Edit tour

Windows Analysis Report
Filtering Rules

Overview

General Information

Sample name:Filtering Rules
Analysis ID:1586205
MD5:a97ea939d1b6d363d1a41c4ab55b9ecb
SHA1:3669e6477eddf2521e874269769b69b042620332
SHA256:97115a369f33b66a7ffcfb3d67c935c1e7a24fc723bb8380ad01971c447cfa9f
Errors
  • No process behavior to analyse as no analysis process or sample was found
  • Corrupt sample or wrongly selected analyzer. Details: invalid parameter

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://gamescarousel.com/Avira URL Cloud: Label: malware
Source: http://www.onclickmega.com/jump/next.php?Avira URL Cloud: Label: malware
Source: https://albionsoftwares.com/Avira URL Cloud: Label: malware
Source: http://pityhostngco2.xyz/Avira URL Cloud: Label: malware
Source: https://fast-redirecting.com/Avira URL Cloud: Label: malware
Source: Filtering RulesString found in binary or memory: (a[href^="http://www.youtube.com/cthru?"] equals www.youtube.com (Youtube)
Source: Filtering RulesString found in binary or memory: )a[href^="https://www.youtube.com/cthru?"] equals www.youtube.com (Youtube)
Source: Filtering RulesString found in binary or memory: www.facebook.com/ajax/ads/ equals www.facebook.com (Facebook)
Source: Filtering RulesString found in binary or memory: www.facebook.com0 equals www.facebook.com (Facebook)
Source: Filtering RulesString found in binary or memory: www.youtube.com/get_midroll_ equals www.youtube.com (Youtube)
Source: Filtering RulesString found in binary or memory: http://1phads.com/
Source: Filtering RulesString found in binary or memory: http://360ads.go2cloud.org/
Source: Filtering RulesString found in binary or memory: http://ad-apac.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://ad-emea.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://ad.au.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://ad.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://ad.yieldmanager.com/
Source: Filtering RulesString found in binary or memory: http://adclick.g.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://adf.ly/?id=
Source: Filtering RulesString found in binary or memory: http://adlev.neodatagroup.com/
Source: Filtering RulesString found in binary or memory: http://admrotate.iplayer.org/
Source: Filtering RulesString found in binary or memory: http://adprovider.adlure.net/
Source: Filtering RulesString found in binary or memory: http://adrunnr.com/
Source: Filtering RulesString found in binary or memory: http://ads.betfair.com/redirect.aspx?
Source: Filtering RulesString found in binary or memory: http://ads.expekt.com/affiliates/
Source: Filtering RulesString found in binary or memory: http://ads.sprintrade.com/
Source: Filtering RulesString found in binary or memory: http://ads2.williamhill.com/redirect.aspx?
Source: Filtering RulesString found in binary or memory: http://adserver.adreactor.com/
Source: Filtering RulesString found in binary or memory: http://adserver.adtech.de/
Source: Filtering RulesString found in binary or memory: http://adserver.adtechus.com/
Source: Filtering RulesString found in binary or memory: http://adserving.unibet.com/
Source: Filtering RulesString found in binary or memory: http://adsrv.keycaptcha.com
Source: Filtering RulesString found in binary or memory: http://adtrack123.pl/
Source: Filtering RulesString found in binary or memory: http://adtrackone.eu/
Source: Filtering RulesString found in binary or memory: http://adultfriendfinder.com/p/register.cgi?pid=
Source: Filtering RulesString found in binary or memory: http://adultgames.xxx/
Source: Filtering RulesString found in binary or memory: http://advertisesimple.info/
Source: Filtering RulesString found in binary or memory: http://aff.ironsocket.com/
Source: Filtering RulesString found in binary or memory: http://affiliate.coral.co.uk/processing/
Source: Filtering RulesString found in binary or memory: http://affiliate.glbtracker.com/
Source: Filtering RulesString found in binary or memory: http://affiliates.lifeselector.com/
Source: Filtering RulesString found in binary or memory: http://affiliates.pinnaclesports.com/processing/
Source: Filtering RulesString found in binary or memory: http://affiliates.score-affiliates.com/
Source: Filtering RulesString found in binary or memory: http://affiliates.thrixxx.com/
Source: Filtering RulesString found in binary or memory: http://aflrm.com/
Source: Filtering RulesString found in binary or memory: http://allaptair.club/
Source: Filtering RulesString found in binary or memory: http://amzn.to/
Source: Filtering RulesString found in binary or memory: http://anonymous-net.com/
Source: Filtering RulesString found in binary or memory: http://api.content.ad/
Source: Filtering RulesString found in binary or memory: http://at.atwola.com/
Source: Filtering RulesString found in binary or memory: http://axdsz.pro/
Source: Filtering RulesString found in binary or memory: http://azmobilestore.co/
Source: Filtering RulesString found in binary or memory: http://banners.victor.com/processing/
Source: Filtering RulesString found in binary or memory: http://bc.vc/?r=
Source: Filtering RulesString found in binary or memory: http://bcntrack.com/
Source: Filtering RulesString found in binary or memory: http://bcp.crwdcntrl.net/
Source: Filtering RulesString found in binary or memory: http://bestorican.com/
Source: Filtering RulesString found in binary or memory: http://betahit.click/
Source: Filtering RulesString found in binary or memory: http://bluehost.com/track/
Source: Filtering RulesString found in binary or memory: http://bodelen.com/
Source: Filtering RulesString found in binary or memory: http://bs.serving-sys.com/
Source: Filtering RulesString found in binary or memory: http://buysellads.com/
Source: Filtering RulesString found in binary or memory: http://c.actiondesk.com/
Source: Filtering RulesString found in binary or memory: http://c.jumia.io/
Source: Filtering RulesString found in binary or memory: http://c.ketads.com/
Source: Filtering RulesString found in binary or memory: http://c43a3cd8f99413891.com/
Source: Filtering RulesString found in binary or memory: http://campaign.bharatmatrimony.com/cbstrack/
Source: Filtering RulesString found in binary or memory: http://campaign.bharatmatrimony.com/track/
Source: Filtering RulesString found in binary or memory: http://campeeks.com/
Source: Filtering RulesString found in binary or memory: http://casino-x.com/?partner
Source: Filtering RulesString found in binary or memory: http://cdn.adsrvmedia.net/
Source: Filtering RulesString found in binary or memory: http://cdn.adstract.com/
Source: Filtering RulesString found in binary or memory: http://cdn3.adexprts.com/
Source: Filtering RulesString found in binary or memory: http://chaturbate.com/affiliates/
Source: Filtering RulesString found in binary or memory: http://click.payserve.com/
Source: Filtering RulesString found in binary or memory: http://click.plista.com/pets
Source: Filtering RulesString found in binary or memory: http://clickandjoinyourgirl.com/
Source: Filtering RulesString found in binary or memory: http://clicks.binarypromos.com/
Source: Filtering RulesString found in binary or memory: http://clickserv.sitescout.com/
Source: Filtering RulesString found in binary or memory: http://clkmon.com/adServe/
Source: Filtering RulesString found in binary or memory: http://codec.codecm.com/
Source: Filtering RulesString found in binary or memory: http://cpaway.afftrack.com/
Source: Filtering RulesString found in binary or memory: http://cwcams.com/landing/click/
Source: Filtering RulesString found in binary or memory: http://czotra-32.com/
Source: Filtering RulesString found in binary or memory: http://d2.zedo.com/
Source: Filtering RulesString found in binary or memory: http://databass.info/
Source: Filtering RulesString found in binary or memory: http://deloplen.com/
Source: Filtering RulesString found in binary or memory: http://dftrck.com/
Source: Filtering RulesString found in binary or memory: http://down1oads.com/
Source: Filtering RulesString found in binary or memory: http://download-performance.com/
Source: Filtering RulesString found in binary or memory: http://dwn.pushtraffic.net/
Source: Filtering RulesString found in binary or memory: http://earandmarketing.com/
Source: Filtering RulesString found in binary or memory: http://eclkmpsa.com/
Source: Filtering RulesString found in binary or memory: http://elitefuckbook.com/
Source: Filtering RulesString found in binary or memory: http://engine.newsmaxfeednetwork.com/
Source: Filtering RulesString found in binary or memory: http://enter.anabolic.com/track/
Source: Filtering RulesString found in binary or memory: http://espn.zlbu.net/
Source: Filtering RulesString found in binary or memory: http://ethfw0370q.com/
Source: Filtering RulesString found in binary or memory: http://farm.plista.com/pets
Source: Filtering RulesString found in binary or memory: http://feedads.g.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://ffxitrack.com/
Source: Filtering RulesString found in binary or memory: http://fileboom.me/pr/
Source: Filtering RulesString found in binary or memory: http://finaljuyu.com/
Source: Filtering RulesString found in binary or memory: http://findersocket.com/
Source: Filtering RulesString found in binary or memory: http://freesoftwarelive.com/
Source: Filtering RulesString found in binary or memory: http://fsoft4down.com/
Source: Filtering RulesString found in binary or memory: http://fusionads.net
Source: Filtering RulesString found in binary or memory: http://g1.v.fwmrm.net/ad/
Source: Filtering RulesString found in binary or memory: http://galleries.securewebsiteaccess.com/
Source: Filtering RulesString found in binary or memory: http://globsads.com/
Source: Filtering RulesString found in binary or memory: http://go.247traffic.com/
Source: Filtering RulesString found in binary or memory: http://go.ad2up.com/
Source: Filtering RulesString found in binary or memory: http://go.cm-trk2.com/
Source: Filtering RulesString found in binary or memory: http://go.fpmarkets.com/
Source: Filtering RulesString found in binary or memory: http://go.mobisla.com/
Source: Filtering RulesString found in binary or memory: http://go.oclaserver.com/
Source: Filtering RulesString found in binary or memory: http://go.seomojo.com/tracking202/
Source: Filtering RulesString found in binary or memory: http://go.xtbaffiliates.com/
Source: Filtering RulesString found in binary or memory: http://goldmoney.com/?gmrefcode=
Source: Filtering RulesString found in binary or memory: http://googleads.g.doubleclick.net/pcs/click
Source: Filtering RulesString found in binary or memory: http://greensmoke.com/
Source: Filtering RulesString found in binary or memory: http://guideways.info/
Source: Filtering RulesString found in binary or memory: http://hd-plugins.com/download/
Source: Filtering RulesString found in binary or memory: http://homemoviestube.com/
Source: Filtering RulesString found in binary or memory: http://hotcandyland.com/partner/
Source: Filtering RulesString found in binary or memory: http://hpn.houzz.com/
Source: Filtering RulesString found in binary or memory: http://hyperlinksecure.com/go/
Source: Filtering RulesString found in binary or memory: http://igromir.info/
Source: Filtering RulesString found in binary or memory: http://imads.integral-marketing.com/
Source: Filtering RulesString found in binary or memory: http://install.securewebsiteaccess.com/
Source: Filtering RulesString found in binary or memory: http://intent.bingads.com/
Source: Filtering RulesString found in binary or memory: http://istri.it/?
Source: Filtering RulesString found in binary or memory: http://join.hardcoreshemalevideo.com/
Source: Filtering RulesString found in binary or memory: http://join.michelle-austin.com/
Source: Filtering RulesString found in binary or memory: http://join.rodneymoore.com/
Source: Filtering RulesString found in binary or memory: http://join.shemale.xxx/
Source: Filtering RulesString found in binary or memory: http://join.shemalepornstar.com/
Source: Filtering RulesString found in binary or memory: http://join.shemalesfromhell.com/
Source: Filtering RulesString found in binary or memory: http://join.trannies-fuck.com/
Source: Filtering RulesString found in binary or memory: http://join.ts-dominopresley.com/
Source: Filtering RulesString found in binary or memory: http://join3.bannedsextapes.com/track/
Source: Filtering RulesString found in binary or memory: http://k2s.cc/code/
Source: Filtering RulesString found in binary or memory: http://k2s.cc/pr/
Source: Filtering RulesString found in binary or memory: http://keep2share.cc/pr/
Source: Filtering RulesString found in binary or memory: http://landingpagegenius.com/
Source: Filtering RulesString found in binary or memory: http://latestdownloads.net/download.php?
Source: Filtering RulesString found in binary or memory: http://linksnappy.com/?ref=
Source: Filtering RulesString found in binary or memory: http://liversely.com/
Source: Filtering RulesString found in binary or memory: http://liversely.net/
Source: Filtering RulesString found in binary or memory: http://look.djfiln.com/
Source: Filtering RulesString found in binary or memory: http://lp.ezdownloadpro.info/
Source: Filtering RulesString found in binary or memory: http://lp.ncdownloader.com/
Source: Filtering RulesString found in binary or memory: http://marketgid.com
Source: Filtering RulesString found in binary or memory: http://media.paddypower.com/redirect.aspx?
Source: Filtering RulesString found in binary or memory: http://mgid.com/
Source: Filtering RulesString found in binary or memory: http://mmo123.co/
Source: Filtering RulesString found in binary or memory: http://mob1ledev1ces.com/
Source: Filtering RulesString found in binary or memory: http://n.admagnet.net/
Source: Filtering RulesString found in binary or memory: http://onclickads.net/
Source: Filtering RulesString found in binary or memory: http://online.ladbrokes.com/promoRedirect?
Source: Filtering RulesString found in binary or memory: http://pan.adraccoon.com?
Source: Filtering RulesString found in binary or memory: http://papi.mynativeplatform.com:80/pub2/
Source: Filtering RulesString found in binary or memory: http://partners.etoro.com/
Source: Filtering RulesString found in binary or memory: http://pityhostngco2.xyz/
Source: Filtering RulesString found in binary or memory: http://play4k.co/
Source: Filtering RulesString found in binary or memory: http://pokershibes.com/index.php?ref=
Source: Filtering RulesString found in binary or memory: http://promos.bwin.com/
Source: Filtering RulesString found in binary or memory: http://pubads.g.doubleclick.net/
Source: Filtering RulesString found in binary or memory: http://pwrads.net/
Source: Filtering RulesString found in binary or memory: http://reallygoodlink.extremefreegames.com/
Source: Filtering RulesString found in binary or memory: http://reallygoodlink.freehookupaffair.com/
Source: Filtering RulesString found in binary or memory: http://record.betsafe.com/
Source: Filtering RulesString found in binary or memory: http://record.sportsbetaffiliates.com.au/
Source: Filtering RulesString found in binary or memory: http://refer.webhostingbuzz.com/
Source: Filtering RulesString found in binary or memory: http://refpa.top/
Source: Filtering RulesString found in binary or memory: http://refpaano.host/
Source: Filtering RulesString found in binary or memory: http://rs-stripe.wsj.com/stripe/redirect
Source: Filtering RulesString found in binary or memory: http://s5prou7ulr.com/
Source: Filtering RulesString found in binary or memory: http://s9kkremkr0.com/
Source: Filtering RulesString found in binary or memory: http://searchtabnew.com/
Source: Filtering RulesString found in binary or memory: http://secure.cbdpure.com/aff/
Source: Filtering RulesString found in binary or memory: http://secure.hostgator.com/~affiliat/
Source: Filtering RulesString found in binary or memory: http://secure.signup-page.com/
Source: Filtering RulesString found in binary or memory: http://secure.vivid.com/track/
Source: Filtering RulesString found in binary or memory: http://see-work.info/
Source: Filtering RulesString found in binary or memory: http://see.kmisln.com/
Source: Filtering RulesString found in binary or memory: http://semi-cod.com/clicks/
Source: Filtering RulesString found in binary or memory: http://serve.williamhill.com/promoRedirect?
Source: Filtering RulesString found in binary or memory: http://server.cpmstar.com/click.aspx?poolid=
Source: Filtering RulesString found in binary or memory: http://servicegetbook.net/
Source: Filtering RulesString found in binary or memory: http://sharesuper.info/
Source: Filtering RulesString found in binary or memory: http://spygasm.com/track?
Source: Filtering RulesString found in binary or memory: http://srvpub.com/
Source: Filtering RulesString found in binary or memory: http://stateresolver.link/
Source: Filtering RulesString found in binary or memory: http://static.fleshlight.com/images/banners/
Source: Filtering RulesString found in binary or memory: http://syndication.exoclick.com/
Source: Filtering RulesString found in binary or memory: http://t.wowtrk.com/
Source: Filtering RulesString found in binary or memory: http://tc.tradetracker.net/
Source: Filtering RulesString found in binary or memory: http://tezfiles.com/pr/
Source: Filtering RulesString found in binary or memory: http://tour.mrskin.com/
Source: Filtering RulesString found in binary or memory: http://track.afcpatrk.com/
Source: Filtering RulesString found in binary or memory: http://track.trkvluum.com/
Source: Filtering RulesString found in binary or memory: http://tracking.deltamediallc.com/
Source: Filtering RulesString found in binary or memory: http://traffic.tc-clicks.com/
Source: Filtering RulesString found in binary or memory: http://trafficare.net/
Source: Filtering RulesString found in binary or memory: http://trk.mdrtrck.com/
Source: Filtering RulesString found in binary or memory: http://ucam.xxx/?utm_
Source: Filtering RulesString found in binary or memory: http://ul.to/ref/
Source: Filtering RulesString found in binary or memory: http://uploaded.net/ref/
Source: Filtering RulesString found in binary or memory: http://us.marketgid.com
Source: Filtering RulesString found in binary or memory: http://vinfdv6b4j.com/
Source: Filtering RulesString found in binary or memory: http://vo2.qrlsx.com/
Source: Filtering RulesString found in binary or memory: http://wct.link/
Source: Filtering RulesString found in binary or memory: http://web.adblade.com/
Source: Filtering RulesString found in binary or memory: http://webgirlz.online/landing/
Source: Filtering RulesString found in binary or memory: http://websitedhoome.com/
Source: Filtering RulesString found in binary or memory: http://webtrackerplus.com/
Source: Filtering RulesString found in binary or memory: http://wgpartner.com/
Source: Filtering RulesString found in binary or memory: http://wopertific.info/
Source: Filtering RulesString found in binary or memory: http://www.123-reg.co.uk/affiliate2.cgi
Source: Filtering RulesString found in binary or memory: http://www.1clickdownloader.com/
Source: Filtering RulesString found in binary or memory: http://www.FriendlyDuck.com/
Source: Filtering RulesString found in binary or memory: http://www.TwinPlan.com/AF_
Source: Filtering RulesString found in binary or memory: http://www.adbrite.com/mb/commerce/purchase_form.php?
Source: Filtering RulesString found in binary or memory: http://www.adskeeper.co.uk/
Source: Filtering RulesString found in binary or memory: http://www.adultdvdempire.com/?partner_id=
Source: Filtering RulesString found in binary or memory: http://www.adultempire.com/unlimited/promo?
Source: Filtering RulesString found in binary or memory: http://www.advcashpro.com/aff/
Source: Filtering RulesString found in binary or memory: http://www.adxpansion.com
Source: Filtering RulesString found in binary or memory: http://www.affiliates1128.com/processing/
Source: Filtering RulesString found in binary or memory: http://www.afgr2.com/
Source: Filtering RulesString found in binary or memory: http://www.afgr3.com/
Source: Filtering RulesString found in binary or memory: http://www.amazon.co.uk/exec/obidos/external-search?
Source: Filtering RulesString found in binary or memory: http://www.babylon.com/welcome/index?affID
Source: Filtering RulesString found in binary or memory: http://www.badoink.com/go.php?
Source: Filtering RulesString found in binary or memory: http://www.bet365.com/
Source: Filtering RulesString found in binary or memory: http://www.bitlord.me/share/
Source: Filtering RulesString found in binary or memory: http://www.bluehost.com/track/
Source: Filtering RulesString found in binary or memory: http://www.cdjapan.co.jp/aff/click.cgi/
Source: Filtering RulesString found in binary or memory: http://www.clkads.com/adServe/
Source: Filtering RulesString found in binary or memory: http://www.coiwqe.site/
Source: Filtering RulesString found in binary or memory: http://www.dealcent.com/register.php?affid=
Source: Filtering RulesString found in binary or memory: http://www.dl-provider.com/search/
Source: Filtering RulesString found in binary or memory: http://www.down1oads.com/
Source: Filtering RulesString found in binary or memory: http://www.download-provider.org/
Source: Filtering RulesString found in binary or memory: http://www.downloadplayer1.com/
Source: Filtering RulesString found in binary or memory: http://www.downloadthesefiles.com/
Source: Filtering RulesString found in binary or memory: http://www.downloadweb.org/
Source: Filtering RulesString found in binary or memory: http://www.easydownloadnow.com/
Source: Filtering RulesString found in binary or memory: http://www.fbooksluts.com/
Source: Filtering RulesString found in binary or memory: http://www.firstclass-download.com/
Source: Filtering RulesString found in binary or memory: http://www.firstload.com/affiliate/
Source: Filtering RulesString found in binary or memory: http://www.firstload.de/affiliate/
Source: Filtering RulesString found in binary or memory: http://www.flashx.tv/downloadthis
Source: Filtering RulesString found in binary or memory: http://www.fleshlight.com/
Source: Filtering RulesString found in binary or memory: http://www.fonts.com/BannerScript/
Source: Filtering RulesString found in binary or memory: http://www.fpcTraffic2.com/blind/in.cgi?
Source: Filtering RulesString found in binary or memory: http://www.freefilesdownloader.com/
Source: Filtering RulesString found in binary or memory: http://www.friendlyadvertisements.com/
Source: Filtering RulesString found in binary or memory: http://www.friendlyduck.com/AF_
Source: Filtering RulesString found in binary or memory: http://www.friendlyquacks.com/
Source: Filtering RulesString found in binary or memory: http://www.gamebookers.com/cgi-bin/intro.cgi?
Source: Filtering RulesString found in binary or memory: http://www.getyourguide.com/?partner_id=
Source: Filtering RulesString found in binary or memory: http://www.gfrevenge.com/landing/
Source: Filtering RulesString found in binary or memory: http://www.graboid.com/affiliates/
Source: Filtering RulesString found in binary or memory: http://www.greenmangaming.com/?tap_a=
Source: Filtering RulesString found in binary or memory: http://www.hibids10.com/
Source: Filtering RulesString found in binary or memory: http://www.hitcpm.com/
Source: Filtering RulesString found in binary or memory: http://www.idownloadplay.com/
Source: Filtering RulesString found in binary or memory: http://www.linkbucks.com/referral/
Source: Filtering RulesString found in binary or memory: http://www.liutilities.com/
Source: Filtering RulesString found in binary or memory: http://www.liversely.net/
Source: Filtering RulesString found in binary or memory: http://www.menaon.com/installs/
Source: Filtering RulesString found in binary or memory: http://www.mobileandinternetadvertising.com/
Source: Filtering RulesString found in binary or memory: http://www.mrskin.com/tour
Source: Filtering RulesString found in binary or memory: http://www.my-dirty-hobby.com/?sub=
Source: Filtering RulesString found in binary or memory: http://www.myfreepaysite.com/sfw.php?aid
Source: Filtering RulesString found in binary or memory: http://www.myfreepaysite.com/sfw_int.php?aid
Source: Filtering RulesString found in binary or memory: http://www.mysuperpharm.com/
Source: Filtering RulesString found in binary or memory: http://www.on2url.com/app/adtrack.asp
Source: Filtering RulesString found in binary or memory: http://www.onclickmega.com/jump/next.php?
Source: Filtering RulesString found in binary or memory: http://www.onwebcam.com/random?t_link=
Source: Filtering RulesString found in binary or memory: http://www.paddypower.com/?AFF_ID=
Source: Filtering RulesString found in binary or memory: http://www.pingperfect.com/aff.php
Source: Filtering RulesString found in binary or memory: http://www.pinkvisualgames.com/?revid=
Source: Filtering RulesString found in binary or memory: http://www.pinkvisualpad.com/?revid=
Source: Filtering RulesString found in binary or memory: http://www.plus500.com/?id=
Source: Filtering RulesString found in binary or memory: http://www.quick-torrent.com/download.html?aff
Source: Filtering RulesString found in binary or memory: http://www.ragazzeinvendita.com/?rcid=
Source: Filtering RulesString found in binary or memory: http://www.reimageplus.com
Source: Filtering RulesString found in binary or memory: http://www.revenuehits.com/
Source: Filtering RulesString found in binary or memory: http://www.roboform.com/php/land.php
Source: Filtering RulesString found in binary or memory: http://www.securegfm.com/
Source: Filtering RulesString found in binary or memory: http://www.seekbang.com/cs/
Source: Filtering RulesString found in binary or memory: http://www.sexgangsters.com/?pid=
Source: Filtering RulesString found in binary or memory: http://www.sfippa.com/
Source: Filtering RulesString found in binary or memory: http://www.socialsex.com/
Source: Filtering RulesString found in binary or memory: http://www.streamate.com/exports/
Source: Filtering RulesString found in binary or memory: http://www.streamtunerhd.com/signup?
Source: Filtering RulesString found in binary or memory: http://www.terraclicks.com/
Source: Filtering RulesString found in binary or memory: http://www.text-link-ads.com/
Source: Filtering RulesString found in binary or memory: http://www.tirerack.com/affiliates/
Source: Filtering RulesString found in binary or memory: http://www.torntv-downloader.com/
Source: Filtering RulesString found in binary or memory: http://www.twinplan.com/AF_
Source: Filtering RulesString found in binary or memory: http://www.uniblue.com/cm/
Source: Filtering RulesString found in binary or memory: http://www.urmediazone.com/signup
Source: Filtering RulesString found in binary or memory: http://www.usearchmedia.com/signup?
Source: Filtering RulesString found in binary or memory: http://www.wantstraffic.com/
Source: Filtering RulesString found in binary or memory: http://www.webtrackerplus.com/
Source: Filtering RulesString found in binary or memory: http://www.xmediaserve.com/
Source: Filtering RulesString found in binary or memory: http://wxdownloadmanager.com/dl/
Source: Filtering RulesString found in binary or memory: http://xads.zedo.com/
Source: Filtering RulesString found in binary or memory: http://xtgem.com/click?
Source: Filtering RulesString found in binary or memory: http://yads.zedo.com/
Source: Filtering RulesString found in binary or memory: http://z1.zedo.com/
Source: Filtering RulesString found in binary or memory: http://zevera.com/afi.html
Source: Filtering RulesString found in binary or memory: https://a-ads.com/?partner=
Source: Filtering RulesString found in binary or memory: https://a-ads.com/campaigns/
Source: Filtering RulesString found in binary or memory: https://a.adtng.com/
Source: Filtering RulesString found in binary or memory: https://a.bestcontentfood.top/
Source: Filtering RulesString found in binary or memory: https://a.bestcontentoperation.top/
Source: Filtering RulesString found in binary or memory: https://a.bestcontentweb.top/
Source: Filtering RulesString found in binary or memory: https://a.montangop.top/
Source: Filtering RulesString found in binary or memory: https://aaucwbe.com/
Source: Filtering RulesString found in binary or memory: https://ad.atdmt.com/
Source: Filtering RulesString found in binary or memory: https://ad.doubleclick.net/
Source: Filtering RulesString found in binary or memory: https://ad.zanox.com/ppc/
Source: Filtering RulesString found in binary or memory: https://ad13.adfarm1.adition.com/
Source: Filtering RulesString found in binary or memory: https://adclick.g.doubleclick.net/
Source: Filtering RulesString found in binary or memory: https://adhealers.com/
Source: Filtering RulesString found in binary or memory: https://adnetwrk.com/
Source: Filtering RulesString found in binary or memory: https://ads-for-free.com/click.php?
Source: Filtering RulesString found in binary or memory: https://ads.ad4game.com/
Source: Filtering RulesString found in binary or memory: https://ads.betfair.com/redirect.aspx?
Source: Filtering RulesString found in binary or memory: https://ads.cdn.live/
Source: Filtering RulesString found in binary or memory: https://ads.leovegas.com/redirect.aspx?
Source: Filtering RulesString found in binary or memory: https://ads.planetwin365affiliate.com/redirect.aspx?
Source: Filtering RulesString found in binary or memory: https://ads.trafficpoizon.com/
Source: Filtering RulesString found in binary or memory: https://adserver.adreactor.com/
Source: Filtering RulesString found in binary or memory: https://adsrv4k.com/
Source: Filtering RulesString found in binary or memory: https://adswick.com/
Source: Filtering RulesString found in binary or memory: https://adultfriendfinder.com/go/page/landing
Source: Filtering RulesString found in binary or memory: https://aff-ads.stickywilds.com/
Source: Filtering RulesString found in binary or memory: https://affcpatrk.com/
Source: Filtering RulesString found in binary or memory: https://affect3dnetwork.com/track/
Source: Filtering RulesString found in binary or memory: https://affiliate.fastcomet.com/
Source: Filtering RulesString found in binary or memory: https://affiliate.geekbuying.com/gkbaffiliate.php?
Source: Filtering RulesString found in binary or memory: https://affiliates.bet-at-home.com/processing/
Source: Filtering RulesString found in binary or memory: https://agacelebir.com/
Source: Filtering RulesString found in binary or memory: https://ak.hetaruwg.com/
Source: Filtering RulesString found in binary or memory: https://albionsoftwares.com/
Source: Filtering RulesString found in binary or memory: https://americafirstpolls.com/
Source: Filtering RulesString found in binary or memory: https://as.conjectwatson.com/
Source: Filtering RulesString found in binary or memory: https://as.sexad.net/
Source: Filtering RulesString found in binary or memory: https://ausoafab.net/
Source: Filtering RulesString found in binary or memory: https://awbbjmp.com/
Source: Filtering RulesString found in binary or memory: https://awecrptjmp.com/
Source: Filtering RulesString found in binary or memory: https://awejmp.com/
Source: Filtering RulesString found in binary or memory: https://awentw.com/
Source: Filtering RulesString found in binary or memory: https://aweptjmp.com/
Source: Filtering RulesString found in binary or memory: https://awptjmp.com/
Source: Filtering RulesString found in binary or memory: https://axdsz.pro/
Source: Filtering RulesString found in binary or memory: https://azpresearch.club/
Source: Filtering RulesString found in binary or memory: https://badoinkvr.com/
Source: Filtering RulesString found in binary or memory: https://bestcond1tions.com/
Source: Filtering RulesString found in binary or memory: https://betway.com/
Source: Filtering RulesString found in binary or memory: https://blackorange.go2cloud.org/
Source: Filtering RulesString found in binary or memory: https://bluedelivery.pro/
Source: Filtering RulesString found in binary or memory: https://bngpt.com/
Source: Filtering RulesString found in binary or memory: https://bnsjb1ab1e.com/
Source: Filtering RulesString found in binary or memory: https://bongacams10.com/track?
Source: Filtering RulesString found in binary or memory: https://bongacams2.com/track?
Source: Filtering RulesString found in binary or memory: https://bs.serving-sys.com
Source: Filtering RulesString found in binary or memory: https://bullads.net/get/
Source: Filtering RulesString found in binary or memory: https://burpee.xyz/
Source: Filtering RulesString found in binary or memory: https://cagothie.net/
Source: Filtering RulesString found in binary or memory: https://camfapr.com/landing/click/
Source: Filtering RulesString found in binary or memory: https://cams.imagetwist.com/in/?track=
Source: Filtering RulesString found in binary or memory: https://chaturbate.com/affiliates/
Source: Filtering RulesString found in binary or memory: https://chaturbate.com/in/?tour=
Source: Filtering RulesString found in binary or memory: https://chaturbate.com/in/?track=
Source: Filtering RulesString found in binary or memory: https://chaturbate.jjgirls.com/?track=
Source: Filtering RulesString found in binary or memory: https://chaturbate.xyz/
Source: Filtering RulesString found in binary or memory: https://claring-loccelkin.com/
Source: Filtering RulesString found in binary or memory: https://click.a-ads.com/
Source: Filtering RulesString found in binary or memory: https://click.hoolig.app/
Source: Filtering RulesString found in binary or memory: https://click.plista.com/pets
Source: Filtering RulesString found in binary or memory: https://click2cvs.com/
Source: Filtering RulesString found in binary or memory: https://clickadilla.com/
Source: Filtering RulesString found in binary or memory: https://clicks.pipaffiliates.com/
Source: Filtering RulesString found in binary or memory: https://clixtrac.com/
Source: Filtering RulesString found in binary or memory: https://content.oneindia.com/www/delivery/
Source: Filtering RulesString found in binary or memory: https://control.trafficfabrik.com/
Source: Filtering RulesString found in binary or memory: https://cpartner.bdswiss.com/
Source: Filtering RulesString found in binary or memory: https://cpmspace.com/
Source: Filtering RulesString found in binary or memory: https://creacdn.top-convert.com/
Source: Filtering RulesString found in binary or memory: https://dediseedbox.com/clients/aff.php?
Source: Filtering RulesString found in binary or memory: https://deliver.ptgncdn.com/
Source: Filtering RulesString found in binary or memory: https://deliver.tf2www.com/
Source: Filtering RulesString found in binary or memory: https://delivery.porn.com/
Source: Filtering RulesString found in binary or memory: https://detachedbates.com/
Source: Filtering RulesString found in binary or memory: https://dianches-inchor.com/
Source: Filtering RulesString found in binary or memory: https://dltags.com/
Source: Filtering RulesString found in binary or memory: https://dooloust.net/
Source: Filtering RulesString found in binary or memory: https://dynamicadx.com/
Source: Filtering RulesString found in binary or memory: https://earandmarketing.com/
Source: Filtering RulesString found in binary or memory: https://easygamepromo.com/ef/custom_affiliate/
Source: Filtering RulesString found in binary or memory: https://engine.phn.doublepimp.com/
Source: Filtering RulesString found in binary or memory: https://explore.findanswersnow.net/
Source: Filtering RulesString found in binary or memory: https://fakelay.com/
Source: Filtering RulesString found in binary or memory: https://farm.plista.com/pets
Source: Filtering RulesString found in binary or memory: https://fast-redirecting.com/
Source: Filtering RulesString found in binary or memory: https://fertilitycommand.com/
Source: Filtering RulesString found in binary or memory: https://fileboom.me/pr/
Source: Filtering RulesString found in binary or memory: https://financeads.net/tc.php?
Source: Filtering RulesString found in binary or memory: https://fleshlight.sjv.io/
Source: Filtering RulesString found in binary or memory: https://flirtaescopa.com/
Source: Filtering RulesString found in binary or memory: https://fonts.fontplace9.com/
Source: Filtering RulesString found in binary or memory: https://frameworkdeserve.com/
Source: Filtering RulesString found in binary or memory: https://freeadult.games/
Source: Filtering RulesString found in binary or memory: https://galaxyroms.net/?scr=
Source: Filtering RulesString found in binary or memory: https://gamescarousel.com/
Source: Filtering RulesString found in binary or memory: https://geniusdexchange.com/
Source: Filtering RulesString found in binary or memory: https://gghf.mobi/
Source: Filtering RulesString found in binary or memory: https://giftsale.co.uk/?utm_
Source: Filtering RulesString found in binary or memory: https://glersakr.com/
Source: Filtering RulesString found in binary or memory: https://go.247traffic.com/
Source: Filtering RulesString found in binary or memory: https://go.4rabettraff.com/
Source: Filtering RulesString found in binary or memory: https://go.ad2up.com/
Source: Filtering RulesString found in binary or memory: https://go.admjmp.com/
Source: Filtering RulesString found in binary or memory: https://go.affiliatexe.com/
Source: Filtering RulesString found in binary or memory: https://go.alxbgo.com/
Source: Filtering RulesString found in binary or memory: https://go.astutelinks.com/
Source: Filtering RulesString found in binary or memory: https://go.cmrdr.com/
Source: Filtering RulesString found in binary or memory: https://go.currency.com/
Source: Filtering RulesString found in binary or memory: https://go.ebrokerserve.com/
Source: Filtering RulesString found in binary or memory: https://go.etoro.com/
Source: Filtering RulesString found in binary or memory: https://go.gldrdr.com/
Source: Filtering RulesString found in binary or memory: https://go.goaserv.com/
Source: Filtering RulesString found in binary or memory: https://go.goasrv.com/
Source: Filtering RulesString found in binary or memory: https://go.hpyjmp.com/
Source: Filtering RulesString found in binary or memory: https://go.hpyrdr.com/
Source: Filtering RulesString found in binary or memory: https://go.julrdr.com/
Source: Filtering RulesString found in binary or memory: https://go.markets.com/visit/?bta=
Source: Filtering RulesString found in binary or memory: https://go.onclasrv.com/
Source: Filtering RulesString found in binary or memory: https://go.strpjmp.com/
Source: Filtering RulesString found in binary or memory: https://go.tmrjmp.com
Source: Filtering RulesString found in binary or memory: https://go.trackitalltheway.com/
Source: Filtering RulesString found in binary or memory: https://go.trkclick2.com/
Source: Filtering RulesString found in binary or memory: https://go.xtbaffiliates.com/
Source: Filtering RulesString found in binary or memory: https://go.xxxjmp.com
Source: Filtering RulesString found in binary or memory: https://gogoman.me/
Source: Filtering RulesString found in binary or memory: https://gohere.pl/
Source: Filtering RulesString found in binary or memory: https://googleads.g.doubleclick.net/pcs/click
Source: Filtering RulesString found in binary or memory: https://goraps.com/
Source: Filtering RulesString found in binary or memory: https://graizoah.com/
Source: Filtering RulesString found in binary or memory: https://horny-pussies.com/tds
Source: Filtering RulesString found in binary or memory: https://iac.ampxdirect.com/
Source: Filtering RulesString found in binary or memory: https://iactrivago.ampxdirect.com/
Source: Filtering RulesString found in binary or memory: https://incisivetrk.cvtr.io/click?
Source: Filtering RulesString found in binary or memory: https://infinitytrk.com/
Source: Filtering RulesString found in binary or memory: https://intenseaffiliates.com/redirect/
Source: Filtering RulesString found in binary or memory: https://intrev.co/
Source: Filtering RulesString found in binary or memory: https://iqbroker.com/
Source: Filtering RulesString found in binary or memory: https://ismlks.com/
Source: Filtering RulesString found in binary or memory: https://jmp.awempire.com/
Source: Filtering RulesString found in binary or memory: https://join.dreamsexworld.com/
Source: Filtering RulesString found in binary or memory: https://join.girlsoutwest.com/
Source: Filtering RulesString found in binary or memory: https://join.playboyplus.com/track/
Source: Filtering RulesString found in binary or memory: https://join.sexworld3d.com/track/
Source: Filtering RulesString found in binary or memory: https://join.virtuallust3d.com/
Source: Filtering RulesString found in binary or memory: https://join.virtualtaboo.com/track/
Source: Filtering RulesString found in binary or memory: https://join3.bannedsextapes.com
Source: Filtering RulesString found in binary or memory: https://juicyads.in/
Source: Filtering RulesString found in binary or memory: https://k2s.cc/pr/
Source: Filtering RulesString found in binary or memory: https://keep2share.cc/pr/
Source: Filtering RulesString found in binary or memory: https://land.brazzersnetwork.com/landing/
Source: Filtering RulesString found in binary or memory: https://land.rk.com/landing/
Source: Filtering RulesString found in binary or memory: https://landing.brazzersnetwork.com/
Source: Filtering RulesString found in binary or memory: https://landing.brazzersplus.com/
Source: Filtering RulesString found in binary or memory: https://landing1.brazzersnetwork.com
Source: Filtering RulesString found in binary or memory: https://lead1.pl/
Source: Filtering RulesString found in binary or memory: https://leg.xyz/?track=
Source: Filtering RulesString found in binary or memory: https://look.utndln.com/
Source: Filtering RulesString found in binary or memory: https://m.do.co/c/
Source: Filtering RulesString found in binary or memory: https://maymooth-stopic.com/
Source: Filtering RulesString found in binary or memory: https://mcdlks.com/
Source: Filtering RulesString found in binary or memory: https://mediaserver.entainpartners.com/renderBanner.do?
Source: Filtering RulesString found in binary or memory: https://mediaserver.gvcaffiliates.com/renderBanner.do?
Source: Filtering RulesString found in binary or memory: https://mylead.global/stl/
Source: Filtering RulesString found in binary or memory: https://mypillow.com/
Source: Filtering RulesString found in binary or memory: https://r.kraken.com/
Source: Filtering RulesString found in binary or memory: https://rapidgator.net/article/premium/ref/
Source: Filtering RulesString found in binary or memory: https://secure.bmtmicro.com/servlets/
Source: Filtering RulesString found in binary or memory: https://shiftnetwork.infusionsoft.com/go/
Source: Filtering RulesString found in binary or memory: https://shrugartisticelder.com
Source: Filtering RulesString found in binary or memory: https://stvkr.com/
Source: Filtering RulesString found in binary or memory: https://t.ajrkm.link/
Source: Filtering RulesString found in binary or memory: https://totlnkcl.com/
Source: Filtering RulesString found in binary or memory: https://track.fiverr.com/visit/
Source: Filtering RulesString found in binary or memory: https://traffserve.com/
Source: Filtering RulesString found in binary or memory: https://v.investologic.co.uk/
Source: Filtering RulesString found in binary or memory: https://wct.link/
Source: Filtering RulesString found in binary or memory: https://www.dcpodj3k5.com/
Source: Filtering RulesString found in binary or memory: https://www.hostg.xyz/aff_c
Source: Filtering RulesString found in binary or memory: https://www.mypillow.com/
Source: Filtering RulesString found in binary or memory: https://www.reimageplus.com/
Source: Filtering RulesString found in binary or memory: https://www.restoro.com/
Source: Filtering RulesString found in binary or memory: https://www.targetingpartner.com/
Source: Filtering RulesString found in binary or memory: https://zone.gotrackier.com/
Source: classification engineClassification label: mal48.win@0/0@0/0
Source: Filtering RulesStatic file information: File size 1850055 > 1048576
No Mitre Att&ck techniques found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1586205 Sample: Filtering Rules Startdate: 08/01/2025 Architecture: WINDOWS Score: 48 5 Antivirus detection for URL or domain 2->5

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Filtering Rules0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.freefilesdownloader.com/0%Avira URL Cloudsafe
https://iactrivago.ampxdirect.com/0%Avira URL Cloudsafe
http://join.rodneymoore.com/0%Avira URL Cloudsafe
https://gamescarousel.com/100%Avira URL Cloudmalware
https://cpmspace.com/0%Avira URL Cloudsafe
http://record.betsafe.com/0%Avira URL Cloudsafe
http://ad-apac.doubleclick.net/0%Avira URL Cloudsafe
http://www.onclickmega.com/jump/next.php?100%Avira URL Cloudmalware
http://see-work.info/0%Avira URL Cloudsafe
https://traffserve.com/0%Avira URL Cloudsafe
http://www.linkbucks.com/referral/0%Avira URL Cloudsafe
http://go.ad2up.com/0%Avira URL Cloudsafe
http://www.sexgangsters.com/?pid=0%Avira URL Cloudsafe
http://papi.mynativeplatform.com:80/pub2/0%Avira URL Cloudsafe
http://www.affiliates1128.com/processing/0%Avira URL Cloudsafe
http://www.flashx.tv/downloadthis0%Avira URL Cloudsafe
http://reallygoodlink.freehookupaffair.com/0%Avira URL Cloudsafe
http://www.friendlyduck.com/AF_0%Avira URL Cloudsafe
https://m.do.co/c/0%Avira URL Cloudsafe
https://ads.planetwin365affiliate.com/redirect.aspx?0%Avira URL Cloudsafe
http://install.securewebsiteaccess.com/0%Avira URL Cloudsafe
https://gohere.pl/0%Avira URL Cloudsafe
http://affiliates.thrixxx.com/0%Avira URL Cloudsafe
http://servicegetbook.net/0%Avira URL Cloudsafe
http://greensmoke.com/0%Avira URL Cloudsafe
http://www.downloadweb.org/0%Avira URL Cloudsafe
http://adprovider.adlure.net/0%Avira URL Cloudsafe
http://www.graboid.com/affiliates/0%Avira URL Cloudsafe
http://360ads.go2cloud.org/0%Avira URL Cloudsafe
https://v.investologic.co.uk/0%Avira URL Cloudsafe
https://ads.trafficpoizon.com/0%Avira URL Cloudsafe
http://engine.newsmaxfeednetwork.com/0%Avira URL Cloudsafe
https://albionsoftwares.com/100%Avira URL Cloudmalware
https://cpartner.bdswiss.com/0%Avira URL Cloudsafe
https://dianches-inchor.com/0%Avira URL Cloudsafe
http://adsrv.keycaptcha.com0%Avira URL Cloudsafe
https://americafirstpolls.com/0%Avira URL Cloudsafe
http://join3.bannedsextapes.com/track/0%Avira URL Cloudsafe
https://burpee.xyz/0%Avira URL Cloudsafe
https://badoinkvr.com/0%Avira URL Cloudsafe
http://vinfdv6b4j.com/0%Avira URL Cloudsafe
http://findersocket.com/0%Avira URL Cloudsafe
http://ffxitrack.com/0%Avira URL Cloudsafe
https://adnetwrk.com/0%Avira URL Cloudsafe
http://hotcandyland.com/partner/0%Avira URL Cloudsafe
http://affiliates.pinnaclesports.com/processing/0%Avira URL Cloudsafe
http://elitefuckbook.com/0%Avira URL Cloudsafe
https://bestcond1tions.com/0%Avira URL Cloudsafe
http://www.friendlyquacks.com/0%Avira URL Cloudsafe
https://land.rk.com/landing/0%Avira URL Cloudsafe
http://join.shemalesfromhell.com/0%Avira URL Cloudsafe
http://pityhostngco2.xyz/100%Avira URL Cloudmalware
https://join.sexworld3d.com/track/0%Avira URL Cloudsafe
http://secure.hostgator.com/~affiliat/0%Avira URL Cloudsafe
http://www.onwebcam.com/random?t_link=0%Avira URL Cloudsafe
https://adswick.com/0%Avira URL Cloudsafe
http://dftrck.com/0%Avira URL Cloudsafe
http://cdn.adstract.com/0%Avira URL Cloudsafe
http://www.firstload.de/affiliate/0%Avira URL Cloudsafe
http://enter.anabolic.com/track/0%Avira URL Cloudsafe
http://zevera.com/afi.html0%Avira URL Cloudsafe
https://jmp.awempire.com/0%Avira URL Cloudsafe
http://www.text-link-ads.com/0%Avira URL Cloudsafe
https://fast-redirecting.com/100%Avira URL Cloudmalware
http://clkmon.com/adServe/0%Avira URL Cloudsafe
https://clixtrac.com/0%Avira URL Cloudsafe
http://www.TwinPlan.com/AF_0%Avira URL Cloudsafe
http://www.mysuperpharm.com/0%Avira URL Cloudsafe
https://chaturbate.jjgirls.com/?track=0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://k2s.cc/pr/Filtering Rulesfalse
    high
    https://clicks.pipaffiliates.com/Filtering Rulesfalse
      high
      https://iactrivago.ampxdirect.com/Filtering Rulesfalse
      • Avira URL Cloud: safe
      unknown
      https://landing1.brazzersnetwork.comFiltering Rulesfalse
        high
        http://see-work.info/Filtering Rulesfalse
        • Avira URL Cloud: safe
        unknown
        http://record.betsafe.com/Filtering Rulesfalse
        • Avira URL Cloud: safe
        unknown
        https://financeads.net/tc.php?Filtering Rulesfalse
          high
          http://adclick.g.doubleclick.net/Filtering Rulesfalse
            high
            http://ad-apac.doubleclick.net/Filtering Rulesfalse
            • Avira URL Cloud: safe
            unknown
            https://gamescarousel.com/Filtering Rulesfalse
            • Avira URL Cloud: malware
            unknown
            https://go.strpjmp.com/Filtering Rulesfalse
              high
              http://join.rodneymoore.com/Filtering Rulesfalse
              • Avira URL Cloud: safe
              unknown
              https://traffserve.com/Filtering Rulesfalse
              • Avira URL Cloud: safe
              unknown
              https://cpmspace.com/Filtering Rulesfalse
              • Avira URL Cloud: safe
              unknown
              http://www.onclickmega.com/jump/next.php?Filtering Rulesfalse
              • Avira URL Cloud: malware
              unknown
              https://clickadilla.com/Filtering Rulesfalse
                high
                http://www.freefilesdownloader.com/Filtering Rulesfalse
                • Avira URL Cloud: safe
                unknown
                http://www.plus500.com/?id=Filtering Rulesfalse
                  high
                  http://papi.mynativeplatform.com:80/pub2/Filtering Rulesfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://adf.ly/?id=Filtering Rulesfalse
                    high
                    https://www.reimageplus.com/Filtering Rulesfalse
                      high
                      http://www.linkbucks.com/referral/Filtering Rulesfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://homemoviestube.com/Filtering Rulesfalse
                        high
                        http://go.ad2up.com/Filtering Rulesfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://www.sexgangsters.com/?pid=Filtering Rulesfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://bcp.crwdcntrl.net/Filtering Rulesfalse
                          high
                          https://m.do.co/c/Filtering Rulesfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://adserver.adtechus.com/Filtering Rulesfalse
                            high
                            http://reallygoodlink.freehookupaffair.com/Filtering Rulesfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://ads.cdn.live/Filtering Rulesfalse
                              high
                              https://as.sexad.net/Filtering Rulesfalse
                                high
                                http://www.affiliates1128.com/processing/Filtering Rulesfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://wct.link/Filtering Rulesfalse
                                  high
                                  http://www.friendlyduck.com/AF_Filtering Rulesfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.flashx.tv/downloadthisFiltering Rulesfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://ad.yieldmanager.com/Filtering Rulesfalse
                                    high
                                    https://ads.planetwin365affiliate.com/redirect.aspx?Filtering Rulesfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://install.securewebsiteaccess.com/Filtering Rulesfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://geniusdexchange.com/Filtering Rulesfalse
                                      high
                                      https://gohere.pl/Filtering Rulesfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://affiliates.thrixxx.com/Filtering Rulesfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://adprovider.adlure.net/Filtering Rulesfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://bc.vc/?r=Filtering Rulesfalse
                                        high
                                        https://ads.betfair.com/redirect.aspx?Filtering Rulesfalse
                                          high
                                          http://greensmoke.com/Filtering Rulesfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          http://www.bluehost.com/track/Filtering Rulesfalse
                                            high
                                            http://servicegetbook.net/Filtering Rulesfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://www.downloadweb.org/Filtering Rulesfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://www.graboid.com/affiliates/Filtering Rulesfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://360ads.go2cloud.org/Filtering Rulesfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://v.investologic.co.uk/Filtering Rulesfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://ads.trafficpoizon.com/Filtering Rulesfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://go.goasrv.com/Filtering Rulesfalse
                                              high
                                              https://albionsoftwares.com/Filtering Rulesfalse
                                              • Avira URL Cloud: malware
                                              unknown
                                              http://engine.newsmaxfeednetwork.com/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://cpartner.bdswiss.com/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://adsrv.keycaptcha.comFiltering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://dianches-inchor.com/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://join3.bannedsextapes.com/track/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://americafirstpolls.com/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://badoinkvr.com/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://burpee.xyz/Filtering Rulesfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://syndication.exoclick.com/Filtering Rulesfalse
                                                high
                                                http://www.tirerack.com/affiliates/Filtering Rulesfalse
                                                  high
                                                  http://findersocket.com/Filtering Rulesfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://vinfdv6b4j.com/Filtering Rulesfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://ffxitrack.com/Filtering Rulesfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://adnetwrk.com/Filtering Rulesfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://hotcandyland.com/partner/Filtering Rulesfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://ad.doubleclick.net/Filtering Rulesfalse
                                                    high
                                                    http://affiliates.pinnaclesports.com/processing/Filtering Rulesfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://land.rk.com/landing/Filtering Rulesfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    http://elitefuckbook.com/Filtering Rulesfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    http://ad-emea.doubleclick.net/Filtering Rulesfalse
                                                      high
                                                      http://www.friendlyquacks.com/Filtering Rulesfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://bestcond1tions.com/Filtering Rulesfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://join.sexworld3d.com/track/Filtering Rulesfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://join.shemalesfromhell.com/Filtering Rulesfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://secure.hostgator.com/~affiliat/Filtering Rulesfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://pityhostngco2.xyz/Filtering Rulesfalse
                                                      • Avira URL Cloud: malware
                                                      unknown
                                                      http://server.cpmstar.com/click.aspx?poolid=Filtering Rulesfalse
                                                        high
                                                        http://www.onwebcam.com/random?t_link=Filtering Rulesfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        https://adswick.com/Filtering Rulesfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://enter.anabolic.com/track/Filtering Rulesfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://www.firstload.de/affiliate/Filtering Rulesfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://dftrck.com/Filtering Rulesfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://cdn.adstract.com/Filtering Rulesfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://marketgid.comFiltering Rulesfalse
                                                          high
                                                          https://chaturbate.com/in/?track=Filtering Rulesfalse
                                                            high
                                                            http://zevera.com/afi.htmlFiltering Rulesfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://click.hoolig.app/Filtering Rulesfalse
                                                              high
                                                              https://jmp.awempire.com/Filtering Rulesfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              http://www.text-link-ads.com/Filtering Rulesfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://fast-redirecting.com/Filtering Rulesfalse
                                                              • Avira URL Cloud: malware
                                                              unknown
                                                              http://clkmon.com/adServe/Filtering Rulesfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              http://www.mysuperpharm.com/Filtering Rulesfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://clixtrac.com/Filtering Rulesfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              http://www.mrskin.com/tourFiltering Rulesfalse
                                                                high
                                                                http://www.TwinPlan.com/AF_Filtering Rulesfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://chaturbate.jjgirls.com/?track=Filtering Rulesfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                No contacted IP infos
                                                                Joe Sandbox version:41.0.0 Charoite
                                                                Analysis ID:1586205
                                                                Start date and time:2025-01-08 20:39:30 +01:00
                                                                Joe Sandbox product:CloudBasic
                                                                Overall analysis duration:0h 1m 28s
                                                                Hypervisor based Inspection enabled:false
                                                                Report type:full
                                                                Cookbook file name:default.jbs
                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                Number of analysed new started processes analysed:0
                                                                Number of new started drivers analysed:0
                                                                Number of existing processes analysed:0
                                                                Number of existing drivers analysed:0
                                                                Number of injected processes analysed:0
                                                                Technologies:
                                                                • EGA enabled
                                                                • AMSI enabled
                                                                Analysis Mode:default
                                                                Analysis stop reason:Timeout
                                                                Sample name:Filtering Rules
                                                                Detection:MAL
                                                                Classification:mal48.win@0/0@0/0
                                                                Cookbook Comments:
                                                                • Unable to launch sample, stop analysis
                                                                • No process behavior to analyse as no analysis process or sample was found
                                                                • Corrupt sample or wrongly selected analyzer. Details: invalid parameter
                                                                • VT rate limit hit for: Filtering Rules
                                                                No simulations
                                                                No context
                                                                No context
                                                                No context
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:data
                                                                Entropy (8bit):5.679579246502512
                                                                TrID:
                                                                  File name:Filtering Rules
                                                                  File size:1'850'055 bytes
                                                                  MD5:a97ea939d1b6d363d1a41c4ab55b9ecb
                                                                  SHA1:3669e6477eddf2521e874269769b69b042620332
                                                                  SHA256:97115a369f33b66a7ffcfb3d67c935c1e7a24fc723bb8380ad01971c447cfa9f
                                                                  SHA512:399cb37e5790effcd4d62b9b09f706c4fb19eb2ab220f1089698f1e1c6f1efdd2f55d9f4c6d58ddbcc64d7a7cf689ab0dbbfae52ce96d5baa53c43775e018279
                                                                  SSDEEP:24576:y+DPoZGeOT4JQm1zX3nJhS33dpuaQcLzNPNPCoMB50TcpdGGi:FAZxu3dplQcxNPCoMB50TcpYGi
                                                                  TLSH:0185D7137929FEB11BB22F6D98079D08C138A3F083D7ECC6EA27D11DD1E164EB9505A9
                                                                  File Content Preview:............0.8.@.R.&action=getads&..........0.8.@.R.&ad_code=..........0.8.@.R.&ad_height=..........0.8.@.R.&ad_ids=..........0.8.@.R.&ad_network_..........0.8.@.R.&ad_slot=..........0.8.@.R.&ad_sub=..........0.8.@.R.&ad_system=..........0.8.@.R.&ad_time
                                                                  Icon Hash:72e2a2a292a2a2b2
                                                                  No network behavior found
                                                                  No statistics
                                                                  No system behavior
                                                                  No disassembly