Windows
Analysis Report
WiezmDFd6L.exe
Overview
General Information
Detection
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64native
- WiezmDFd6L.exe (PID: 4400 cmdline:
"C:\Users\ user\Deskt op\WiezmDF d6L.exe" MD5: 37B0FD9C5E815053E72C20931D2E414C) - cmd.exe (PID: 6976 cmdline:
"C:\Window s\System32 \cmd.exe" /c start C :\Users\Pu blic\Bilit e\Axialis\ RuntimeBro kers.exe MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 4732 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68) - RuntimeBrokers.exe (PID: 7720 cmdline:
C:\Users\P ublic\Bili te\Axialis \RuntimeBr okers.exe MD5: 30A274E00DA842B09E9763F19777ADED) - cmd.exe (PID: 1324 cmdline:
cmd.exe /B /c "C:\Us ers\user\A ppData\Loc al\Temp\\m onitor.bat " MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6512 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68) - tasklist.exe (PID: 4228 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 1492 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 6024 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 5784 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 6404 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 4248 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 2088 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 3064 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 5620 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 6268 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 1712 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 3428 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 4572 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 4936 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 5972 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 5560 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 3052 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 604 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 7728 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 1852 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 6208 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 5628 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 4040 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 192 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 7636 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 2100 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 2352 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 4944 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 7084 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 4444 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 7944 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 5308 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 1640 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 4548 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - findstr.exe (PID: 7096 cmdline:
findstr /I "RuntimeB rokers.exe " MD5: F1D4BE0E99EC734376FDE474A8D4EA3E) - timeout.exe (PID: 5092 cmdline:
timeout /t 30 /nobre ak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3) - tasklist.exe (PID: 7916 cmdline:
tasklist / FI "IMAGEN AME eq Run timeBroker s.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1) - cmd.exe (PID: 6828 cmdline:
cmd.exe /C powershel l -Command "Set-Exec utionPolic y Unrestri cted -Scop e CurrentU ser" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5712 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68) - powershell.exe (PID: 1620 cmdline:
powershell -Command "Set-Execu tionPolicy Unrestric ted -Scope CurrentUs er" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - cmd.exe (PID: 5284 cmdline:
cmd.exe /C powershel l -Executi onPolicy B ypass -Fil e C:\Users \user\AppD ata\Local\ updated.ps 1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 1500 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68) - powershell.exe (PID: 2924 cmdline:
powershell -Executio nPolicy By pass -File C:\Users\ user\AppDa ta\Local\u pdated.ps1 MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
- cleanup
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), Tim Shelton: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Tim Shelton: |
Source: | Author: frack113: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-25T13:39:49.816521+0100 | 2052875 | 1 | A Network Trojan was detected | 192.168.11.20 | 49755 | 134.122.155.90 | 9091 | TCP |
2024-12-25T13:46:36.336559+0100 | 2052875 | 1 | A Network Trojan was detected | 192.168.11.20 | 49773 | 134.122.155.90 | 9092 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_0040301A | |
Source: | Code function: | 0_2_00402B79 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Binary or memory string: | memstr_925cff00-8 |
Source: | Windows user hook set: | Jump to behavior |
Source: | Process Stats: |
Source: | Code function: | 0_2_00404FAA | |
Source: | Code function: | 0_2_0041206B | |
Source: | Code function: | 0_2_0041022D | |
Source: | Code function: | 0_2_00411F91 |
Source: | Dropped File: |
Source: | Code function: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00407776 |
Source: | Code function: | 0_2_0040118A |
Source: | Code function: | 0_2_004034C1 |
Source: | Code function: | 0_2_00401BDF |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | Static PE information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Process created: |
Source: | LNK file: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00406D5D |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00411C4E | |
Source: | Code function: | 13_2_04C342EA | |
Source: | Code function: | 15_2_041A0EBD |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Key value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior |
Source: | Code function: | 0_2_0040301A | |
Source: | Code function: | 0_2_00402B79 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00406D5D |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_0040D72E |
Source: | Code function: | 0_2_00401F9D |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00401626 |
Source: | Code function: | 0_2_00404FAA |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | 1 Replication Through Removable Media | 1 Windows Management Instrumentation | 1 Scripting | 11 Process Injection | 1 Masquerading | 2 Input Capture | 1 System Time Discovery | Remote Services | 2 Input Capture | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Modify Registry | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Virtualization/Sandbox Evasion | Security Account Manager | 2 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 11 Process Injection | NTDS | 11 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Obfuscated Files or Information | Cached Domain Credentials | 11 Peripheral Device Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 2 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 37 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
45% | Virustotal | Browse | ||
47% | ReversingLabs | Win32.Dropper.Vilsel |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
61% | ReversingLabs | Win32.Trojan.DllHijack | ||
4% | ReversingLabs | |||
4% | ReversingLabs | |||
61% | ReversingLabs | Win32.Trojan.DllHijack | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
134.122.155.90 | unknown | United States | 64050 | BCPL-SGBGPNETGlobalASNSG | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1580628 |
Start date and time: | 2024-12-25 13:36:19 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 17m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 128, Firefox 91, Adobe Reader DC 21, Java 8 Update 301 |
Run name: | Suspected Instruction Hammering |
Number of analysed new started processes analysed: | 50 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | WiezmDFd6L.exe |
Detection: | MAL |
Classification: | mal88.troj.evad.winEXE@101/45@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
- Exclude process from analysis (whitelisted): dllhost.exe
- Execution Graph export aborted for target powershell.exe, PID 1620 because it is empty
- Execution Graph export aborted for target powershell.exe, PID 2924 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
07:39:11 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BCPL-SGBGPNETGlobalASNSG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 0.34726597513537405 |
Encrypted: | false |
SSDEEP: | 3:Nlll:Nll |
MD5: | 446DD1CF97EABA21CF14D03AEBC79F27 |
SHA1: | 36E4CC7367E0C7B40F4A8ACE272941EA46373799 |
SHA-256: | A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF |
SHA-512: | A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7 |
Malicious: | false |
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1893 |
Entropy (8bit): | 5.212287775015203 |
Encrypted: | false |
SSDEEP: | 48:c55XzDl4Q2ZbXL6Q0QFdOFQOzN33O4OiDdKrKsTLXbGMv:O5XzDl4Q2ZbGQhFdOFQOzBdKrKsTLXbV |
MD5: | E3FB2ECD2AD10C30913339D97E0E9042 |
SHA1: | A004CE2B3D398312B80E2955E76BDA69EF9B7203 |
SHA-256: | 1BD6DB55FFF870C9DF7A0AAC11B895B50F57774F20A5744E63BBC3BD40D11F28 |
SHA-512: | 9D6F0C1E344F1DC5A0EF4CAAD86281F92A6C108E1085BACD8D6143F9C742198C2F759CA5BDFFAD4D9E40203E6B0460E84896D1C6B8B1759350452E1DE809B716 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2290968 |
Entropy (8bit): | 6.6054620256900645 |
Encrypted: | false |
SSDEEP: | 49152:AWc2Dj3hktNUysuFDbfes+p9bZuR6c3ne3EQBSeZyWF2:Vc2Dj3hkHRsuFP2s+pvuR6c3nKEQBSeu |
MD5: | C257B09BEDDF38B3F89381997852AD36 |
SHA1: | 1CD6B43CBCB0AE1BA1BE52F667F538735E89DFEB |
SHA-256: | 1618A5C7CEB3AC1B7680616339AD472EDBE3C706023D3DC7891688F40EEEA637 |
SHA-512: | DC39825D00348D9E421287904F16FEFF0AC29B92C9ACCEF5D2DD270F4A9297F1418BF62A133DCC448386DEBA931BAA14377A3CA03C9254B770EF276A33A731B1 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 777816 |
Entropy (8bit): | 6.621348016864403 |
Encrypted: | false |
SSDEEP: | 12288:hEj1aAa/zgWDTuE8jegvwIDMuecTenORuFjBw7oHOSgmskduZnTKVrdMujyE3e+0:ooBCoH3BdoTKxdLyAZXdOEvnBzLRUFgi |
MD5: | 30A274E00DA842B09E9763F19777ADED |
SHA1: | 848C6A9348020EAEEC1A5674990683A1D9977B80 |
SHA-256: | 9E65D0E8A1BE49EDE20AD53EE1CF57696C99A28D1B058A185818B58B7FD83F66 |
SHA-512: | 81DED3C48D3FFDCF82952922C4B70D5F0945B1B0D5E178A1B552C7D5E8F39D00D3E007D161A7AFBA4502CC5CB2E92DF973902D94C28DF2DE5176FD2F50DE036A |
Malicious: | true |
Antivirus: |
|
Joe Sandbox View: | |
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 788 |
Entropy (8bit): | 5.10946826685498 |
Encrypted: | false |
SSDEEP: | 24:NFW/WcuW/WcuWEAzWcyMZKx31SIYaYZLZ6y:NFVcuVcujAzzZKx31SIYN/6y |
MD5: | B8422B84DA3F3E791EAB8621899B55D1 |
SHA1: | 0214A135F224C150852D30FE9CA743585C9BB57B |
SHA-256: | 565D247FC0F778E67EE20EC635E815D19A12DEB5FEFEC94F11274956B44C3627 |
SHA-512: | D151F620777C5B67056A6CFEE0A88278B2E5FB9AD57DCDD80F2DFF75A801D63EBDDD6D0C74BEDAB8CBF9E8BA152EB7913F2790720AD4B73490ECD250789E7F18 |
Malicious: | false |
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 2.0 |
Encrypted: | false |
SSDEEP: | 3:PB:J |
MD5: | BB7946E7D85C81A9E69FEE1CEA4A087C |
SHA1: | F3341DBCDDA605B1601524B0D01655750CC60E0D |
SHA-256: | DD49477B0B970DDE26D58606384CFEDD0DC5740B719BFFC06442E7D949849DEB |
SHA-512: | A2F1AE8A47024D6DD07DB5B0BD4758FE7A6049AAA18FBEDBBC3A39E071D26A6AA9E04A338E5559834CB85AB2B6530A086FA11A8CBEF5F633AD8C723A82E2A072 |
Malicious: | false |
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 151 |
Entropy (8bit): | 4.741657013789009 |
Encrypted: | false |
SSDEEP: | 3:41Ai+PBoAwnLFsI2FIERMJyjqLWAfXIhS/ytIEFMEQVGdAn:4yi+5dwnLFsI2F5KJy0fXnMFFQhn |
MD5: | AA0E1012D3B7C24FAD1BE4806756C2CF |
SHA1: | FE0D130AF9105D9044FF3D657D1ABEAF0B750516 |
SHA-256: | FC47E1FA89397C3139D9047DC667531A9153A339F8E29AC713E518D51A995897 |
SHA-512: | 15FAE192951747A0C71059F608700F88548F3E60BB5C708B206BF793A7E3D059A278F2058D4AC86B86781B202037401A29602EE4D6C0CBAAFF532CEF311975F4 |
Malicious: | true |
Preview: |
Process: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1051 |
Entropy (8bit): | 4.66750539631775 |
Encrypted: | false |
SSDEEP: | 12:84NBGjU4IUZcCHqXNmIrZvACmqyW3t2iXuWv2NUjA6MyLfGPNvavUwoPsv4t2YCh:84mMuItqNAA6T4NyvU7PmJTvm |
MD5: | 4C0B1825334ED939AF1D42370D9BAB87 |
SHA1: | 05741400E1ABBEA92AD39851ADE7C763F0C0EB77 |
SHA-256: | 7A8BDB3C5A77D091BF7917F3FABAEADC0130F5F45CED9058D5E85CEF44A4DBF1 |
SHA-512: | 6394D318E03011E5A363815177EE72BEB06EFB2394AA115CC910891C7EF67D6FF5CB41EA015C4E44B8112BCC398E5E371F7681457D41F4AD40CF4A5D62BC4986 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\WiezmDFd6L.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 44 |
Entropy (8bit): | 4.851365993588127 |
Encrypted: | false |
SSDEEP: | 3:iqktR2INd9IbY:il/NIY |
MD5: | AD536A9CDFCA167DE415D847C7579B8A |
SHA1: | 52405A8B8B8C8734DA13E38C8A9F9A8EA782B8AA |
SHA-256: | 59213964F6B9A818B94C0DED984E16AAFEE71CE912D88C70747E1CC6AD4D1C78 |
SHA-512: | F789FC3BF53213146A47BFCBE8D5E0775720189995488F821A928708C809E5D34AAF9869FA056B3251907B4681157D9380D0E9F259F2F0699B50899877B3F315 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\WiezmDFd6L.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 777816 |
Entropy (8bit): | 6.621348016864403 |
Encrypted: | false |
SSDEEP: | 12288:hEj1aAa/zgWDTuE8jegvwIDMuecTenORuFjBw7oHOSgmskduZnTKVrdMujyE3e+0:ooBCoH3BdoTKxdLyAZXdOEvnBzLRUFgi |
MD5: | 30A274E00DA842B09E9763F19777ADED |
SHA1: | 848C6A9348020EAEEC1A5674990683A1D9977B80 |
SHA-256: | 9E65D0E8A1BE49EDE20AD53EE1CF57696C99A28D1B058A185818B58B7FD83F66 |
SHA-512: | 81DED3C48D3FFDCF82952922C4B70D5F0945B1B0D5E178A1B552C7D5E8F39D00D3E007D161A7AFBA4502CC5CB2E92DF973902D94C28DF2DE5176FD2F50DE036A |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\WiezmDFd6L.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2290968 |
Entropy (8bit): | 6.6054620256900645 |
Encrypted: | false |
SSDEEP: | 49152:AWc2Dj3hktNUysuFDbfes+p9bZuR6c3ne3EQBSeZyWF2:Vc2Dj3hkHRsuFP2s+pvuR6c3nKEQBSeu |
MD5: | C257B09BEDDF38B3F89381997852AD36 |
SHA1: | 1CD6B43CBCB0AE1BA1BE52F667F538735E89DFEB |
SHA-256: | 1618A5C7CEB3AC1B7680616339AD472EDBE3C706023D3DC7891688F40EEEA637 |
SHA-512: | DC39825D00348D9E421287904F16FEFF0AC29B92C9ACCEF5D2DD270F4A9297F1418BF62A133DCC448386DEBA931BAA14377A3CA03C9254B770EF276A33A731B1 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\WiezmDFd6L.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33724701 |
Entropy (8bit): | 7.999992899770466 |
Encrypted: | true |
SSDEEP: | 786432:CJ3OEsZI99fnh9+4RzOqcFWQTUIQUjt1ol9bHoQcq4LliKKG/:3hZIHfhJOnWQTr1olN7qoK1/ |
MD5: | 68A106A46BCD32515D30B56C8ABC29BB |
SHA1: | E8EC8977D1DB3152869C46AB630B0B6586C04F71 |
SHA-256: | 10DEEBDC6F75ED88A66BEAEF6AE24D125CCCF14F97E5E03FCE7EA33FBCA37111 |
SHA-512: | BD5909C2F1904CD416F7BA759939413757D09B06DFF6C37E16B7028EDB114CEDEDE173B7BD8C47C012E38ECA6922E18921453DC79D8CF81B31B13D7CC8FBACBB |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\WiezmDFd6L.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10384768 |
Entropy (8bit): | 6.780996075213578 |
Encrypted: | false |
SSDEEP: | 196608:VpjYZ94Z6AhJ5NtGdDDIauMJZZCgdaTos7s4QA/rmYeus5dvXCKsJdVV3qHDYyY2:VpjwKZF5LGdDDvJZZCgdwbcAheus5xXB |
MD5: | C8B07E0F9BA7C97B55CB29835FFAF5F6 |
SHA1: | 9FFFC728C361DCDD4828212F1F0E56A0DAC92463 |
SHA-256: | A68355D5F7E99F3BE66D84EA5AD4A72F92D1611C53F959C0B4E742B363678578 |
SHA-512: | 0AB0D39F0FBCDB11E241AE95CC540A54EF4D9A6E611AE516EF189627E73505696AEBEDACE7D4527C40F31A021850CB7CB563F4D0CE0411BE2F9B87ABA2493866 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\timeout.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 172 |
Entropy (8bit): | 3.8842159555406113 |
Encrypted: | false |
SSDEEP: | 3:hYFRZARcWmFsFJQZ/ctXvY/4to/9uF8cttEfYhnQUqg2Htyst3g4t32vov:hYFRamFSQZ0lv5y/9JctESnQUq3tyMXZ |
MD5: | B44FC16E07912C24524F74A8D3C9BCED |
SHA1: | CCBA90D10D32BFF18221183C88146B378011CC3B |
SHA-256: | FA51D90457861D7169034A0D4122B3AFDA2B4C07E157A4C18AF06D833C96ED2A |
SHA-512: | 1B9F0DD3387FDD1324828AA7CC94A98EC0344A5CAF1EDFFAAF7C0F98F134B09A4DCFD440E9374B0D3C80E099DFE43DABD838B0BE34C395C2F64C9334AE569516 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.999965747494865 |
TrID: |
|
File name: | WiezmDFd6L.exe |
File size: | 37'394'506 bytes |
MD5: | 37b0fd9c5e815053e72c20931d2e414c |
SHA1: | 0dc5769ff9a644e67fe9115fa6158f820a6b39e2 |
SHA256: | e0cf2976621e7ededbbffb8c8feecc307b73ddaa89d859cb9623bfc972c1f0cc |
SHA512: | 942828476488658ce86644ea68adea083d34cd176100336c74bc86a1c564d661861934838ff019bbc53cebc3598d0e65d02f35894027f75adc0ee1a0aa7bcc13 |
SSDEEP: | 786432:XlG05eVClWToLBb7rWDCbIlxKjMrCV5cKzMPzTKd/IsiJ7Z:BMAcebXvI3KjMrgTMbTKdPiT |
TLSH: | 13873369B676E479F3582A3809A04E30F8B88677311647326DB6C49DFBA0F495FD20F1 |
File Content Preview: | MZ`.....................@...................................`...........!..L.!Require Windows..$PE..L...~.&L.....................N...............0....@..........................................................................P............................. |
Icon Hash: | 878fd7f3b9353593 |
Entrypoint: | 0x411def |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x4C26F87E [Sun Jun 27 07:06:38 2010 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | b5a014d7eeb4c2042897567e1288a095 |
Instruction |
---|
push ebp |
mov ebp, esp |
push FFFFFFFFh |
push 00414C50h |
push 00411F80h |
mov eax, dword ptr fs:[00000000h] |
push eax |
mov dword ptr fs:[00000000h], esp |
sub esp, 68h |
push ebx |
push esi |
push edi |
mov dword ptr [ebp-18h], esp |
xor ebx, ebx |
mov dword ptr [ebp-04h], ebx |
push 00000002h |
call dword ptr [00413184h] |
pop ecx |
or dword ptr [00419924h], FFFFFFFFh |
or dword ptr [00419928h], FFFFFFFFh |
call dword ptr [00413188h] |
mov ecx, dword ptr [0041791Ch] |
mov dword ptr [eax], ecx |
call dword ptr [0041318Ch] |
mov ecx, dword ptr [00417918h] |
mov dword ptr [eax], ecx |
mov eax, dword ptr [00413190h] |
mov eax, dword ptr [eax] |
mov dword ptr [00419920h], eax |
call 00007FDDE4C87492h |
cmp dword ptr [00417710h], ebx |
jne 00007FDDE4C8737Eh |
push 00411F78h |
call dword ptr [00413194h] |
pop ecx |
call 00007FDDE4C87464h |
push 00417048h |
push 00417044h |
call 00007FDDE4C8744Fh |
mov eax, dword ptr [00417914h] |
mov dword ptr [ebp-6Ch], eax |
lea eax, dword ptr [ebp-6Ch] |
push eax |
push dword ptr [00417910h] |
lea eax, dword ptr [ebp-64h] |
push eax |
lea eax, dword ptr [ebp-70h] |
push eax |
lea eax, dword ptr [ebp-60h] |
push eax |
call dword ptr [0041319Ch] |
push 00417040h |
push 00417000h |
call 00007FDDE4C8741Ch |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x150dc | 0xb4 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x1a000 | 0x13c0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x13000 | 0x310 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x11317 | 0x11400 | 797279c5ab1a163aed1f2a528f9fe3ce | False | 0.6174988677536232 | data | 6.576987441854239 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x13000 | 0x30ea | 0x3200 | 1359639b02bcb8f0a8743e6ead1c0030 | False | 0.43828125 | data | 5.549434098115495 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x17000 | 0x292c | 0x800 | 9415c9c8dea3245d6d73c23393e27d8e | False | 0.431640625 | data | 3.6583182363171756 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x1a000 | 0x13c0 | 0x1400 | 5293a0fb2c46166ce21247d17e837639 | False | 0.3568359375 | data | 4.96958597460067 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x1a250 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512 | English | United States | 0.3709677419354839 |
RT_ICON | 0x1a538 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128 | English | United States | 0.6081081081081081 |
RT_MENU | 0x1a660 | 0x4a | data | English | United States | 0.8648648648648649 |
RT_DIALOG | 0x1a6ac | 0xf2 | data | English | United States | 0.7148760330578512 |
RT_STRING | 0x1a7a0 | 0x40 | data | English | United States | 0.59375 |
RT_GROUP_ICON | 0x1a7e0 | 0x22 | data | English | United States | 1.0 |
RT_VERSION | 0x1a804 | 0x314 | data | English | United States | 0.44416243654822335 |
RT_MANIFEST | 0x1ab18 | 0x60f | XML 1.0 document, ASCII text, with CRLF line terminators | 0.4229529335912315 | ||
RT_MANIFEST | 0x1b128 | 0x298 | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.4894578313253012 |
DLL | Import |
---|---|
COMCTL32.dll | |
KERNEL32.dll | GetFileAttributesW, CreateDirectoryW, WriteFile, GetStdHandle, VirtualFree, GetModuleHandleW, GetProcAddress, LoadLibraryA, LockResource, LoadResource, SizeofResource, FindResourceExA, MulDiv, GlobalFree, GlobalAlloc, lstrcmpiA, GetSystemDefaultLCID, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, MultiByteToWideChar, GetLocaleInfoW, lstrlenA, lstrcmpiW, GetEnvironmentVariableW, lstrcmpW, GlobalMemoryStatusEx, VirtualAlloc, WideCharToMultiByte, ExpandEnvironmentStringsW, RemoveDirectoryW, FindClose, FindNextFileW, DeleteFileW, FindFirstFileW, SetThreadLocale, GetLocalTime, GetSystemTimeAsFileTime, lstrlenW, GetTempPathW, SetEnvironmentVariableW, CloseHandle, CreateFileW, GetDriveTypeW, SetCurrentDirectoryW, GetModuleFileNameW, GetCommandLineW, GetVersionExW, CreateEventW, SetEvent, ResetEvent, InitializeCriticalSection, TerminateThread, ResumeThread, SuspendThread, IsBadReadPtr, LocalFree, lstrcpyW, FormatMessageW, GetSystemDirectoryW, DeleteCriticalSection, GetFileSize, SetFilePointer, ReadFile, SetFileTime, SetEndOfFile, EnterCriticalSection, LeaveCriticalSection, WaitForMultipleObjects, GetModuleHandleA, SystemTimeToFileTime, GetLastError, CreateThread, WaitForSingleObject, GetExitCodeThread, Sleep, SetLastError, SetFileAttributesW, GetDiskFreeSpaceExW, lstrcatW, ExitProcess, CompareFileTime, GetStartupInfoA |
USER32.dll | CharUpperW, EndDialog, DestroyWindow, KillTimer, ReleaseDC, DispatchMessageW, GetMessageW, SetTimer, CreateWindowExW, ScreenToClient, GetWindowRect, wsprintfW, GetParent, GetSystemMenu, EnableMenuItem, EnableWindow, MessageBeep, LoadIconW, LoadImageW, wvsprintfW, IsWindow, DefWindowProcW, CallWindowProcW, DrawIconEx, DialogBoxIndirectParamW, GetWindow, ClientToScreen, GetDC, DrawTextW, ShowWindow, SystemParametersInfoW, SetFocus, SetWindowLongW, GetSystemMetrics, GetClientRect, GetDlgItem, GetKeyState, MessageBoxA, wsprintfA, SetWindowTextW, GetSysColor, GetWindowTextLengthW, GetWindowTextW, GetClassNameA, GetWindowLongW, GetMenu, SetWindowPos, CopyImage, SendMessageW, GetWindowDC |
GDI32.dll | GetCurrentObject, StretchBlt, SetStretchBltMode, CreateCompatibleBitmap, SelectObject, CreateCompatibleDC, GetObjectW, GetDeviceCaps, DeleteObject, CreateFontIndirectW, DeleteDC |
SHELL32.dll | SHGetFileInfoW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetMalloc, ShellExecuteExW, SHGetSpecialFolderPathW, ShellExecuteW |
ole32.dll | CoInitialize, CreateStreamOnHGlobal, CoCreateInstance |
OLEAUT32.dll | VariantClear, OleLoadPicture, SysAllocString |
MSVCRT.dll | __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, ??1type_info@@UAE@XZ, _onexit, __dllonexit, _CxxThrowException, _beginthreadex, _EH_prolog, memset, _wcsnicmp, strncmp, malloc, memmove, _wtol, memcpy, free, memcmp, _purecall, ??2@YAPAXI@Z, ??3@YAXPAX@Z, _except_handler3, _controlfp |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-25T13:39:49.816521+0100 | 2052875 | ET MALWARE Anonymous RAT CnC Checkin | 1 | 192.168.11.20 | 49755 | 134.122.155.90 | 9091 | TCP |
2024-12-25T13:46:36.336559+0100 | 2052875 | ET MALWARE Anonymous RAT CnC Checkin | 1 | 192.168.11.20 | 49773 | 134.122.155.90 | 9092 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 25, 2024 13:39:45.809895039 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.138766050 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.139064074 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.469439983 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469665051 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469690084 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469707012 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469726086 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469743013 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469760895 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469778061 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469831944 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.469903946 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.469944954 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.469949007 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.470051050 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.470153093 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.798614979 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.798655987 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.798687935 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.798891068 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.798899889 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.798942089 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.798971891 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799000978 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799030066 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799058914 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799087048 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799104929 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.799115896 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799149036 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.799191952 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799200058 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799201965 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799235106 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.799253941 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799295902 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799350977 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.799364090 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799371958 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799379110 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.799393892 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.799410105 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:46.800596952 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:46.800597906 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.128142118 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128278017 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128312111 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128340960 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128379107 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128407955 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128437996 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128490925 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.128595114 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.128644943 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128685951 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128716946 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128746986 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128777027 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128804922 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128834009 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128845930 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.128864050 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128895044 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128923893 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128952980 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.128978014 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.128982067 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129010916 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129040956 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129070044 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129098892 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129127026 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129141092 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129157066 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129184008 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129185915 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129300117 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129340887 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129359007 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129389048 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129417896 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129446983 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129475117 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129498959 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129504919 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129534006 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129542112 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129563093 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129607916 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129618883 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129652977 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129693985 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129723072 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129753113 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.129806995 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129858971 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.129954100 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.130084038 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.130121946 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.130305052 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.457926035 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.457993031 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458034039 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458069086 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458136082 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458173990 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458178997 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458254099 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458293915 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458328962 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458328962 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458364964 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458401918 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458435059 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458452940 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458452940 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458471060 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458506107 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458540916 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458553076 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458575010 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458600998 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458610058 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458645105 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458679914 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458713055 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458718061 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458750963 CET | 18852 | 49754 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:47.458777905 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.458856106 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:47.459014893 CET | 49754 | 18852 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:49.483107090 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:49.815954924 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:49.816266060 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:49.816520929 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.149127960 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.149640083 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.149713993 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.482326984 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.485835075 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.485866070 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.485888004 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.485908031 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486126900 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.486149073 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486179113 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486475945 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486500978 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486522913 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486545086 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486567020 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486675024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.486716986 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.486875057 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.487013102 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.818809032 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819035053 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819067955 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819091082 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819113016 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819336891 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819446087 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.819551945 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819786072 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.819858074 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819894075 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819916010 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819938898 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.819962025 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820128918 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.820128918 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.820132017 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820163012 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820185900 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820209026 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820231915 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820291042 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820314884 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820336103 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:50.820347071 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.820518017 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:50.820518017 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.152167082 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152204990 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152472019 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152475119 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.152508020 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152556896 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152595043 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152621984 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152647972 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152673006 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152698040 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152724028 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152750015 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152774096 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152800083 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152823925 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152848959 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152874947 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152900934 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152925014 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152951956 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.152976990 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153002977 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153027058 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153053045 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153213024 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153291941 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153327942 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153353930 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153373957 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153378010 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153404951 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153429985 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153455019 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153480053 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153505087 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153517008 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153531075 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.153877974 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.153996944 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.154023886 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.154023886 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.154023886 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.154033899 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.154061079 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.154088020 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.154192924 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.154206991 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.154455900 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.196783066 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.485642910 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.485831976 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.485858917 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.485878944 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486099005 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486099005 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486130953 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486157894 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486177921 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486207008 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486241102 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486263037 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486283064 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486301899 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486323118 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486342907 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486362934 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486382008 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486402035 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486413002 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486413002 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486413002 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486421108 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486440897 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486459017 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486459970 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486537933 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486594915 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486614943 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486634016 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486654043 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486661911 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486661911 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486661911 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486674070 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486694098 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486712933 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486732006 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486752033 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486835003 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486835003 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486835003 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.486859083 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.486861944 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487005949 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.487109900 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487138987 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487158060 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487174034 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.487178087 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487198114 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487266064 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487339020 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.487339020 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.487385988 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487416029 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.487479925 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.487659931 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.488112926 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488141060 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488161087 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488179922 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488198996 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488218069 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488236904 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488256931 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488426924 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.488426924 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.488763094 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488790989 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488811970 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488831043 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488965988 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.488982916 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.489119053 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489144087 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489151001 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.489164114 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489726067 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.489753008 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489800930 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489828110 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489846945 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489866972 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489886999 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489906073 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.489926100 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490092993 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.490426064 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.490520954 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490550995 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490571976 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490591049 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490787029 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.490839005 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490880966 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490909100 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490928888 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.490982056 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.491153955 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.491153955 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.491291046 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.491424084 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.491554976 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.491568089 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.491595984 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.491895914 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.529398918 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.529433012 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.529624939 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.819005966 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819034100 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819305897 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819331884 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819413900 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.819550037 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819566965 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.819614887 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819637060 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819861889 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819889069 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.819907904 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.819911003 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.820106030 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.820106030 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:51.820142984 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.820184946 CET | 9091 | 49755 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:51.820473909 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:52.868283033 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:53.195903063 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:53.196103096 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:54.851748943 CET | 49755 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:58.065901041 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:58.393476963 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:58.393548965 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:58.396511078 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:39:58.396846056 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:39:58.776011944 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:08.833101034 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:09.160700083 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:09.196753979 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:09.564831972 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:24.454618931 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:24.781991005 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:24.814246893 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:25.186115026 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:40.076189041 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:40.403764009 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:40.426997900 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:40.802253962 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:55.697848082 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:56.025298119 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:40:56.064126015 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:40:56.434618950 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:11.319355965 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:11.646657944 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:11.674320936 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:12.047310114 CET | 9091 | 49756 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:26.940860987 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:26.940860987 CET | 49756 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:28.878041029 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:29.212534904 CET | 9092 | 49757 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:29.212717056 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:33.764347076 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:33.764446974 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:34.096848011 CET | 9092 | 49757 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:34.096981049 CET | 9092 | 49757 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:34.114454031 CET | 9092 | 49757 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:34.114672899 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:34.492574930 CET | 9092 | 49757 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:44.858783007 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:44.858783960 CET | 49757 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:46.796073914 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:47.126327038 CET | 9091 | 49758 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:47.126553059 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:51.692184925 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:51.692245007 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:52.022584915 CET | 9091 | 49758 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:52.022631884 CET | 9091 | 49758 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:52.025669098 CET | 9091 | 49758 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:41:52.026071072 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:41:52.398936987 CET | 9091 | 49758 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:02.745461941 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:02.745462894 CET | 49758 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:04.682782888 CET | 49759 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:05.015311956 CET | 9092 | 49759 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:05.015594959 CET | 49759 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:09.578212976 CET | 49759 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:09.910619974 CET | 9092 | 49759 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:09.910898924 CET | 9092 | 49759 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:09.913660049 CET | 9092 | 49759 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:09.913934946 CET | 49759 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:10.300797939 CET | 9092 | 49759 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:20.679049015 CET | 49759 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:20.679049015 CET | 49759 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:22.616333961 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:22.948782921 CET | 9091 | 49760 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:22.949285030 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:27.562486887 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:27.562511921 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:27.894855022 CET | 9091 | 49760 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:27.894865990 CET | 9091 | 49760 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:27.897692919 CET | 9091 | 49760 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:27.898056030 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:28.273968935 CET | 9091 | 49760 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:38.581384897 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:38.581384897 CET | 49760 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:40.518560886 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:40.850056887 CET | 9092 | 49761 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:40.850236893 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:45.443300009 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:45.443373919 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:45.774878979 CET | 9092 | 49761 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:45.774893999 CET | 9092 | 49761 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:45.777709007 CET | 9092 | 49761 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:45.778057098 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:46.165045023 CET | 9092 | 49761 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:56.483647108 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:56.483647108 CET | 49761 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:58.420903921 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:42:58.751693964 CET | 9091 | 49762 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:42:58.751992941 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:03.397494078 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:03.397547007 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:03.728233099 CET | 9091 | 49762 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:03.728425026 CET | 9091 | 49762 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:03.733009100 CET | 9091 | 49762 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:03.733376026 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:04.110517025 CET | 9091 | 49762 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:14.432815075 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:14.432815075 CET | 49762 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:16.370105028 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:16.697169065 CET | 9092 | 49763 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:16.697366953 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:21.259605885 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:21.259638071 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:21.586668968 CET | 9092 | 49763 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:21.586678982 CET | 9092 | 49763 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:21.589591026 CET | 9092 | 49763 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:21.590058088 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:21.965625048 CET | 9092 | 49763 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:32.335203886 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:32.335203886 CET | 49763 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:34.272314072 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:34.606215954 CET | 9091 | 49764 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:34.606441021 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:39.204402924 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:39.204488039 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:39.538693905 CET | 9091 | 49764 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:39.538736105 CET | 9091 | 49764 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:39.541802883 CET | 9091 | 49764 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:39.542093992 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:39.931090117 CET | 9091 | 49764 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:50.253032923 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:50.253032923 CET | 49764 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:52.190275908 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:52.521672010 CET | 9092 | 49765 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:52.521853924 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:57.088069916 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:57.088151932 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:57.419733047 CET | 9092 | 49765 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:57.419915915 CET | 9092 | 49765 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:57.423082113 CET | 9092 | 49765 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:43:57.423437119 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:43:57.806848049 CET | 9092 | 49765 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:08.171156883 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:08.171156883 CET | 49765 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:10.108284950 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:10.436405897 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:10.436606884 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:15.021090984 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:15.021174908 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:15.349164963 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:15.349406004 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:15.352569103 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:15.353076935 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:15.722171068 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:26.057758093 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:26.385807991 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:26.405677080 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:26.785458088 CET | 9091 | 49766 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:41.695008039 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:41.695008039 CET | 49766 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:43.632244110 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:43.962326050 CET | 9092 | 49767 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:43.962505102 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:48.675295115 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:48.675362110 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:49.005019903 CET | 9092 | 49767 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:49.005251884 CET | 9092 | 49767 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:49.008426905 CET | 9092 | 49767 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:49.008749008 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:49.384310007 CET | 9092 | 49767 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:44:59.581769943 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:44:59.581769943 CET | 49767 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:01.518944025 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:01.847722054 CET | 9091 | 49768 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:01.847951889 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:06.424884081 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:06.424917936 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:06.753360987 CET | 9091 | 49768 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:06.753371000 CET | 9091 | 49768 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:06.756828070 CET | 9091 | 49768 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:06.757143974 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:07.138660908 CET | 9091 | 49768 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:17.468555927 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:17.468555927 CET | 49768 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:19.405756950 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:19.739573956 CET | 9092 | 49769 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:19.739845991 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:24.297297001 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:24.297321081 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:24.631127119 CET | 9092 | 49769 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:24.631140947 CET | 9092 | 49769 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:24.634591103 CET | 9092 | 49769 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:24.634906054 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:25.012882948 CET | 9092 | 49769 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:35.402112961 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:35.402112961 CET | 49769 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:37.339323997 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:37.667592049 CET | 9091 | 49770 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:37.667794943 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:42.225224018 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:42.225306034 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:42.553508043 CET | 9091 | 49770 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:42.553633928 CET | 9091 | 49770 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:42.556406021 CET | 9091 | 49770 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:42.556776047 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:42.937872887 CET | 9091 | 49770 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:53.288781881 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:53.288783073 CET | 49770 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:55.226052046 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:45:55.560272932 CET | 9092 | 49771 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:45:55.560540915 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:00.123317957 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:00.123369932 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:00.457498074 CET | 9092 | 49771 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:00.459419012 CET | 9092 | 49771 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:00.460463047 CET | 9092 | 49771 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:00.460892916 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:00.837711096 CET | 9092 | 49771 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:11.191176891 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:11.191176891 CET | 49771 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:13.128375053 CET | 49772 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:13.459208012 CET | 9091 | 49772 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:13.459392071 CET | 49772 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:18.041598082 CET | 49772 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:18.372340918 CET | 9091 | 49772 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:18.372402906 CET | 9091 | 49772 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:18.375363111 CET | 9091 | 49772 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:18.375772953 CET | 49772 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:18.760488987 CET | 9091 | 49772 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:29.077951908 CET | 49772 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:29.077971935 CET | 49772 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:31.015563011 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:31.348201990 CET | 9092 | 49773 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:31.348458052 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:35.947345018 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:35.947396040 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:36.280041933 CET | 9092 | 49773 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:36.280056953 CET | 9092 | 49773 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:36.336177111 CET | 9092 | 49773 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:36.336559057 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:36.717802048 CET | 9092 | 49773 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:47.011470079 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:47.011470079 CET | 49773 | 9092 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:48.948862076 CET | 49774 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:49.282882929 CET | 9091 | 49774 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:49.283175945 CET | 49774 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:53.892329931 CET | 49774 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:53.892426968 CET | 49774 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:54.226480007 CET | 9091 | 49774 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:54.226522923 CET | 9091 | 49774 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:54.229363918 CET | 9091 | 49774 | 134.122.155.90 | 192.168.11.20 |
Dec 25, 2024 13:46:54.229681969 CET | 49774 | 9091 | 192.168.11.20 | 134.122.155.90 |
Dec 25, 2024 13:46:54.616363049 CET | 9091 | 49774 | 134.122.155.90 | 192.168.11.20 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:38:29 |
Start date: | 25/12/2024 |
Path: | C:\Users\user\Desktop\WiezmDFd6L.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 37'394'506 bytes |
MD5 hash: | 37B0FD9C5E815053E72C20931D2E414C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 07:38:34 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x200000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 07:38:34 |
Start date: | 25/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b77d0000 |
File size: | 875'008 bytes |
MD5 hash: | 81CA40085FC75BABD2C91D18AA9FFA68 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 07:38:34 |
Start date: | 25/12/2024 |
Path: | C:\Users\Public\Bilite\Axialis\RuntimeBrokers.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xec0000 |
File size: | 777'816 bytes |
MD5 hash: | 30A274E00DA842B09E9763F19777ADED |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x200000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b77d0000 |
File size: | 875'008 bytes |
MD5 hash: | 81CA40085FC75BABD2C91D18AA9FFA68 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 7 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x200000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b77d0000 |
File size: | 875'008 bytes |
MD5 hash: | 81CA40085FC75BABD2C91D18AA9FFA68 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x200000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b77d0000 |
File size: | 875'008 bytes |
MD5 hash: | 81CA40085FC75BABD2C91D18AA9FFA68 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 13 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb40000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 14 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 15 |
Start time: | 07:39:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb40000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 16 |
Start time: | 07:40:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 17 |
Start time: | 07:40:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 07:40:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 07:40:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 07:40:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 21 |
Start time: | 07:40:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 07:41:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 23 |
Start time: | 07:41:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 24 |
Start time: | 07:41:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 25 |
Start time: | 07:41:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 26 |
Start time: | 07:41:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 27 |
Start time: | 07:41:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 28 |
Start time: | 07:42:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 29 |
Start time: | 07:42:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 30 |
Start time: | 07:42:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 31 |
Start time: | 07:42:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 32 |
Start time: | 07:42:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 33 |
Start time: | 07:42:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 34 |
Start time: | 07:43:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 35 |
Start time: | 07:43:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 36 |
Start time: | 07:43:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 37 |
Start time: | 07:43:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 38 |
Start time: | 07:43:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 39 |
Start time: | 07:43:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 40 |
Start time: | 07:44:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 41 |
Start time: | 07:44:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 42 |
Start time: | 07:44:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 43 |
Start time: | 07:44:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 44 |
Start time: | 07:44:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 45 |
Start time: | 07:44:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 46 |
Start time: | 07:45:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 47 |
Start time: | 07:45:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\findstr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x30000 |
File size: | 29'696 bytes |
MD5 hash: | F1D4BE0E99EC734376FDE474A8D4EA3E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 48 |
Start time: | 07:45:15 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\timeout.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 25'088 bytes |
MD5 hash: | 976566BEEFCCA4A159ECBDB2D4B1A3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 49 |
Start time: | 07:45:45 |
Start date: | 25/12/2024 |
Path: | C:\Windows\SysWOW64\tasklist.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 79'360 bytes |
MD5 hash: | 0A4448B31CE7F83CB7691A2657F330F1 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 17.9% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 26.9% |
Total number of Nodes: | 1422 |
Total number of Limit Nodes: | 15 |
Graph
Function 00404FAA Relevance: 250.2, APIs: 103, Strings: 39, Instructions: 1671keyboardsynchronizationwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401626 Relevance: 22.8, APIs: 15, Instructions: 304COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040301A Relevance: 7.5, APIs: 5, Instructions: 45COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040118A Relevance: 3.0, APIs: 2, Instructions: 42windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401B37 Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 47timewindowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402844 Relevance: 6.4, APIs: 5, Instructions: 118stringCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040150B Relevance: 6.1, APIs: 4, Instructions: 100synchronizationthreadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401986 Relevance: 6.0, APIs: 4, Instructions: 27COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040ADC3 Relevance: 4.5, APIs: 3, Instructions: 35COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040C9FC Relevance: 3.2, APIs: 2, Instructions: 184COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A62F Relevance: 3.1, APIs: 2, Instructions: 135COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040112B Relevance: 3.0, APIs: 2, Instructions: 42COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040D9F0 Relevance: 3.0, APIs: 2, Instructions: 30COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040ECED Relevance: 3.0, APIs: 2, Instructions: 24memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E73A Relevance: 2.5, APIs: 2, Instructions: 34COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040A7DE Relevance: 1.6, APIs: 1, Instructions: 74COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040120B Relevance: 1.5, APIs: 1, Instructions: 28COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411A2D Relevance: 1.5, APIs: 1, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040DA56 Relevance: 1.5, APIs: 1, Instructions: 23fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040DB97 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040653F Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040CC59 Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040DADC Relevance: 1.5, APIs: 1, Instructions: 18fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040DB6A Relevance: 1.5, APIs: 1, Instructions: 9timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E9F7 Relevance: 1.3, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E5D3 Relevance: 1.3, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040F42D Relevance: 1.3, APIs: 1, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402F6C Relevance: 1.3, APIs: 1, Instructions: 17COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040D985 Relevance: 1.3, APIs: 1, Instructions: 16COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004024C4 Relevance: 1.3, APIs: 1, Instructions: 12memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401B1F Relevance: 1.3, APIs: 1, Instructions: 5COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040F3FC Relevance: 1.3, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004034C1 Relevance: 37.0, APIs: 20, Strings: 1, Instructions: 290comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401F9D Relevance: 33.4, APIs: 16, Strings: 3, Instructions: 150stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BDF Relevance: 26.3, APIs: 11, Strings: 4, Instructions: 85libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406D5D Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 39libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041022D Relevance: .5, Instructions: 501COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041206B Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411F91 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040D72E Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404AFF Relevance: 36.9, APIs: 14, Strings: 7, Instructions: 144fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404603 Relevance: 35.2, APIs: 3, Strings: 17, Instructions: 207stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402DC0 Relevance: 35.1, APIs: 16, Strings: 4, Instructions: 123windowlibrarystringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401DF3 Relevance: 28.1, APIs: 14, Strings: 2, Instructions: 120windowcommemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403093 Relevance: 26.5, APIs: 10, Strings: 5, Instructions: 244stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406A47 Relevance: 24.3, APIs: 16, Instructions: 270COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040677A Relevance: 13.5, APIs: 9, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406DB2 Relevance: 12.1, APIs: 8, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040695E Relevance: 12.1, APIs: 8, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040408B Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 96stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040755F Relevance: 10.6, APIs: 7, Instructions: 63timethreadinjectionCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407B33 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 102windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401000 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 44stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004021ED Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 39libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402185 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 13libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004021B9 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 12libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402A69 Relevance: 6.1, APIs: 4, Instructions: 101COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403F85 Relevance: 6.1, APIs: 4, Instructions: 66COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A85 Relevance: 6.1, APIs: 4, Instructions: 65COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407FA5 Relevance: 6.1, APIs: 4, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004067ED Relevance: 6.1, APIs: 4, Instructions: 56COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040748A Relevance: 6.1, APIs: 4, Instructions: 55COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004027C7 Relevance: 6.1, APIs: 4, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403AB1 Relevance: 6.0, APIs: 4, Instructions: 41COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040702A Relevance: 6.0, APIs: 4, Instructions: 34windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BA3 Relevance: 6.0, APIs: 4, Instructions: 28COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C329F0 Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C32B00 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0353D01D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0353D006 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071317D8 Relevance: 2.8, Strings: 2, Instructions: 286COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 041A29F0 Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071317BC Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 041A2B00 Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 041A3C00 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 041A3BF2 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090D01D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0090D01C Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07130518 Relevance: 9.1, Strings: 7, Instructions: 322COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07131168 Relevance: 6.4, Strings: 5, Instructions: 192COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07134298 Relevance: 6.4, Strings: 5, Instructions: 128COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07131418 Relevance: 6.4, Strings: 5, Instructions: 123COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07133550 Relevance: 5.3, Strings: 4, Instructions: 255COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 071332A8 Relevance: 5.1, Strings: 4, Instructions: 94COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07130308 Relevance: 5.0, Strings: 4, Instructions: 50COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|