Windows
Analysis Report
TieLoader.exe
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- TieLoader.exe (PID: 5260 cmdline:
"C:\Users\ user\Deskt op\TieLoad er.exe" MD5: 25CB0B651E95894E6543855BE5538B5F) - conhost.exe (PID: 6028 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - chrome.exe (PID: 1352 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t http://g o.microsof t.com/fwli nk/?prd=11 324&pver=4 .5&sbp=App Launch2&pl cid=0x409& o1=SHIM_NO VERSION_FO UND&versio n=(null)&p rocessName =TieLoader .exe&platf orm=0009&o sver=6&isS erver=0&sh imver=4.0. 30319.0 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 7304 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2464 --fi eld-trial- handle=238 4,i,130203 9302958582 051,133451 6785259241 1874,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 8020 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t http://g o.microsof t.com/fwli nk/?prd=11 324&pver=4 .5&sbp=App Launch2&pl cid=0x409& o1=SHIM_NO VERSION_FO UND&versio n=(null)&p rocessName =TieLoader .exe&platf orm=0009&o sver=6&isS erver=0&sh imver=4.0. 30319.0 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 7668 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2040 --fi eld-trial- handle=200 8,i,330603 4645096874 563,120388 8729722097 9311,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Joe Sandbox ML: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Static PE information: |
Source: | Static PE information: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 DLL Side-Loading | 11 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 2 Software Packing | LSASS Memory | 1 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 File Deletion | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | high | |
www.google.com | 142.250.185.68 | true | false | high | |
s-part-0032.t-0009.t-msedge.net | 13.107.246.60 | true | false | high | |
js.monitor.azure.com | unknown | unknown | false | high | |
mdec.nelreports.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.185.68 | www.google.com | United States | 15169 | GOOGLEUS | false | |
13.107.246.60 | s-part-0032.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false |
IP |
---|
192.168.2.7 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582874 |
Start date and time: | 2024-12-31 17:38:23 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | TieLoader.exe |
Detection: | MAL |
Classification: | mal60.winEXE@26/70@8/4 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.184.195, 184.28.89.167, 216.58.212.142, 74.125.133.84, 23.32.186.2, 172.217.16.206, 216.58.206.78, 142.250.185.238, 199.232.214.172, 20.42.65.84, 142.250.181.234, 142.250.186.74, 142.250.74.202, 142.250.185.106, 172.217.16.138, 142.250.185.138, 172.217.23.106, 216.58.206.42, 142.250.186.138, 142.250.186.42, 216.58.206.74, 142.250.185.170, 142.250.185.202, 142.250.184.202, 142.250.185.234, 142.250.186.170, 2.16.168.102, 2.16.168.100, 13.74.129.1, 104.208.16.91, 204.79.197.237, 13.107.21.237, 142.250.185.174, 142.250.184.238, 142.250.184.206, 142.250.74.206, 142.250.185.227, 142.250.186.174, 142.250.186.78, 34.104.35.123, 142.250.185.110, 172.217.18.14, 142.250.181.238, 13.107.246.45, 184.28.90.27, 20.109.210.53
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, c-msn-com-nsatc.trafficmanager.net, clientservices.googleapis.com, browser.events.data.trafficmanager.net, learn.microsoft.com, time.windows.com, onedscolprdcus17.centralus.cloudapp.azure.com, e11290.dspg.akamaiedge.net, mdec.nelreports.net.akamaized.net, go.microsoft.com, clients2.google.com, redirector.gvt1.com, star-azurefd-prod.trafficmanager.net, a1883.dscd.akamai.net, learn.microsoft.com.edgekey.net, onedscolprdeus02.eastus.cloudapp.azure.com, update.googleapis.com, clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, otelrules.azureedge.net, c-bing-com.dual-a-0034.a-msedge.net, ctldl.windowsupdate.com, learn.microsoft.com.edgekey.net.globalredir.akadns.net, firstparty-azurefd-prod.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, browser.events.data.microsoft.com, edgedl.me.gvt1.com, e13636.dscb.akamaiedge.net, c.bing.com, learn-public.trafficmanager.net, go.microsoft.com.edgekey.net, du
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: TieLoader.exe
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
239.255.255.250 | Get hash | malicious | HTMLPhisher, KnowBe4 | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Vidar | Browse | |||
Get hash | malicious | Vidar | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | LummaC, Amadey, Babadeda, LummaC Stealer, Stealc, Vidar | Browse | |||
Get hash | malicious | LummaC | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
13.107.246.60 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | HTMLPhisher, KnowBe4 | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
s-part-0032.t-0009.t-msedge.net | Get hash | malicious | LodaRAT | Browse |
| |
Get hash | malicious | LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | Vidar | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix, DcRat, KeyLogger, StormKitty, VenomRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Vidar | Browse |
|
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping1352_1553945186\LICENSE
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1558 |
Entropy (8bit): | 5.11458514637545 |
Encrypted: | false |
SSDEEP: | 48:OBOCrYJ4rYJVwUCLHDy43HV713XEyMmZ3teTHn:LCrYJ4rYJVwUCHZ3Z13XtdUTH |
MD5: | EE002CB9E51BB8DFA89640A406A1090A |
SHA1: | 49EE3AD535947D8821FFDEB67FFC9BC37D1EBBB2 |
SHA-256: | 3DBD2C90050B652D63656481C3E5871C52261575292DB77D4EA63419F187A55B |
SHA-512: | D1FDCC436B8CA8C68D4DC7077F84F803A535BF2CE31D9EB5D0C466B62D6567B2C59974995060403ED757E92245DB07E70C6BDDBF1C3519FED300CC5B9BF9177C |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping1352_1553945186\_metadata\verified_contents.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 6.018989605004616 |
Encrypted: | false |
SSDEEP: | 48:p/hUI1OwEU3AdIq7ak68O40E2szOxxUJ8BPFkf31U4PrHfqY3J5D:RnOwtQIq7aZ40E2sYUJAYRr/qYZ5D |
MD5: | C4709C1D483C9233A3A66A7E157624EA |
SHA1: | 99A000EB5FE5CC1E94E3155EE075CD6E43DC7582 |
SHA-256: | 225243DC75352D63B0B9B2F48C8AAA09D55F3FB9E385741B12A1956A941880D9 |
SHA-512: | B45E1FD999D1340CC5EB5A49A4CD967DC736EA3F4EC8B02227577CC3D1E903341BE3217FBB0B74765C72085AC51C63EEF6DCB169D137BBAF3CC49E21EA6468D7 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping1352_1553945186\manifest.fingerprint
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.820000180714897 |
Encrypted: | false |
SSDEEP: | 3:SVzHL3phUmWRDNKydvgHVz:SBHLLUmWRbCp |
MD5: | BBEC7670A2519FEB0627F17D0C0B5276 |
SHA1: | 9C30B996F1B069F86EF7C0136DFAF7E614674DEA |
SHA-256: | 670A6F6BBADAB2C2BE63898525FCAF72E7454739E77C04D120BC1A46B6694CAC |
SHA-512: | 1ED4ED6AE2A2CBE86F9E8C6C7A2672EBB2F37DBE83D2BF09D875DB435ED63BF5F5CF60CA846865166F9A498095F6D61BD51B0A092E097430439E8A5A3A14CB15 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping1352_1553945186\manifest.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85 |
Entropy (8bit): | 4.462192586591686 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifFCmMARWHJqS1kULJVPY:F6VlM8aRWpqS1kSJVg |
MD5: | 084E339C0C9FE898102815EAC9A7CDEA |
SHA1: | 6ABF7EAAA407D2EAB8706361E5A2E5F776D6C644 |
SHA-256: | 52CD62F4AC1F9E7D7C4944EE111F84A42337D16D5DE7BE296E945146D6D7DC15 |
SHA-512: | 0B67A89F3EBFF6FEC3796F481EC2AFBAC233CF64FDC618EC6BA1C12AE125F28B27EE09E8CD0FADB8F6C8785C83929EA6F751E0DDF592DD072AB2CF439BD28534 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping1352_1553945186\sets.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9817 |
Entropy (8bit): | 4.629347296880043 |
Encrypted: | false |
SSDEEP: | 96:Mon4mvC4qX19s1blbw/BNKLcxbdmf56MFJtRTGXvcxN43uP+8qJl:v5C4ql7BkIVmtRTGXvcxBsl |
MD5: | 8C702C686B703020BC0290BAFC90D7A0 |
SHA1: | EB08FF7885B4C1DE3EF3D61E40697C0C71903E27 |
SHA-256: | 97D9E39021512305820F27B9662F0351E45639124F5BD29F0466E9072A9D0C62 |
SHA-512: | 6137D0ED10E6A27924ED3AB6A0C5F9B21EB0E16A876447DADABD88338198F31BB9D89EF8F0630F4573EA34A24FB3FD3365D7EA78A97BA10028A0758E0A550739 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 13339 |
Entropy (8bit): | 7.683569563478597 |
Encrypted: | false |
SSDEEP: | 192:zjSKAj04ndWb6OuzZjk6TsEaJS0/bJur2Gz4Imm3MhE4NfM:zutfW69XTspsG3G0TfhEQM |
MD5: | 512625CF8F40021445D74253DC7C28C0 |
SHA1: | F6B27CE0F7D4E48E34FDDCA8A96337F07CFFE730 |
SHA-256: | 1D4DCEE8511D5371FEC911660D6049782E12901C662B409A5C675772E9B87369 |
SHA-512: | AE02319D03884D758A86C286B6F593BDFFD067885D56D82EEB8215FDCB41637C7BB9109039E7FBC93AD246D030C368FB285B3161976ED485ABC5A8DF6DF9A38C |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/install/media/application-not-started/repair-tool-changes-complete.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
URL: | https://learn.microsoft.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5644 |
Entropy (8bit): | 4.785769732002188 |
Encrypted: | false |
SSDEEP: | 96:ogVOjPW7cI3aDNjExAjfWQpL0dpwmWMv7AD8RevyvRJNjyZPtJ27RlhiewZjMeZf:og5cUaDNjESLWQN0dpwm9+6DlUu7lYjX |
MD5: | B5885C991E30238110973653F2408300 |
SHA1: | 39B0A79D951F8254E21821134E047C76F57AD2A8 |
SHA-256: | 085BF5AE32E6F7F1299CA79248B0CB67EBD31566728A69F4466E1659C004732E |
SHA-512: | 6BEC209D933C7A1065047637F550B7A36809D835938C04851A3B09DF644BD3EC85A2CE30F73FCFB709FE7AF3453799B2EB76702D0AB2BE067CD07D2EC03537C0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 13842 |
Entropy (8bit): | 7.802399161550213 |
Encrypted: | false |
SSDEEP: | 192:NLNf+jBQsDHg7av3EEondO8PuRu2mIYXEIiDm42NpsHFMHfgnJ4K2DVwv:NLt+1jDmY+ndXwjLUpiDwpzfwoDVk |
MD5: | F6EC97C43480D41695065AD55A97B382 |
SHA1: | D9C3D0895A5ED1A3951B8774B519B8217F0A54C5 |
SHA-256: | 07A599FAB1E66BABC430E5FED3029F25FF3F4EA2DD0EC8968FFBA71EF1872F68 |
SHA-512: | 22462763178409D60609761A2AF734F97B35B9A818EC1FD9046AFAB489AAD83CE34896EE8586EFE402EA7739ECF088BC2DB5C1C8E4FB39E6A0FC5B3ADC6B4A9B |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/install/media/application-not-started/install-3-5.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33273 |
Entropy (8bit): | 4.918756013698695 |
Encrypted: | false |
SSDEEP: | 384:FnvJOb4OLIch+KCnMet7NPXlJl+HjZjBTRdE0zIwHdZ4vNNpUjV8din4E9hLUukj:5hOEO8chkMet7pCjBfcHkWOzUukj |
MD5: | 86E84C732A96BF9CF18C99B48DB90B6D |
SHA1: | 6A8C212067CB9FE5B8325AE1E89FCA3E7FCF20FA |
SHA-256: | B54678C5BFB00DC1AFBF2E52C56F8E10173975C25FB19062EFE5DC86F1B7D769 |
SHA-512: | AD91A78371074B5BB2105A9AE69664371C235B7C82DFD25C9ED17F435E92018F2A0DD42203F403D7A75DF4FC63966017519F118B2B22F0DE7656B2B155636AA2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.241202481433726 |
Encrypted: | false |
SSDEEP: | 3:YozDD/RNgQJzRWWlKFiFD3e4xCzY:YovtNgmzR/wYFDxkY |
MD5: | 9E576E34B18E986347909C29AE6A82C6 |
SHA1: | 532C767978DC2B55854B3CA2D2DF5B4DB221C934 |
SHA-256: | 88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D |
SHA-512: | 5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5644 |
Entropy (8bit): | 4.785769732002188 |
Encrypted: | false |
SSDEEP: | 96:ogVOjPW7cI3aDNjExAjfWQpL0dpwmWMv7AD8RevyvRJNjyZPtJ27RlhiewZjMeZf:og5cUaDNjESLWQN0dpwm9+6DlUu7lYjX |
MD5: | B5885C991E30238110973653F2408300 |
SHA1: | 39B0A79D951F8254E21821134E047C76F57AD2A8 |
SHA-256: | 085BF5AE32E6F7F1299CA79248B0CB67EBD31566728A69F4466E1659C004732E |
SHA-512: | 6BEC209D933C7A1065047637F550B7A36809D835938C04851A3B09DF644BD3EC85A2CE30F73FCFB709FE7AF3453799B2EB76702D0AB2BE067CD07D2EC03537C0 |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/content-nav/site-header/site-header.json? |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 19696 |
Entropy (8bit): | 7.9898910353479335 |
Encrypted: | false |
SSDEEP: | 384:37wfQhsuDSP36Elj0oScS8w3F1ZTt5JwtRGsh1SJR3YL0BeojRs8E:37Cms69owH3FPutReFYL+eods8E |
MD5: | 4D0BFEA9EBDA0657CEE433600ED087B6 |
SHA1: | F13C690B170D5BA6BE45DEDC576776CA79718D98 |
SHA-256: | 67E7D8E61B9984289B6F3F476BBEB6CEB955BEC823243263CF1EE57D7DB7AE9A |
SHA-512: | 9136ADEC32F1D29A72A486B4604309AA8F9611663FA1E8D49079B67260B2B09CEFDC3852CF5C08CA9F5D8EA718A16DBD8D8120AC3164B0D1519D8EF8A19E4EA5 |
Malicious: | false |
URL: | https://learn.microsoft.com/static/assets/0.4.029026183/styles/docons.6a251ae.34a85e0c.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64291 |
Entropy (8bit): | 7.964191793580486 |
Encrypted: | false |
SSDEEP: | 1536:NHnitWEy8ugr5KeKvJx4FqzmYyIf52YHcd/HpQxhSoywkY8+N4U4Bv:NHitHyJTeysFqiYyIfEYHchQWoywkY8v |
MD5: | 8CCB0248B7F2ABEEAD74C057232DF42A |
SHA1: | C02BD92FEA2DF7ED12C8013B161670B39E1EC52F |
SHA-256: | 0A9FD0C7F32EABBB2834854C655B958EC72A321F3C1CF50035DD87816591CDCC |
SHA-512: | 6D6E3C858886C9D6186AD13B94DBC2D67918AA477FB7D70A7140223FAB435CF109537C51CA7F4B2A0DB00EEAD806BBE8C6B29B947B0BE7044358D2823F5057CE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 35005 |
Entropy (8bit): | 7.980061050467981 |
Encrypted: | false |
SSDEEP: | 768:aHBEr/QXnbCgWotMq4AZZivq2/Qu0cEv1FjHBep6U0Z/68R:ahWqbTWiM7ACvdIdldhep4rR |
MD5: | 522037F008E03C9448AE0AAAF09E93CB |
SHA1: | 8A32997EAB79246BEED5A37DB0C92FBFB006BEF2 |
SHA-256: | 983C35607C4FB0B529CA732BE42115D3FCAAC947CEE9C9632F7CACDBDECAF5A7 |
SHA-512: | 643EC613B2E7BDBB2F61E1799C189B0E3392EA5AE10845EB0B1F1542A03569E886F4B54D5B38AF10E78DB49C71357108C94589474B181F6A4573B86CF2D6F0D8 |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/install/media/application-not-started/app-could-not-be-started.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.241202481433726 |
Encrypted: | false |
SSDEEP: | 3:YozDD/RNgQJzRWWlKFiFD3e4xCzY:YovtNgmzR/wYFDxkY |
MD5: | 9E576E34B18E986347909C29AE6A82C6 |
SHA1: | 532C767978DC2B55854B3CA2D2DF5B4DB221C934 |
SHA-256: | 88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D |
SHA-512: | 5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4897 |
Entropy (8bit): | 4.8007377074457604 |
Encrypted: | false |
SSDEEP: | 96:A0AIvEQ+KfZcbhaW9dp45qtAdflfDOFnymoLByzfwqrLvJ4QG63JkRJ+dRp8TJHr:dgQ+KfZcbhaWjp45qtAdflfDOFnNgByQ |
MD5: | 0E78F790402498FA57E649052DA01218 |
SHA1: | 9ED4D0846DA5D66D44EE831920B141BBF60A0200 |
SHA-256: | 73F3061A46EA8FD11D674FB21FEEEFE3753FC3A3ED77224E7F66A964C0420603 |
SHA-512: | B46E4B90E53C7DABC7208A6FDAE53F25BD70FCFBBEF03FFC64B1B5D1EB1C01C870A7309DF167246FCCD114B483038A64D7C46CA3B9FCB3779A77E42DB6967051 |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/content-nav/MSDocsHeader-DotNet.json? |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.241202481433726 |
Encrypted: | false |
SSDEEP: | 3:YozDD/RNgQJzRWWlKFiFD3e4xCzY:YovtNgmzR/wYFDxkY |
MD5: | 9E576E34B18E986347909C29AE6A82C6 |
SHA1: | 532C767978DC2B55854B3CA2D2DF5B4DB221C934 |
SHA-256: | 88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D |
SHA-512: | 5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 64291 |
Entropy (8bit): | 7.964191793580486 |
Encrypted: | false |
SSDEEP: | 1536:NHnitWEy8ugr5KeKvJx4FqzmYyIf52YHcd/HpQxhSoywkY8+N4U4Bv:NHitHyJTeysFqiYyIfEYHchQWoywkY8v |
MD5: | 8CCB0248B7F2ABEEAD74C057232DF42A |
SHA1: | C02BD92FEA2DF7ED12C8013B161670B39E1EC52F |
SHA-256: | 0A9FD0C7F32EABBB2834854C655B958EC72A321F3C1CF50035DD87816591CDCC |
SHA-512: | 6D6E3C858886C9D6186AD13B94DBC2D67918AA477FB7D70A7140223FAB435CF109537C51CA7F4B2A0DB00EEAD806BBE8C6B29B947B0BE7044358D2823F5057CE |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/media/event-banners/banner-learn-challenge-2024.jpg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1173007 |
Entropy (8bit): | 5.503893944397598 |
Encrypted: | false |
SSDEEP: | 24576:VMga+4IVzOjS1Jho1WXQFjTEr39/jHXzT:VMcVzOjS1Jho1WXQar39/bXzT |
MD5: | 2E00D51C98DBB338E81054F240E1DEB2 |
SHA1: | D33BAC6B041064AE4330DCC2D958EBE4C28EBE58 |
SHA-256: | 300480069078B5892D2363A2B65E2DFBBF30FE5C80F83EDBFECF4610FD093862 |
SHA-512: | B6268D980CE9CB729C82DBA22F04FD592952B2A1AAB43079CA5330C68A86E72B0D232CE4070DB893A5054EE5C68325C92C9F1A33F868D61EBB35129E74FC7EF9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1154 |
Entropy (8bit): | 4.59126408969148 |
Encrypted: | false |
SSDEEP: | 24:txFRuJpzYeGK+VS6ckNL2091JP/UcHc8oQJ1sUWMLc/jH6GbKqjHJIOHA:JsfcU6ckNL2091Z/U/YsUDM+GhS |
MD5: | 37258A983459AE1C2E4F1E551665F388 |
SHA1: | 603A4E9115E613CC827206CF792C62AEB606C941 |
SHA-256: | 8E34F3807B4BF495D8954E7229681DA8D0DD101DD6DDC2AD7F90CD2983802B44 |
SHA-512: | 184CB63EF510143B0AF013F506411C917D68BB63F2CFA47EA2A42688FD4F55F3B820AF94F87083C24F48AACEE6A692199E185FC5C5CFBED5D70790454EED7F5C |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/media/logos/logo_net.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 33273 |
Entropy (8bit): | 4.918756013698695 |
Encrypted: | false |
SSDEEP: | 384:FnvJOb4OLIch+KCnMet7NPXlJl+HjZjBTRdE0zIwHdZ4vNNpUjV8din4E9hLUukj:5hOEO8chkMet7pCjBfcHkWOzUukj |
MD5: | 86E84C732A96BF9CF18C99B48DB90B6D |
SHA1: | 6A8C212067CB9FE5B8325AE1E89FCA3E7FCF20FA |
SHA-256: | B54678C5BFB00DC1AFBF2E52C56F8E10173975C25FB19062EFE5DC86F1B7D769 |
SHA-512: | AD91A78371074B5BB2105A9AE69664371C235B7C82DFD25C9ED17F435E92018F2A0DD42203F403D7A75DF4FC63966017519F118B2B22F0DE7656B2B155636AA2 |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/toc.json |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35005 |
Entropy (8bit): | 7.980061050467981 |
Encrypted: | false |
SSDEEP: | 768:aHBEr/QXnbCgWotMq4AZZivq2/Qu0cEv1FjHBep6U0Z/68R:ahWqbTWiM7ACvdIdldhep4rR |
MD5: | 522037F008E03C9448AE0AAAF09E93CB |
SHA1: | 8A32997EAB79246BEED5A37DB0C92FBFB006BEF2 |
SHA-256: | 983C35607C4FB0B529CA732BE42115D3FCAAC947CEE9C9632F7CACDBDECAF5A7 |
SHA-512: | 643EC613B2E7BDBB2F61E1799C189B0E3392EA5AE10845EB0B1F1542A03569E886F4B54D5B38AF10E78DB49C71357108C94589474B181F6A4573B86CF2D6F0D8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13842 |
Entropy (8bit): | 7.802399161550213 |
Encrypted: | false |
SSDEEP: | 192:NLNf+jBQsDHg7av3EEondO8PuRu2mIYXEIiDm42NpsHFMHfgnJ4K2DVwv:NLt+1jDmY+ndXwjLUpiDwpzfwoDVk |
MD5: | F6EC97C43480D41695065AD55A97B382 |
SHA1: | D9C3D0895A5ED1A3951B8774B519B8217F0A54C5 |
SHA-256: | 07A599FAB1E66BABC430E5FED3029F25FF3F4EA2DD0EC8968FFBA71EF1872F68 |
SHA-512: | 22462763178409D60609761A2AF734F97B35B9A818EC1FD9046AFAB489AAD83CE34896EE8586EFE402EA7739ECF088BC2DB5C1C8E4FB39E6A0FC5B3ADC6B4A9B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4897 |
Entropy (8bit): | 4.8007377074457604 |
Encrypted: | false |
SSDEEP: | 96:A0AIvEQ+KfZcbhaW9dp45qtAdflfDOFnymoLByzfwqrLvJ4QG63JkRJ+dRp8TJHr:dgQ+KfZcbhaWjp45qtAdflfDOFnNgByQ |
MD5: | 0E78F790402498FA57E649052DA01218 |
SHA1: | 9ED4D0846DA5D66D44EE831920B141BBF60A0200 |
SHA-256: | 73F3061A46EA8FD11D674FB21FEEEFE3753FC3A3ED77224E7F66A964C0420603 |
SHA-512: | B46E4B90E53C7DABC7208A6FDAE53F25BD70FCFBBEF03FFC64B1B5D1EB1C01C870A7309DF167246FCCD114B483038A64D7C46CA3B9FCB3779A77E42DB6967051 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1817143 |
Entropy (8bit): | 5.501007973622959 |
Encrypted: | false |
SSDEEP: | 24576:aLX8PHFluFxBSB1DkCXWjfz8gEPPXL/tie:auHFluFxBSB1DkCXWjfz7EPPXztH |
MD5: | F57E274AE8E8889C7516D3E53E3EB026 |
SHA1: | F8D21465C0C19051474BE6A4A681FA0B0D3FCC0C |
SHA-256: | 2A2198DDBDAEDD1E968C0A1A45F800765AAE703675E419E46F6E51E3E9729D01 |
SHA-512: | 9A9B42F70E09D821B799B92CB6AC981236FCF190F0A467CA7F7D382E3BCA1BC1D71673D37CD7426499D24DFBC0B7A6D10676C0E3FB2B0292249A5ABAB78F23F4 |
Malicious: | false |
URL: | https://learn.microsoft.com/static/assets/0.4.029026183/scripts/en-us/index-docs.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 47062 |
Entropy (8bit): | 5.016149588804727 |
Encrypted: | false |
SSDEEP: | 768:haAq16LIElO6L6x2bTI1ln4a1T0MCFnFMBVeZrdLg:hTKGLlO6eAbTIr4audZqBkZRLg |
MD5: | 1FF4CE3C1DB69A5146B03AD8BE62F5EB |
SHA1: | 5D177F6D11FCFF2BD62E61983383BB39D9F045E4 |
SHA-256: | 222F320F99EF710DCE98F125314F30DAC99CF408525D86F185B317A878D48A5C |
