: injector.exe.0.dr |
Static PE information: Section: ZLIB complexity 0.9983979985955056 |
Source: injector.exe.0.dr |
Static PE information: Section: ZLIB complexity 1.0107421875 |
Source: injector.exe.0.dr |
Static PE information: Section: .reloc ZLIB complexity 1.5 |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: vcruntime140.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\swift-bootstrapper.exe |
Section loaded: cryptnet.dll |
Jump to behavior |
Source: |
Binary string: Swift.pdb source: swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BCE12000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2249307786.000001B2BBD0C000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
Source: |
Binary string: bunni_bootstrapper.pdb* source: swift-bootstrapper.exe |
Source: |
Binary string: C:\Users\matic\source\repos\Dll3\Dll3\x64\Release\Dll3.pdb source: swift-bootstrapper.exe, 00000000.00000003.2502561829.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2499011093.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
Source: |
Binary string: bunni_bootstrapper.pdb source: swift-bootstrapper.exe |
Source: |
Binary string: C:\Users\matic\source\repos\Dll3\Dll3\x64\Release\Dll3.pdb- source: swift-bootstrapper.exe, 00000000.00000003.2502561829.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2506922351.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2499011093.000001B2BC2D8000.00000004.00000020.00020000.00000000.sdmp, Dll3.dll.0.dr |
Source: Dll3.dll.0.dr |
Static PE information: section name: .fptable |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: |
Source: injector.exe.0.dr |
Static PE information: section name: .themida |
Source: injector.exe.0.dr |
Static PE information: section name: .boot |
Source: swift-bootstrapper.exe, 00000000.00000003.2219675030.000001B2BB5C2000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2262258118.000001B2BC412000.00000004.00000020.00020000.00000000.sdmp, swift-bootstrapper.exe, 00000000.00000003.2217336712.000001B2BB5C2000.00000004.00000020.00020000.00000000.sdmp, Swift.exe.0.dr |
Binary or memory string: iHGFs |
Source: swift-bootstrapper.exe, 00000000.00000002.2945495102.000001B2B9FFB000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |