Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
png2obj1_XClient.exe

Overview

General Information

Sample name:png2obj1_XClient.exe
(renamed file extension from none to exe)
Original sample name:png2obj1_XClient
Analysis ID:1579798
MD5:24c587128fec0ff6d2b02d8722c0c8c1
SHA1:25bf1ef6182dd53388b2332bafadc592c9983e0f
SHA256:7bd6448fe487d0b8998f8da1ea906eb43a26240e8fb47f1f56fb16d5447ec333
Infos:

Detection

XWorm
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected XWorm
.NET source code contains potential unpacker
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Yara signature match

Classification

  • System is w7x64
  • png2obj1_XClient.exe (PID: 3436 cmdline: "C:\Users\user\Desktop\png2obj1_XClient.exe" MD5: 24C587128FEC0FF6D2B02D8722C0C8C1)
  • cleanup
{"C2 url": ["92.255.57.155"], "Port": 4411, "Aes key": "P0WER", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.6"}
SourceRuleDescriptionAuthorStrings
00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_XWormYara detected XWormJoe Security
    00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmpMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
    • 0x2550:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
    • 0xc4bc:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
    • 0x25a4:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
    • 0xc574:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
    • 0x2634:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
    • 0xc6a4:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
    • 0x23ec:$cnc4: POST / HTTP/1.1
    Process Memory Space: png2obj1_XClient.exe PID: 3436JoeSecurity_XWormYara detected XWormJoe Security
      Process Memory Space: png2obj1_XClient.exe PID: 3436MALWARE_Win_AsyncRATDetects AsyncRATditekSHen
      • 0x4cd9e:$s8: Win32_ComputerSystem
      • 0x4ce0a:$s8: Win32_ComputerSystem
      • 0xa131:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
      • 0xa1ed:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
      • 0xa277:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
      • 0x9fff:$cnc4: POST / HTTP/1.1
      No Sigma rule has matched
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-23T08:29:36.963119+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:37.072506+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:37.156314+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:37.305526+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:37.347949+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:37.528633+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:41.495696+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:54.017182+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:54.209139+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:29:58.355118+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:09.032366+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:12.172730+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:14.908491+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:18.426435+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:21.507471+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:22.940928+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:24.050505+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:24.989326+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:25.409799+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:25.711844+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:25.841166+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:26.025498+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:26.154642+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:26.217287+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:26.996174+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:27.624981+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:28.843193+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:29.035046+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:29.928491+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:30.324169+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:30.515940+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:30.683196+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:31.154899+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:31.451123+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:31.667851+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:31.787858+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:31.979463+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:32.448425+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:32.743945+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:33.052630+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:33.244399+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:33.474659+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:33.781618+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:34.070035+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:34.213959+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:34.332883+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:34.755273+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:34.836536+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:34.957229+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:35.237262+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:35.304185+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:35.663204+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:35.863241+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:38.873857+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:39.065541+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:39.185603+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:43.694758+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:43.921855+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:44.043092+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:44.163648+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:54.027184+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:56.581329+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      2024-12-23T08:30:56.836792+010028528701Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-23T08:29:37.097312+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:37.156385+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:37.217135+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:37.348870+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:37.511774+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:37.917066+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:41.497552+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:54.211359+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:29:58.358314+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:09.038439+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:12.175483+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:14.910846+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:18.428607+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:21.509496+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:22.942784+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:25.095334+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:25.454392+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:25.714059+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:25.843148+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:26.027139+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:26.156644+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:26.317757+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:26.998261+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:27.626999+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:28.845286+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:29.037004+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:30.371563+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:30.517811+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:30.798590+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:31.157844+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:31.476211+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:31.669708+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:31.789649+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:31.911039+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:31.979633+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:32.022533+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:32.451992+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:32.817854+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:33.114241+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:33.393998+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:33.513632+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:38.135361+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:38.447566+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      2024-12-23T08:30:43.579284+010028529231Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-23T08:29:54.017182+010028588011Malware Command and Control Activity Detected92.255.57.1554411192.168.2.2249161TCP
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-12-23T08:30:27.191059+010028587991Malware Command and Control Activity Detected192.168.2.224916192.255.57.1554411TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: png2obj1_XClient.exeAvira: detected
      Source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Xworm {"C2 url": ["92.255.57.155"], "Port": 4411, "Aes key": "P0WER", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.6"}
      Source: png2obj1_XClient.exeReversingLabs: Detection: 68%
      Source: png2obj1_XClient.exeVirustotal: Detection: 77%Perma Link
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
      Source: png2obj1_XClient.exeJoe Sandbox ML: detected
      Source: png2obj1_XClient.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
      Source: png2obj1_XClient.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
      Source: Binary string: lib.pdb source: png2obj1_XClient.exe, 00000000.00000002.534882828.0000000000FF9000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: mscorlib.pdbFramework64\v4.0.30319;;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\WindowsPowerShell\ source: png2obj1_XClient.exe, 00000000.00000002.535357258.000000001CD1F000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbJ source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: Binary string: symbols\dll\mscorlib.pdbpdb source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: Binary string: .pdb+0 source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: Binary string: 0C:\Windows\mscorlib.pdb source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\en-US\tzres.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\en-US\avicap32.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\en-US\MSVFW32.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\028f9e8b0c8b1820df7bec952b01fe12\System.Windows.Forms.ni.dll.auxJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\wbem\en-US\wmiutils.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\7e5e0d92b127a5150606d81839f29044\System.Drawing.ni.dll.auxJump to behavior

      Networking

      barindex
      Source: Network trafficSuricata IDS: 2858800 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.22:49161 -> 92.255.57.155:4411
      Source: Network trafficSuricata IDS: 2852870 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes : 92.255.57.155:4411 -> 192.168.2.22:49161
      Source: Network trafficSuricata IDS: 2852923 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) : 192.168.2.22:49161 -> 92.255.57.155:4411
      Source: Network trafficSuricata IDS: 2858801 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Command - Ping Inbound : 92.255.57.155:4411 -> 192.168.2.22:49161
      Source: Network trafficSuricata IDS: 2858799 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.22:49161 -> 92.255.57.155:4411
      Source: Malware configuration extractorURLs: 92.255.57.155
      Source: global trafficTCP traffic: 192.168.2.22:49161 -> 92.255.57.155:4411
      Source: Joe Sandbox ViewIP Address: 92.255.57.155 92.255.57.155
      Source: Joe Sandbox ViewASN Name: TELSPRU TELSPRU
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: unknownTCP traffic detected without corresponding DNS query: 92.255.57.155
      Source: png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

      System Summary

      barindex
      Source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
      Source: Process Memory Space: png2obj1_XClient.exe PID: 3436, type: MEMORYSTRMatched rule: Detects AsyncRAT Author: ditekSHen
      Source: png2obj1_XClient.exe, 00000000.00000000.350844339.000000000128C000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameXClient.exe4 vs png2obj1_XClient.exe
      Source: png2obj1_XClient.exe, 00000000.00000002.534691848.00000000002ED000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs png2obj1_XClient.exe
      Source: png2obj1_XClient.exeBinary or memory string: OriginalFilenameXClient.exe4 vs png2obj1_XClient.exe
      Source: png2obj1_XClient.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
      Source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
      Source: Process Memory Space: png2obj1_XClient.exe PID: 3436, type: MEMORYSTRMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
      Source: png2obj1_XClient.exe, -----------------------------------------.csCryptographic APIs: 'CreateDecryptor'
      Source: png2obj1_XClient.exe, -----------------------------------------.csCryptographic APIs: 'TransformFinalBlock'
      Source: png2obj1_XClient.exe, -----------------------------------------.csCryptographic APIs: 'TransformFinalBlock'
      Source: png2obj1_XClient.exe, -----------------------------------------.csCryptographic APIs: 'CreateDecryptor'
      Source: classification engineClassification label: mal100.troj.evad.winEXE@1/0@0/1
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeMutant created: NULL
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeMutant created: \Sessions\1\BaseNamedObjects\o8kSNczORMveFDjV
      Source: png2obj1_XClient.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: png2obj1_XClient.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: png2obj1_XClient.exeReversingLabs: Detection: 68%
      Source: png2obj1_XClient.exeVirustotal: Detection: 77%
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile read: C:\Users\user\Desktop\png2obj1_XClient.exeJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: amsi.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: bcrypt.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: rpcrtremote.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: wbemcomn2.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: ntdsapi.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: avicap32.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: winmm.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeSection loaded: msvfw32.dllJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
      Source: png2obj1_XClient.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
      Source: png2obj1_XClient.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
      Source: Binary string: lib.pdb source: png2obj1_XClient.exe, 00000000.00000002.534882828.0000000000FF9000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: mscorlib.pdbFramework64\v4.0.30319;;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\WindowsPowerShell\ source: png2obj1_XClient.exe, 00000000.00000002.535357258.000000001CD1F000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbJ source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: Binary string: symbols\dll\mscorlib.pdbpdb source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: Binary string: .pdb+0 source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp
      Source: Binary string: 0C:\Windows\mscorlib.pdb source: png2obj1_XClient.exe, 00000000.00000002.535288155.000000001BB59000.00000004.00000010.00020000.00000000.sdmp

      Data Obfuscation

      barindex
      Source: png2obj1_XClient.exe, -----------------------------------------.cs.Net Code: _202B_200C_206B_202B_200F_202E_206A_206B_206F_206A_206F_206D_206B_206B_202B_202E_200B_200D_206C_202C_200E_200C_206B_202B_200C_200E_202E_200B_202A_200D_200C_206E_200B_206E_206E_202A_200B_206D_202A_202C_202E System.AppDomain.Load(byte[])
      Source: png2obj1_XClient.exe, -Module-.cs.Net Code: _202B_202D_200B_200C_202A_206F_206C_206C_200E_200E_202C_206B_200B_200E_202B_202B_200B_206B_200E_206D_206C_202B_200C_206F_206C_202A_200F_206F_206F_202D_206C_206A_206B_206E_202A_200C_202E_206A_200D_200F_202E System.Reflection.Assembly.Load(byte[])
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

      Malware Analysis System Evasion

      barindex
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeMemory allocated: 230000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeMemory allocated: 1A690000 memory reserve | memory write watchJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeWindow / User API: threadDelayed 1386Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeWindow / User API: threadDelayed 8453Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeWindow / User API: foregroundWindowGot 473Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exe TID: 3548Thread sleep time: -420000s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exe TID: 3576Thread sleep time: -1844674407370954s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exe TID: 3584Thread sleep count: 1386 > 30Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exe TID: 3584Thread sleep count: 8453 > 30Jump to behavior
      Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeThread delayed: delay time: 922337203685477Jump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\en-US\tzres.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\en-US\avicap32.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\en-US\MSVFW32.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\028f9e8b0c8b1820df7bec952b01fe12\System.Windows.Forms.ni.dll.auxJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\system32\wbem\en-US\wmiutils.dll.muiJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeFile opened: C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\7e5e0d92b127a5150606d81839f29044\System.Drawing.ni.dll.auxJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeProcess token adjusted: DebugJump to behavior
      Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeMemory allocated: page read and write | page guardJump to behavior
      Source: png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002774000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002748000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 'PING!<Xwormmm>Program Manager<Xwormmm>0
      Source: png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002774000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.00000000029EC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
      Source: png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002774000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002748000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: PING!<Xwormmm>Program Manager<Xwormmm>0
      Source: png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002774000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002748000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 'PING!<Xwormmm>Program Manager<Xwormmm>0@
      Source: png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002774000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, png2obj1_XClient.exe, 00000000.00000002.534955459.0000000002748000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager2
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeQueries volume information: C:\Users\user\Desktop\png2obj1_XClient.exe VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
      Source: C:\Users\user\Desktop\png2obj1_XClient.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: png2obj1_XClient.exe PID: 3436, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: png2obj1_XClient.exe PID: 3436, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
      Windows Management Instrumentation
      1
      DLL Side-Loading
      1
      Process Injection
      1
      Disable or Modify Tools
      OS Credential Dumping11
      Security Software Discovery
      Remote Services1
      Archive Collected Data
      1
      Non-Standard Port
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      DLL Side-Loading
      131
      Virtualization/Sandbox Evasion
      LSASS Memory1
      Process Discovery
      Remote Desktop ProtocolData from Removable Media1
      Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      Process Injection
      Security Account Manager131
      Virtualization/Sandbox Evasion
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
      Deobfuscate/Decode Files or Information
      NTDS1
      Application Window Discovery
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      Software Packing
      LSA Secrets1
      File and Directory Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
      DLL Side-Loading
      Cached Domain Credentials14
      System Information Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      png2obj1_XClient.exe68%ReversingLabsByteCode-MSIL.Infostealer.Tinba
      png2obj1_XClient.exe78%VirustotalBrowse
      png2obj1_XClient.exe100%AviraTR/Dropper.Gen
      png2obj1_XClient.exe100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameMaliciousAntivirus DetectionReputation
      92.255.57.155false
        high
        NameSourceMaliciousAntivirus DetectionReputation
        http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepng2obj1_XClient.exe, 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmpfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          92.255.57.155
          unknownRussian Federation
          42253TELSPRUtrue
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1579798
          Start date and time:2024-12-23 08:28:38 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 55s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:default.jbs
          Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
          Number of analysed new started processes analysed:5
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Sample name:png2obj1_XClient.exe
          (renamed file extension from none to exe)
          Original Sample Name:png2obj1_XClient
          Detection:MAL
          Classification:mal100.troj.evad.winEXE@1/0@0/1
          • Exclude process from analysis (whitelisted): dllhost.exe, WerFault.exe, WMIADAP.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 104.208.16.93
          • Excluded domains from analysis (whitelisted): onedsblobprdcus07.centralus.cloudapp.azure.com, watson.microsoft.com, legacywatson.trafficmanager.net
          • Report size getting too big, too many NtDeviceIoControlFile calls found.
          • Report size getting too big, too many NtQueryValueKey calls found.
          TimeTypeDescription
          02:29:30API Interceptor841656x Sleep call for process: png2obj1_XClient.exe modified
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          92.255.57.155anyrunsample.ps1Get hashmaliciousUnknownBrowse
          • 92.255.57.155/1/1.png
          https://reviewgustereports.com/Get hashmaliciousCAPTCHA Scam ClickFix, XWormBrowse
          • 92.255.57.155/1/1.png
          No context
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          TELSPRUDm35sdidf3.exeGet hashmaliciousXWormBrowse
          • 92.255.57.155
          QP2uO3eN2p.ps1Get hashmaliciousXWormBrowse
          • 92.255.57.155
          WErY5oc4hl.ps1Get hashmaliciousXWormBrowse
          • 92.255.57.155
          NLXwvLjXPh.ps1Get hashmaliciousXWormBrowse
          • 92.255.57.155
          mhqxUdpe7V.ps1Get hashmaliciousXWormBrowse
          • 92.255.57.155
          anyrunsample.ps1Get hashmaliciousUnknownBrowse
          • 92.255.57.155
          sEOELQpFOB.lnkGet hashmaliciousRedLineBrowse
          • 92.255.57.75
          ref095vq842r70_classement_atout_france.pdf.lnk.d.lnkGet hashmaliciousRedLine, SectopRATBrowse
          • 92.255.57.75
          No context
          No context
          No created / dropped files found
          File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
          Entropy (8bit):5.442060260254694
          TrID:
          • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
          • Win32 Executable (generic) a (10002005/4) 49.75%
          • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
          • Windows Screen Saver (13104/52) 0.07%
          • Generic Win/DOS Executable (2004/3) 0.01%
          File name:png2obj1_XClient.exe
          File size:172'032 bytes
          MD5:24c587128fec0ff6d2b02d8722c0c8c1
          SHA1:25bf1ef6182dd53388b2332bafadc592c9983e0f
          SHA256:7bd6448fe487d0b8998f8da1ea906eb43a26240e8fb47f1f56fb16d5447ec333
          SHA512:52a832340bae126eb8d1d6d316f3e9f741e23d73c1d1dca9cf8c096518174d14aa35d83e7e09f075de3afbe4e11bb7120020f4604de132b09590c97eeb3a6ced
          SSDEEP:3072:K2dT8eGZeApZQALXSt+b8aMOjx/S0hXAQltJmDfm0mbmKvD3+Ztm+p6OD/I:DGZeAAA9b5MOjx/S0hXAQltJmDfm0mbY
          TLSH:0EF3599D765076DFC867D872DEA81C64EA6074BB531B9203A02316EDEE4D89BCF140F2
          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Pg................................. ........@.. ....................................@................................
          Icon Hash:aaf3e3e3918382a0
          Entrypoint:0x42b3fe
          Entrypoint Section:.text
          Digitally signed:false
          Imagebase:0x400000
          Subsystem:windows gui
          Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
          DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Time Stamp:0x675011CD [Wed Dec 4 08:24:45 2024 UTC]
          TLS Callbacks:
          CLR (.Net) Version:
          OS Version Major:4
          OS Version Minor:0
          File Version Major:4
          File Version Minor:0
          Subsystem Version Major:4
          Subsystem Version Minor:0
          Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
          Instruction
          jmp dword ptr [00402000h]
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          add byte ptr [eax], al
          NameVirtual AddressVirtual Size Is in Section
          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IMPORT0x2b3a80x53.text
          IMAGE_DIRECTORY_ENTRY_RESOURCE0x2c0000x4d0.rsrc
          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
          IMAGE_DIRECTORY_ENTRY_BASERELOC0x2e0000xc.reloc
          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
          .text0x20000x294040x2960039930a7769bf92556bcd6d79fbafdadeFalse0.41033327039274925data5.4484487095064065IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          .rsrc0x2c0000x4d00x600b96ace240ba3c99bbb9761e4e8dd22a1False0.3756510416666667data3.7307785693156315IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
          .reloc0x2e0000xc0x200bfe7ebb58020353c73f346783fabca80False0.041015625data0.08153941234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
          NameRVASizeTypeLanguageCountryZLIB Complexity
          RT_VERSION0x2c0a00x244data0.4724137931034483
          RT_MANIFEST0x2c2e40x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5469387755102041
          DLLImport
          mscoree.dll_CorExeMain
          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
          2024-12-23T08:29:36.402195+01002858800ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:36.963119+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:37.072506+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:37.097312+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:37.156314+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:37.156385+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:37.217135+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:37.305526+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:37.347949+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:37.348870+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:37.511774+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:37.528633+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:37.917066+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:41.495696+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:41.497552+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:54.017182+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:54.017182+01002858801ETPRO MALWARE Win32/XWorm CnC Command - Ping Inbound192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:54.209139+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:54.211359+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:29:58.355118+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:29:58.358314+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:09.032366+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:09.038439+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:12.172730+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:12.175483+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:14.908491+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:14.910846+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:18.426435+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:18.428607+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:21.507471+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:21.509496+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:22.940928+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:22.942784+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:24.050505+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:24.989326+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:25.095334+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:25.409799+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:25.454392+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:25.711844+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:25.714059+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:25.841166+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:25.843148+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:26.025498+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:26.027139+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:26.154642+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:26.156644+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:26.217287+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:26.317757+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:26.996174+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:26.998261+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:27.191059+01002858799ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:27.624981+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:27.626999+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:28.843193+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:28.845286+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:29.035046+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:29.037004+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:29.928491+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:30.324169+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:30.371563+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:30.515940+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:30.517811+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:30.683196+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:30.798590+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:31.154899+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:31.157844+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:31.451123+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:31.476211+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:31.667851+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:31.669708+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:31.787858+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:31.789649+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:31.911039+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:31.979463+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:31.979633+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:32.022533+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:32.448425+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:32.451992+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:32.743945+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:32.817854+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:33.052630+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:33.114241+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:33.244399+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:33.393998+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:33.474659+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:33.513632+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:33.781618+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:34.070035+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:34.213959+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:34.332883+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:34.755273+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:34.836536+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:34.957229+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:35.237262+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:35.304185+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:35.663204+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:35.863241+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:38.135361+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:38.447566+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:38.873857+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:39.065541+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:39.185603+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:43.579284+01002852923ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client)1192.168.2.224916192.255.57.1554411TCP
          2024-12-23T08:30:43.694758+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:43.921855+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:44.043092+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:44.163648+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:54.027184+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:56.581329+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          2024-12-23T08:30:56.836792+01002852870ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes192.255.57.1554411192.168.2.2249161TCP
          TimestampSource PortDest PortSource IPDest IP
          Dec 23, 2024 08:29:34.923965931 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:35.043627024 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:35.043692112 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.282519102 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.402147055 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:36.402194977 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.521847963 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:36.521905899 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.641501904 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:36.641563892 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.761101007 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:36.761152983 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.880642891 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:36.880702019 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:36.963119030 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.000355005 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.072505951 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.072587967 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.097311974 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.156313896 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.156384945 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.216988087 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.217134953 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.275834084 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.305526018 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.347949028 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.348870039 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.509669065 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.511774063 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.528633118 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.631294012 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:37.800860882 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:37.917066097 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:38.036673069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:41.061572075 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:41.181164980 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:41.495696068 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:41.497551918 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:41.617085934 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:53.542082071 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:53.661923885 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:54.017182112 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:54.209139109 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:54.209245920 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:54.211359024 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:54.331470966 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:57.918354988 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:58.038247108 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:58.355118036 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:29:58.358314037 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:29:58.477917910 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:08.596164942 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:08.715892076 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:09.032366037 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:09.038439035 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:09.158231020 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:11.738554001 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:11.858263969 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:12.172729969 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:12.175482988 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:12.294997931 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:14.474014997 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:14.594019890 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:14.908490896 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:14.910845995 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:15.030527115 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:17.986890078 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:18.106388092 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:18.426434994 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:18.428606987 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:18.548116922 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:20.947870970 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:21.067343950 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:21.507471085 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:21.509495974 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:21.628976107 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:22.495417118 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:22.614968061 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:22.940927982 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:22.942784071 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:23.062360048 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:24.050504923 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:24.257886887 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:24.554672003 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:24.674288988 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:24.975764990 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:24.989326000 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.095242023 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.095334053 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.214812040 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.214947939 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.334489107 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.334609985 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.409799099 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.409945011 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.454305887 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.454391956 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.529613018 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.529727936 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.573909998 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.649274111 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.711843967 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.714059114 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:25.833652020 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.841166019 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:25.843147993 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:26.005721092 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.025497913 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.027138948 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:26.146945953 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.154642105 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.156644106 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:26.217287064 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.317688942 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.317756891 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:26.437253952 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.437362909 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:26.556875944 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.996174097 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:26.998260975 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:27.117821932 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:27.191059113 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:27.310640097 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:27.624980927 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:27.626998901 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:27.746494055 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:28.407784939 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:28.527358055 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:28.548472881 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:28.667954922 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:28.843193054 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:28.845285892 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:28.964811087 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:29.035046101 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:29.037003994 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:29.156580925 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:29.484173059 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:29.604214907 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:29.889736891 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:29.928491116 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.009202003 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.009305000 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:30.128948927 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.129158020 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:30.248719931 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.324168921 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.371562958 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:30.491086960 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.515939951 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.517811060 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:30.677753925 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.677886963 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:30.683196068 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.798511982 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.798589945 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:30.918210983 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:30.918265104 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.038146019 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.038206100 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.154898882 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.154985905 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.157790899 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.157844067 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.274432898 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.277498007 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.356067896 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.451122999 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.476151943 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.476211071 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.596692085 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.667850971 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.669708014 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.787858009 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.789278984 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.789649010 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.902580976 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.902667999 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.910990000 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.911039114 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:31.979463100 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:31.979633093 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.022422075 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.022532940 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.030605078 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.099406004 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.143274069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.143616915 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.270694971 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.448425055 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.451992035 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.575295925 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.575340986 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.695161104 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.698070049 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.743944883 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.817745924 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.817853928 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:32.937561989 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:32.994438887 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.052629948 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.114154100 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.114240885 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.234092951 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.234158039 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.244399071 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.393891096 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.393997908 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.474658966 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.474736929 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.513591051 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.513632059 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.594343901 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.594413042 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.633475065 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.714078903 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.714210987 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.781618118 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.781713963 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.833869934 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.833961010 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.901398897 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:33.901511908 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:33.953625917 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.021167994 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.021240950 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.070034981 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.213958979 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.214071035 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.332882881 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.332953930 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.441793919 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.441852093 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.452650070 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.524815083 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.524863005 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.561378002 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.561433077 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.644383907 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.644433975 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.644594908 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.737894058 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.755273104 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.755362988 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.769198895 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.800056934 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.836535931 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.836575031 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.925234079 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:34.925297022 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:34.957228899 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.015383005 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.048083067 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.048139095 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.071283102 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.209918022 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.210036039 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.237262011 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.237317085 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.304184914 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.304238081 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.333266973 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.357237101 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.425230980 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.425281048 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.429250956 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.429297924 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.550024986 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.550043106 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.550074100 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.663203955 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.663288116 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.719336987 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.719430923 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.782849073 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.782902956 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.841245890 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.841888905 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.863240957 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.863303900 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.945914984 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.945997953 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:35.961708069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.974879026 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:35.974937916 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.029871941 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.029979944 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.031125069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.065597057 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.065660000 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.095127106 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.095180988 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.150753975 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.150813103 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.153382063 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.214859009 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.214920998 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.287010908 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.287080050 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.406727076 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.406740904 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.406800985 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.521766901 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.521812916 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.641369104 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.641590118 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.718545914 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.718606949 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.833425999 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.833498955 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:36.953933954 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.954042912 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:36.954111099 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.030127048 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.030191898 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.145086050 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.145159006 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.264766932 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.264863014 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.270411015 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.270925999 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.390476942 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.390692949 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.463377953 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.463514090 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.576771021 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.577234983 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.697066069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.697623968 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.697659969 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:37.822824955 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:37.823137999 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.001645088 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.009221077 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.135179043 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.135360956 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.321120024 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.417629004 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.447465897 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.447566032 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.512819052 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.512872934 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.567207098 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.567280054 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.639213085 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.639276981 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.758955002 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.759031057 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.873857021 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.873919010 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:38.993546963 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:38.993623018 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.065541029 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.065618992 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.185522079 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.185589075 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.185602903 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.301652908 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.301712990 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.377408981 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.377530098 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.497205019 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.497461081 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.613256931 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.613708973 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.733342886 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.733544111 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.808993101 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.809276104 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.928936958 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.929065943 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:39.970612049 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:39.970822096 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.041707993 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.041910887 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.090758085 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.091005087 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.120982885 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.121087074 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.210640907 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.210854053 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.233532906 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.233864069 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.330440998 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.330498934 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.353538990 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.353604078 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.473201990 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.473262072 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.522381067 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.522428989 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.641978979 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.642049074 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.642086029 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.761645079 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.761707067 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.813877106 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.813946962 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.833833933 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.881395102 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.881458998 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.933587074 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.933655024 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:40.953627110 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:40.953687906 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.045979023 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.046037912 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.053216934 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.073389053 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.073432922 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.125799894 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.125866890 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.165704012 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.165760040 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.192994118 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.245194912 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.245246887 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.245353937 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.285370111 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.285429955 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.357875109 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.361342907 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.364917994 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.365052938 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.404974937 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.407463074 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.477443933 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.481056929 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.481101990 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.484566927 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.487477064 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.527111053 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.527350903 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.597084999 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.599498034 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.607096910 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.607274055 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.717892885 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.719079971 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.719206095 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.769864082 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.773297071 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.838812113 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.838885069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.839061022 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.933803082 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.937325954 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:41.958694935 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:41.958795071 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.030971050 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.031754017 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.057118893 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.059478045 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.078413010 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.081338882 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.085146904 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.179236889 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.181312084 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.245892048 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.248394012 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.249011040 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.300949097 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.301054001 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.318387985 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.318434000 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.409862041 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.409914017 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.420650959 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.420711040 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.438019991 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.440758944 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.440804005 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.540430069 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.540488958 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.559969902 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.605945110 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.606007099 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.660114050 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.660177946 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.721575022 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.721626997 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.725639105 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.725687981 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.779798031 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.779850960 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.841239929 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.841290951 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:42.845216990 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.852013111 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.917506933 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:42.917613983 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.001899958 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.037252903 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.070753098 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.191044092 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.191118002 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.203767061 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.203815937 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.323414087 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.327518940 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.383054018 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.387465000 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.489839077 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.489962101 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.502903938 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.507122040 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.574860096 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.579283953 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.609873056 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.610383034 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.694757938 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.695015907 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.698900938 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.729985952 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.731323957 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.801863909 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.802092075 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.814663887 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.814809084 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.851022959 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.851228952 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.921789885 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.921854973 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.927350998 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:43.970777988 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:43.971005917 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.043092012 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.043358088 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.090600014 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.090739965 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.163647890 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.163774014 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.211184025 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.211321115 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.283590078 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.286310911 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.331715107 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.331783056 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.403243065 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.403356075 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.452312946 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.452370882 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.522895098 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.522953033 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.571918964 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.643368006 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.643426895 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.764678001 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.764739990 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:44.881623983 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:44.881762981 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.002312899 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.002372026 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.073498964 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.073550940 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.193176031 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.193240881 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.194242001 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.194294930 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.305783987 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.305857897 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.313824892 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.313875914 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.385119915 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.386010885 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.433585882 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.497526884 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.617518902 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:45.617588043 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:45.849703074 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:46.042392969 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:46.044608116 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:54.027184010 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:54.241132021 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:56.139863968 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:56.385899067 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:56.385968924 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:56.505568027 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:56.581329107 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:56.743029118 CET491614411192.168.2.2292.255.57.155
          Dec 23, 2024 08:30:56.836791992 CET44114916192.255.57.155192.168.2.22
          Dec 23, 2024 08:30:56.836862087 CET491614411192.168.2.2292.255.57.155

          Click to jump to process

          Click to jump to process

          Click to dive into process behavior distribution

          Target ID:0
          Start time:02:29:29
          Start date:23/12/2024
          Path:C:\Users\user\Desktop\png2obj1_XClient.exe
          Wow64 process (32bit):false
          Commandline:"C:\Users\user\Desktop\png2obj1_XClient.exe"
          Imagebase:0x1260000
          File size:172'032 bytes
          MD5 hash:24C587128FEC0FF6D2B02D8722C0C8C1
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Yara matches:
          • Rule: JoeSecurity_XWorm, Description: Yara detected XWorm, Source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
          • Rule: MALWARE_Win_AsyncRAT, Description: Detects AsyncRAT, Source: 00000000.00000002.534955459.0000000002691000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
          Reputation:low
          Has exited:true

          No disassembly