SHA-512: | 36D198120D83AA9BDC2E74F80B99E2219EE4F03A8DD93A1E58A9E30BD48E829E5220A9F5FE6FC29B3810ED85005A8DCD0EAD04EE06DCCD0A15CD6D080E88641D |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/install/application-not-started?version=(null)&processName=TieLoader.exe&platform=0009&osver=6&isServer=0&shimver=4.0.30319.0 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3130 |
Entropy (8bit): | 4.790069981348324 |
Encrypted: | false |
SSDEEP: | 48:YWuGl640ynAqgDJ9OJWuO6Z3Db8VgK/ni47ttbtlSlA37ERw7II77Aj5M1:Nv0ynAhD3CO5t5lNEYIOEjc |
MD5: | EBA6E81304F2F555E1D2EA3126A18A41 |
SHA1: | 61429C3FE837FD4DD68E7B26678F131F2E00070D |
SHA-256: | F309CCCE17B2B4706E7110F6C76F81761F0A44168D12C358AC4D120776907F81 |
SHA-512: | 3BE0466794E7BDDC8565758DBF5553E89ED0003271F07695F09283F242BB65C1978ED79A38D5E589A99F68C0130E1E4B52576D7CD655EE272EE104BE0378E72E |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/breadcrumb/toc.json |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18367 |
Entropy (8bit): | 7.7772261735974215 |
Encrypted: | false |
SSDEEP: | 384:4qqZYz7CAda2Qmd6VWWNg9h8XvdkRbdi2nki:1qZYz7Cma2hYNMh8XvdObdi2nX |
MD5: | 240C4CC15D9FD65405BB642AB81BE615 |
SHA1: | 5A66783FE5DD932082F40811AE0769526874BFD3 |
SHA-256: | 030272CE6BA1BECA700EC83FDED9DBDC89296FBDE0633A7F5943EF5831876C07 |
SHA-512: | 267FE31BC25944DD7B6071C2C2C271CCC188AE1F6A0D7E587DCF9198B81598DA6B058D1B413F228DF0CB37C8304329E808089388359651E81B5F3DEC566D0EE0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13339 |
Entropy (8bit): | 7.683569563478597 |
Encrypted: | false |
SSDEEP: | 192:zjSKAj04ndWb6OuzZjk6TsEaJS0/bJur2Gz4Imm3MhE4NfM:zutfW69XTspsG3G0TfhEQM |
MD5: | 512625CF8F40021445D74253DC7C28C0 |
SHA1: | F6B27CE0F7D4E48E34FDDCA8A96337F07CFFE730 |
SHA-256: | 1D4DCEE8511D5371FEC911660D6049782E12901C662B409A5C675772E9B87369 |
SHA-512: | AE02319D03884D758A86C286B6F593BDFFD067885D56D82EEB8215FDCB41637C7BB9109039E7FBC93AD246D030C368FB285B3161976ED485ABC5A8DF6DF9A38C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1432 |
Entropy (8bit): | 4.986131881931089 |
Encrypted: | false |
SSDEEP: | 24:TGAcSRrEV4YUmjiqIWD5bfD9yRSmkYR/stZLKvVqXRRlAfr6VXBAuU:Ti4IV4YUmjiqr9bfskAmZTXGfSXqh |
MD5: | 6B8763B76F400DC480450FD69072F215 |
SHA1: | 6932907906AFCF8EAFA22154D8478106521BC9EE |
SHA-256: | 3FB84D357F0C9A66100570EDD62A04D0574C45E8A5209A3E6870FF22AF839DFC |
SHA-512: | 8A07EBB806A0BA8EF54B463BD6AF37C77A10C1FA38A57128FD90FCB2C16DF71CE697D4FE65C623E5C6054C5715975831C36861D5574F59DF28836D9BC2B0BC22 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18367 |
Entropy (8bit): | 7.7772261735974215 |
Encrypted: | false |
SSDEEP: | 384:4qqZYz7CAda2Qmd6VWWNg9h8XvdkRbdi2nki:1qZYz7Cma2hYNMh8XvdObdi2nX |
MD5: | 240C4CC15D9FD65405BB642AB81BE615 |
SHA1: | 5A66783FE5DD932082F40811AE0769526874BFD3 |
SHA-256: | 030272CE6BA1BECA700EC83FDED9DBDC89296FBDE0633A7F5943EF5831876C07 |
SHA-512: | 267FE31BC25944DD7B6071C2C2C271CCC188AE1F6A0D7E587DCF9198B81598DA6B058D1B413F228DF0CB37C8304329E808089388359651E81B5F3DEC566D0EE0 |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/install/media/application-not-started/repair-tool-no-resolution.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1154 |
Entropy (8bit): | 4.59126408969148 |
Encrypted: | false |
SSDEEP: | 24:txFRuJpzYeGK+VS6ckNL2091JP/UcHc8oQJ1sUWMLc/jH6GbKqjHJIOHA:JsfcU6ckNL2091Z/U/YsUDM+GhS |
MD5: | 37258A983459AE1C2E4F1E551665F388 |
SHA1: | 603A4E9115E613CC827206CF792C62AEB606C941 |
SHA-256: | 8E34F3807B4BF495D8954E7229681DA8D0DD101DD6DDC2AD7F90CD2983802B44 |
SHA-512: | 184CB63EF510143B0AF013F506411C917D68BB63F2CFA47EA2A42688FD4F55F3B820AF94F87083C24F48AACEE6A692199E185FC5C5CFBED5D70790454EED7F5C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3130 |
Entropy (8bit): | 4.790069981348324 |
Encrypted: | false |
SSDEEP: | 48:YWuGl640ynAqgDJ9OJWuO6Z3Db8VgK/ni47ttbtlSlA37ERw7II77Aj5M1:Nv0ynAhD3CO5t5lNEYIOEjc |
MD5: | EBA6E81304F2F555E1D2EA3126A18A41 |
SHA1: | 61429C3FE837FD4DD68E7B26678F131F2E00070D |
SHA-256: | F309CCCE17B2B4706E7110F6C76F81761F0A44168D12C358AC4D120776907F81 |
SHA-512: | 3BE0466794E7BDDC8565758DBF5553E89ED0003271F07695F09283F242BB65C1978ED79A38D5E589A99F68C0130E1E4B52576D7CD655EE272EE104BE0378E72E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15427 |
Entropy (8bit): | 7.784472070227724 |
Encrypted: | false |
SSDEEP: | 384:CKKdvwj3SJMpKKKKKKKKikCyKwqHILyPGQV4ykihKKKKKKKCm:CKKdvMMgKKKKKKKKiqB3yPVXkihKKKKI |
MD5: | 3062488F9D119C0D79448BE06ED140D8 |
SHA1: | 8A148951C894FC9E968D3E46589A2E978267650E |
SHA-256: | C47A383DE6DD60149B37DD24825D42D83CB48BE0ED094E3FC3B228D0A7BB9332 |
SHA-512: | 00BBA6BCBFBF44B977129594A47F732809DCE7D4E2D22D050338E4EEA91FCC02A9B333C45EEB4C9024DF076CBDA0B46B621BF48309C0D037D19BBEAE0367F5ED |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 207935 |
Entropy (8bit): | 5.420780972514107 |
Encrypted: | false |
SSDEEP: | 3072:Wx2fZBMb0y0Xi13tL9+pjXDMe/m7GG3/lHNVliMTqwK:Wof3G0NSkNzMeO7z/l3lhTa |
MD5: | 3DE400B2682E30C3F33FA4B93116491F |
SHA1: | BC48B898DF43BA2178DE28F5A29D977B2204F846 |
SHA-256: | 84E9EAD32EFA16BE0D5B2407F799FC3DAE497BCB4A90758C0106C8D8F55003FE |
SHA-512: | D4004E4A62A81116D346B7A7F95FC67F97A258E82B3BDDBF4A9F28CEBB633E4A336A17057A765DA306AD9B1E40A99FE349D698B095A6F386B9CDF4A46457FC06 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 27868 |
Entropy (8bit): | 5.155680085584642 |
Encrypted: | false |
SSDEEP: | 768:63ZUfTvLg6jLjnjrjGjXMQjtzjMFzXY8v1gWj/rlOVqnACpK3o3hhl0OU2/8BlsX:BTvL7HBJv11pOVqlh382/rIN1Y |
MD5: | 0A0F2E1CCB8E5F7C38CB11B101A8941F |
SHA1: | 112F4B7CB3DEDB9D9744CAC000E05DC949E89891 |
SHA-256: | DBDB03D01BA044C4072BBC169C1E54D05A3D89623D2EBEAC28AC89ABDA3ABC2A |
SHA-512: | 9BD4E9C2415FB62E55D04DDEB9ECE04CB9AE2B8F8B93632A11A0AFD1CE6A632DF7D58DD571BF34C6E8E99107E80340CFAFF4BB4A8E18D05B5CAA7445DE55839C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 207935 |
Entropy (8bit): | 5.420780972514107 |
Encrypted: | false |
SSDEEP: | 3072:Wx2fZBMb0y0Xi13tL9+pjXDMe/m7GG3/lHNVliMTqwK:Wof3G0NSkNzMeO7z/l3lhTa |
MD5: | 3DE400B2682E30C3F33FA4B93116491F |
SHA1: | BC48B898DF43BA2178DE28F5A29D977B2204F846 |
SHA-256: | 84E9EAD32EFA16BE0D5B2407F799FC3DAE497BCB4A90758C0106C8D8F55003FE |
SHA-512: | D4004E4A62A81116D346B7A7F95FC67F97A258E82B3BDDBF4A9F28CEBB633E4A336A17057A765DA306AD9B1E40A99FE349D698B095A6F386B9CDF4A46457FC06 |
Malicious: | false |
URL: | https://js.monitor.azure.com/scripts/c/ms.jsll-4.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 27868 |
Entropy (8bit): | 5.155680085584642 |
Encrypted: | false |
SSDEEP: | 768:63ZUfTvLg6jLjnjrjGjXMQjtzjMFzXY8v1gWj/rlOVqnACpK3o3hhl0OU2/8BlsX:BTvL7HBJv11pOVqlh382/rIN1Y |
MD5: | 0A0F2E1CCB8E5F7C38CB11B101A8941F |
SHA1: | 112F4B7CB3DEDB9D9744CAC000E05DC949E89891 |
SHA-256: | DBDB03D01BA044C4072BBC169C1E54D05A3D89623D2EBEAC28AC89ABDA3ABC2A |
SHA-512: | 9BD4E9C2415FB62E55D04DDEB9ECE04CB9AE2B8F8B93632A11A0AFD1CE6A632DF7D58DD571BF34C6E8E99107E80340CFAFF4BB4A8E18D05B5CAA7445DE55839C |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/banners/index.json |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 15427 |
Entropy (8bit): | 7.784472070227724 |
Encrypted: | false |
SSDEEP: | 384:CKKdvwj3SJMpKKKKKKKKikCyKwqHILyPGQV4ykihKKKKKKKCm:CKKdvMMgKKKKKKKKiqB3yPVXkihKKKKI |
MD5: | 3062488F9D119C0D79448BE06ED140D8 |
SHA1: | 8A148951C894FC9E968D3E46589A2E978267650E |
SHA-256: | C47A383DE6DD60149B37DD24825D42D83CB48BE0ED094E3FC3B228D0A7BB9332 |
SHA-512: | 00BBA6BCBFBF44B977129594A47F732809DCE7D4E2D22D050338E4EEA91FCC02A9B333C45EEB4C9024DF076CBDA0B46B621BF48309C0D037D19BBEAE0367F5ED |
Malicious: | false |
URL: | https://learn.microsoft.com/en-us/dotnet/framework/install/media/application-not-started/repair-tool-recommended-changes.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1432 |
Entropy (8bit): | 4.986131881931089 |
Encrypted: | false |
SSDEEP: | 24:TGAcSRrEV4YUmjiqIWD5bfD9yRSmkYR/stZLKvVqXRRlAfr6VXBAuU:Ti4IV4YUmjiqr9bfskAmZTXGfSXqh |
MD5: | 6B8763B76F400DC480450FD69072F215 |
SHA1: | 6932907906AFCF8EAFA22154D8478106521BC9EE |
SHA-256: | 3FB84D357F0C9A66100570EDD62A04D0574C45E8A5209A3E6870FF22AF839DFC |
SHA-512: | 8A07EBB806A0BA8EF54B463BD6AF37C77A10C1FA38A57128FD90FCB2C16DF71CE697D4FE65C623E5C6054C5715975831C36861D5574F59DF28836D9BC2B0BC22 |
Malicious: | false |
URL: | https://learn.microsoft.com/static/assets/0.4.029026183/global/deprecation.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 464328 |
Entropy (8bit): | 5.0747157240281755 |
Encrypted: | false |
SSDEEP: | 6144:XegPrbKCerH5dyUJ6Yh6BFPDxZYX04GK7M4:1KCerXyUh |
MD5: | 875E7F3672FEC41DDB5A2386D2331531 |
SHA1: | 282979933E99BDE3A6342DC1EF93FBC51682F2C3 |
SHA-256: | F205B3CBA340ECB0B5D45E5DE6D385947CC4C21248707A90BFD5894E9B61F3C9 |
SHA-512: | 67A3C1D8FF089E01C20962D96968DE43F3E8D49B474C396F08827EE891C0315693634E663D3148D7441B501EA6939A7D84A80B1E855B7C2A8BCB17E0013AFAD4 |
Malicious: | false |
URL: | https://learn.microsoft.com/static/assets/0.4.029026183/styles/site-ltr.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 52717 |
Entropy (8bit): | 5.462668685745912 |
Encrypted: | false |
SSDEEP: | 1536:tjspYRrxlhd0fq3agV3IcgPPPI3r7DAQHCloIB3Tj7xHw:tjZLCtxQ |
MD5: | 413FCC759CC19821B61B6941808B29B5 |
SHA1: | 1AD23B8A202043539C20681B1B3E9F3BC5D55133 |
SHA-256: | DAF7759FEDD9AF6C4D7E374B0D056547AE7CB245EC24A1C4ACF02932F30DC536 |
SHA-512: | E9BF8A74FEF494990AAFD15A0F21E0398DC28B4939C8F9F8AA1F3FFBD18056C8D1AB282B081F5C56F0928C48E30E768F7E347929304B55547F9CA8C1AABD80B8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 52717 |
Entropy (8bit): | 5.462668685745912 |
Encrypted: | false |
SSDEEP: | 1536:tjspYRrxlhd0fq3agV3IcgPPPI3r7DAQHCloIB3Tj7xHw:tjZLCtxQ |
MD5: | 413FCC759CC19821B61B6941808B29B5 |
SHA1: | 1AD23B8A202043539C20681B1B3E9F3BC5D55133 |
SHA-256: | DAF7759FEDD9AF6C4D7E374B0D056547AE7CB245EC24A1C4ACF02932F30DC536 |
SHA-512: | E9BF8A74FEF494990AAFD15A0F21E0398DC28B4939C8F9F8AA1F3FFBD18056C8D1AB282B081F5C56F0928C48E30E768F7E347929304B55547F9CA8C1AABD80B8 |
Malicious: | false |
URL: | https://wcpstatic.microsoft.com/mscc/lib/v2/wcp-consent.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1173007 |
Entropy (8bit): | 5.503893944397598 |
Encrypted: | false |
SSDEEP: | 24576:VMga+4IVzOjS1Jho1WXQFjTEr39/jHXzT:VMcVzOjS1Jho1WXQar39/bXzT |
MD5: | 2E00D51C98DBB338E81054F240E1DEB2 |
SHA1: | D33BAC6B041064AE4330DCC2D958EBE4C28EBE58 |
SHA-256: | 300480069078B5892D2363A2B65E2DFBBF30FE5C80F83EDBFECF4610FD093862 |
SHA-512: | B6268D980CE9CB729C82DBA22F04FD592952B2A1AAB43079CA5330C68A86E72B0D232CE4070DB893A5054EE5C68325C92C9F1A33F868D61EBB35129E74FC7EF9 |
Malicious: | false |
URL: | https://learn.microsoft.com/static/third-party/MathJax/3.2.2/tex-mml-chtml.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | 3:HMB:k |
MD5: | 0B04EA412F8FC88B51398B1CBF38110E |
SHA1: | E073BCC5A03E7BBA2A16CF201A3CED1BE7533FBF |
SHA-256: | 7562254FF78FD854F0A8808E75A406F5C6058B57B71514481DAE490FC7B8F4C3 |
SHA-512: | 6D516068C3F3CBFC1500032E600BFF5542EE30C0EAC11A929EE002C707810BBF614A5586C2673EE959AFDF19C08F6EAEFA18193AD6CEDC839BDF249CF95E8079 |
Malicious: | false |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzQSEAkEurwx6c-nJBIFDb_mJfI=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1817143 |
Entropy (8bit): | 5.501007973622959 |
Encrypted: | false |
SSDEEP: | 24576:aLX8PHFluFxBSB1DkCXWjfz8gEPPXL/tie:auHFluFxBSB1DkCXWjfz7EPPXztH |
MD5: | F57E274AE8E8889C7516D3E53E3EB026 |
SHA1: | F8D21465C0C19051474BE6A4A681FA0B0D3FCC0C |
SHA-256: | 2A2198DDBDAEDD1E968C0A1A45F800765AAE703675E419E46F6E51E3E9729D01 |
SHA-512: | 9A9B42F70E09D821B799B92CB6AC981236FCF190F0A467CA7F7D382E3BCA1BC1D71673D37CD7426499D24DFBC0B7A6D10676C0E3FB2B0292249A5ABAB78F23F4 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 0.3228113519578857 |
TrID: |
|
File name: | TieLoader.exe |
File size: | 34'317'824 bytes |
MD5: | 25cb0b651e95894e6543855be5538b5f |
SHA1: | 5ee5585f34701029392a1f49b202e161f4310cef |
SHA256: | 4373ab5c151d15c97c4d8ec7f9bf9e36edc7a6169b2e2b5673bba49bd1113c87 |
SHA512: | 05390de5840b20704dca8b834779d0285fb27d9fb55804973f54bff4d1c397896a0bbcd9c0e1f609c3d8a1627633c800a1ce7f173ae71465a5e8f6f986696d58 |
SSDEEP: | 12288:IZX1D3e2JavPi/W1K9L+A3mYJyrFCbj1tLJndM/OOvL+fhg8u73cxvFaQk659a1H:iBh2GL+A3mauFcj1JJndMJb |
TLSH: | 92774A9C726072DFC867C472DEA82CA4FA51747B931F4253A027C6ADAA4D897CF150F2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...%.sg..............0...................... ....@.. .......................@............@................................ |
Icon Hash: | 0d0f0a1b132529d6 |
Entrypoint: | 0x4c000a |
Entrypoint Section: | .reloc |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6773E025 [Tue Dec 31 12:14:29 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | v4.0.30319 |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x90750 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xbc000 | 0x22a2 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xc0000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0xc2000 | 0x8 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x90000 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
bdE}&WF | 0x2000 | 0x8cdfc | 0x8ce00 | 2e57560307542085d377ff307cc50cf2 | False | 1.0003223436113575 | data | 7.99971824751899 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.text | 0x90000 | 0x2aaa8 | 0x2ac00 | 0449079c46c749b4568d60a6aebd1717 | False | 0.31661184210526316 | data | 4.6024653813837855 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xbc000 | 0x22a2 | 0x2400 | f66791220c1678307b3c136b4fdfd258 | False | 0.8394097222222222 | data | 7.381545639335723 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xc0000 | 0xc | 0x200 | 5ba34c2ca37b35a0de4f3409909cbf7a | False | 0.041015625 | data | 0.07225252269057866 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
0xc2000 | 0x10 | 0x200 | 17f9b25275a4d7c97677dd9cc8f5a01d | False | 0.044921875 | data | 0.12227588125913882 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xbc138 | 0x1be6 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9578549425931112 | ||
RT_GROUP_ICON | 0xbdd20 | 0x14 | data | 1.05 | ||
RT_VERSION | 0xbdd34 | 0x384 | data | 0.46444444444444444 | ||
RT_MANIFEST | 0xbe0b8 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 31, 2024 17:39:15.525878906 CET | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:15.525891066 CET | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:15.650897026 CET | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:16.275885105 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Dec 31, 2024 17:39:20.306864977 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:20.666408062 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:21.088475943 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Dec 31, 2024 17:39:21.416414022 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:22.916450977 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:25.135174990 CET | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:25.135200977 CET | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:25.260169983 CET | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:25.900799990 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:27.691226959 CET | 443 | 49700 | 104.98.116.138 | 192.168.2.7 |
Dec 31, 2024 17:39:27.691550970 CET | 49700 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:30.700993061 CET | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Dec 31, 2024 17:39:31.853362083 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:33.430532932 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:33.430581093 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:33.430666924 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:33.431447983 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:33.431463957 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:33.847620964 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:33.847651005 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:33.847791910 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:33.848073006 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:33.848083019 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.083386898 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:34.087272882 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:34.087285995 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:34.088376999 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:34.088445902 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:34.090348005 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:34.090559959 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:34.137820959 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:34.137831926 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:34.183293104 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:34.498261929 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.498585939 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.498605013 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.500391006 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.500448942 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.501440048 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.501519918 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.501650095 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.501657963 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.547457933 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.645149946 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.645325899 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.645344973 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.645354033 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.645365953 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.645380974 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.645411015 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.645426035 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.645426035 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.645457983 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.723155022 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.723181963 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.723228931 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.723248959 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.723262072 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.723285913 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.733896971 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.733918905 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.733961105 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.733967066 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.734023094 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.810642004 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.810672998 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.810755968 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.810794115 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.810837984 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.811695099 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.811712980 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.811762094 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.811767101 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.811791897 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.811816931 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.813270092 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.813287973 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.813340902 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.813345909 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.813390970 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.813407898 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.823395014 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.823419094 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.823494911 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.823501110 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.823546886 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.899061918 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.899092913 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.899374962 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.899394989 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.899491072 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.899512053 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.899519920 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.899528980 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.899549961 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.899626970 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.900368929 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.900384903 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.900480032 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.900485992 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.900576115 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.901350975 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.901370049 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.901566029 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.901571989 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.901995897 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.902268887 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.902285099 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.902468920 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.902475119 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.902570963 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.903134108 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.903165102 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.903219938 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:34.903249979 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.903249979 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.903359890 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.905493975 CET | 49753 | 443 | 192.168.2.7 | 13.107.246.60 |
Dec 31, 2024 17:39:34.905508995 CET | 443 | 49753 | 13.107.246.60 | 192.168.2.7 |
Dec 31, 2024 17:39:37.335274935 CET | 49700 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:37.335850000 CET | 49800 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:37.335876942 CET | 443 | 49800 | 104.98.116.138 | 192.168.2.7 |
Dec 31, 2024 17:39:37.335956097 CET | 49800 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:37.340198040 CET | 443 | 49700 | 104.98.116.138 | 192.168.2.7 |
Dec 31, 2024 17:39:37.362822056 CET | 49800 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:39:37.362865925 CET | 443 | 49800 | 104.98.116.138 | 192.168.2.7 |
Dec 31, 2024 17:39:43.832148075 CET | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Dec 31, 2024 17:39:43.980740070 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:43.980823994 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:39:43.981682062 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:44.375868082 CET | 49742 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:39:44.375899076 CET | 443 | 49742 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:20.208767891 CET | 443 | 49800 | 104.98.116.138 | 192.168.2.7 |
Dec 31, 2024 17:40:20.208861113 CET | 49800 | 443 | 192.168.2.7 | 104.98.116.138 |
Dec 31, 2024 17:40:32.209624052 CET | 51841 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:40:32.214427948 CET | 53 | 51841 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:32.214513063 CET | 51841 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:40:32.219429016 CET | 53 | 51841 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:32.676528931 CET | 51841 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:40:32.681550980 CET | 53 | 51841 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:32.681627035 CET | 51841 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:40:33.246041059 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:33.246087074 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:33.246155977 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:33.246417046 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:33.246437073 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:33.922849894 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:33.923962116 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:33.923985004 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:33.924329996 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:33.925462008 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:33.925537109 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:33.978873014 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:43.820791006 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:43.820885897 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Dec 31, 2024 17:40:43.820933104 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:46.579236984 CET | 51843 | 443 | 192.168.2.7 | 142.250.185.68 |
Dec 31, 2024 17:40:46.579267025 CET | 443 | 51843 | 142.250.185.68 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 31, 2024 17:39:26.730252981 CET | 123 | 123 | 192.168.2.7 | 20.101.57.9 |
Dec 31, 2024 17:39:27.286992073 CET | 123 | 123 | 20.101.57.9 | 192.168.2.7 |
Dec 31, 2024 17:39:28.827171087 CET | 53 | 49801 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:39:29.090790033 CET | 53 | 64996 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:39:30.085633039 CET | 53 | 51469 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:39:32.557141066 CET | 56276 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:32.557955027 CET | 63133 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:33.251214027 CET | 64313 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:33.251446009 CET | 59852 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:33.257894993 CET | 53 | 64313 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:39:33.257944107 CET | 53 | 59852 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:39:33.830941916 CET | 49318 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:33.831199884 CET | 59262 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:37.775638103 CET | 53 | 62797 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:39:38.358246088 CET | 63225 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:38.358700037 CET | 58258 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 31, 2024 17:39:47.147932053 CET | 53 | 54230 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:06.129533052 CET | 53 | 62589 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:20.783349991 CET | 138 | 138 | 192.168.2.7 | 192.168.2.255 |
Dec 31, 2024 17:40:28.740684986 CET | 53 | 49210 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:28.785593033 CET | 53 | 57877 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:32.209171057 CET | 53 | 58187 | 1.1.1.1 | 192.168.2.7 |
Dec 31, 2024 17:40:58.895190954 CET | 53 | 63954 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Dec 31, 2024 17:39:32.571604967 CET | 192.168.2.7 | 1.1.1.1 | c2b7 | (Port unreachable) | Destination Unreachable |
Dec 31, 2024 17:39:33.863663912 CET | 192.168.2.7 | 1.1.1.1 | c2c4 | (Port unreachable) | Destination Unreachable |
Dec 31, 2024 17:39:34.601425886 CET | 192.168.2.7 | 1.1.1.1 | c2e6 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 31, 2024 17:39:32.557141066 CET | 192.168.2.7 | 1.1.1.1 | 0xee51 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:39:32.557955027 CET | 192.168.2.7 | 1.1.1.1 | 0xad7b | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 31, 2024 17:39:33.251214027 CET | 192.168.2.7 | 1.1.1.1 | 0xa907 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:39:33.251446009 CET | 192.168.2.7 | 1.1.1.1 | 0x50e3 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 31, 2024 17:39:33.830941916 CET | 192.168.2.7 | 1.1.1.1 | 0xabe9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:39:33.831199884 CET | 192.168.2.7 | 1.1.1.1 | 0x9f9e | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 31, 2024 17:39:38.358246088 CET | 192.168.2.7 | 1.1.1.1 | 0xd068 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 31, 2024 17:39:38.358700037 CET | 192.168.2.7 | 1.1.1.1 | 0x627 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 31, 2024 17:39:32.559598923 CET | 1.1.1.1 | 192.168.2.7 | 0x1187 | No error (0) | firstparty-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.559598923 CET | 1.1.1.1 | 192.168.2.7 | 0x1187 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.559598923 CET | 1.1.1.1 | 192.168.2.7 | 0x1187 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.563792944 CET | 1.1.1.1 | 192.168.2.7 | 0xee51 | No error (0) | aijscdn2-bwfdfxezdubebtb0.z01.azurefd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.563792944 CET | 1.1.1.1 | 192.168.2.7 | 0xee51 | No error (0) | star-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.563792944 CET | 1.1.1.1 | 192.168.2.7 | 0xee51 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.563792944 CET | 1.1.1.1 | 192.168.2.7 | 0xee51 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.565368891 CET | 1.1.1.1 | 192.168.2.7 | 0xad7b | No error (0) | aijscdn2-bwfdfxezdubebtb0.z01.azurefd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.565368891 CET | 1.1.1.1 | 192.168.2.7 | 0xad7b | No error (0) | star-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:32.571526051 CET | 1.1.1.1 | 192.168.2.7 | 0x161f | No error (0) | firstparty-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.257894993 CET | 1.1.1.1 | 192.168.2.7 | 0xa907 | No error (0) | 142.250.185.68 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.257944107 CET | 1.1.1.1 | 192.168.2.7 | 0x50e3 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 31, 2024 17:39:33.688363075 CET | 1.1.1.1 | 192.168.2.7 | 0xcc95 | No error (0) | firstparty-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.688363075 CET | 1.1.1.1 | 192.168.2.7 | 0xcc95 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.688363075 CET | 1.1.1.1 | 192.168.2.7 | 0xcc95 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.689114094 CET | 1.1.1.1 | 192.168.2.7 | 0xdb03 | No error (0) | firstparty-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.838464975 CET | 1.1.1.1 | 192.168.2.7 | 0xabe9 | No error (0) | aijscdn2-bwfdfxezdubebtb0.z01.azurefd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.838464975 CET | 1.1.1.1 | 192.168.2.7 | 0xabe9 | No error (0) | star-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.838464975 CET | 1.1.1.1 | 192.168.2.7 | 0xabe9 | No error (0) | s-part-0032.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.838464975 CET | 1.1.1.1 | 192.168.2.7 | 0xabe9 | No error (0) | 13.107.246.60 | A (IP address) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.863509893 CET | 1.1.1.1 | 192.168.2.7 | 0x9f9e | No error (0) | aijscdn2-bwfdfxezdubebtb0.z01.azurefd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:33.863509893 CET | 1.1.1.1 | 192.168.2.7 | 0x9f9e | No error (0) | star-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:38.366969109 CET | 1.1.1.1 | 192.168.2.7 | 0xd068 | No error (0) | mdec.nelreports.net.akamaized.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:38.370992899 CET | 1.1.1.1 | 192.168.2.7 | 0x627 | No error (0) | mdec.nelreports.net.akamaized.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:39.358561993 CET | 1.1.1.1 | 192.168.2.7 | 0x5165 | No error (0) | c-msn-com-nsatc.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:39.362086058 CET | 1.1.1.1 | 192.168.2.7 | 0xd459 | No error (0) | c-msn-com-nsatc.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:42.326071024 CET | 1.1.1.1 | 192.168.2.7 | 0xb7c8 | No error (0) | c-msn-com-nsatc.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 31, 2024 17:39:42.326231956 CET | 1.1.1.1 | 192.168.2.7 | 0xe8d | No error (0) | c-msn-com-nsatc.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49753 | 13.107.246.60 | 443 | 7304 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-31 16:39:34 UTC | 370 | OUT | |
2024-12-31 16:39:34 UTC | 896 | IN | |
2024-12-31 16:39:34 UTC | 15488 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN | |
2024-12-31 16:39:34 UTC | 16384 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 11:39:19 |
Start date: | 31/12/2024 |
Path: | C:\Users\user\Desktop\TieLoader.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x820000 |
File size: | 34'317'824 bytes |
MD5 hash: | 25CB0B651E95894E6543855BE5538B5F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:39:19 |
Start date: | 31/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 11:39:25 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 11:39:27 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 13 |
Start time: | 11:39:31 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 11:39:31 |
Start date: | 31/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |