Windows
Analysis Report
prgNb8YFEA.exe
Overview
General Information
Sample name: | prgNb8YFEA.exerenamed because original name is a hash value |
Original sample name: | e248994d1154ecc091a72040543631f6faf42e980b524193b6ea207262a374a7.exe |
Analysis ID: | 1588806 |
MD5: | 5314dc731381de014b294374b0eb7666 |
SHA1: | 9e3577f1495fdbb76115231a8a6680db0bed3632 |
SHA256: | e248994d1154ecc091a72040543631f6faf42e980b524193b6ea207262a374a7 |
Tags: | exeSnakeKeyloggeruser-adrian__luca |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- prgNb8YFEA.exe (PID: 2644 cmdline:
"C:\Users\ user\Deskt op\prgNb8Y FEA.exe" MD5: 5314DC731381DE014B294374B0EB7666) - brontothere.exe (PID: 2892 cmdline:
"C:\Users\ user\Deskt op\prgNb8Y FEA.exe" MD5: 5314DC731381DE014B294374B0EB7666) - RegSvcs.exe (PID: 6952 cmdline:
"C:\Users\ user\Deskt op\prgNb8Y FEA.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94)
- wscript.exe (PID: 4696 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\Micro soft\Windo ws\Start M enu\Progra ms\Startup \brontothe re.vbs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - brontothere.exe (PID: 6448 cmdline:
"C:\Users\ user\AppDa ta\Local\M ilburr\bro ntothere.e xe" MD5: 5314DC731381DE014B294374B0EB7666) - RegSvcs.exe (PID: 6480 cmdline:
"C:\Users\ user\AppDa ta\Local\M ilburr\bro ntothere.e xe" MD5: 9D352BC46709F0CB5EC974633A0C3C94)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"Exfil Mode": "FTP", "FTP Server": "ftp://ftp.hogarsancamilo.org/", "FTP Username": "Johnson@hogarsancamilo.org", "Password": "eg0wtRsF5HKA", "Version": "5.1"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
Windows_Trojan_SnakeKeylogger_af3faa65 | unknown | unknown |
| |
MALWARE_Win_SnakeKeylogger | Detects Snake Keylogger | ditekSHen |
| |
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Click to see the 24 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
Windows_Trojan_SnakeKeylogger_af3faa65 | unknown | unknown |
| |
MAL_Envrial_Jan18_1 | Detects Encrial credential stealer malware | Florian Roth |
| |
INDICATOR_SUSPICIOUS_EXE_DotNetProcHook | Detects executables with potential process hoocking | ditekSHen |
| |
MALWARE_Win_SnakeKeylogger | Detects Snake Keylogger | ditekSHen |
| |
Click to see the 23 entries |
System Summary |
---|
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Michael Haag: |
Data Obfuscation |
---|
Source: | Author: Joe Security: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T05:44:14.428651+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49703 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:17.317027+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49713 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:18.661966+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49725 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:21.524781+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49744 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:25.519627+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49776 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:30.694284+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49817 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:31.996574+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49823 | 104.21.112.1 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T05:44:12.839145+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49701 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:13.792316+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49701 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:15.432902+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49704 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:16.698738+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49707 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:24.089423+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49762 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:24.964350+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49762 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:26.214397+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49783 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:27.448861+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49791 | 193.122.6.168 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 5_2_00D84696 | |
Source: | Code function: | 5_2_00D8C9C7 | |
Source: | Code function: | 5_2_00D8C93C | |
Source: | Code function: | 5_2_00D8F200 | |
Source: | Code function: | 5_2_00D8F35D | |
Source: | Code function: | 5_2_00D8F65E | |
Source: | Code function: | 5_2_00D83A2B | |
Source: | Code function: | 5_2_00D83D4E | |
Source: | Code function: | 5_2_00D8BF27 | |
Source: | Code function: | 7_2_00B74696 | |
Source: | Code function: | 7_2_00B7C9C7 | |
Source: | Code function: | 7_2_00B7C93C | |
Source: | Code function: | 7_2_00B7F200 | |
Source: | Code function: | 7_2_00B7F35D | |
Source: | Code function: | 7_2_00B7F65E | |
Source: | Code function: | 7_2_00B73A2B | |
Source: | Code function: | 7_2_00B73D4E | |
Source: | Code function: | 7_2_00B7BF27 | |
Source: | Code function: | 11_2_00B74696 | |
Source: | Code function: | 11_2_00B7C9C7 | |
Source: | Code function: | 11_2_00B7C93C | |
Source: | Code function: | 11_2_00B7F200 | |
Source: | Code function: | 11_2_00B7F35D | |
Source: | Code function: | 11_2_00B7F65E | |
Source: | Code function: | 11_2_00B73A2B | |
Source: | Code function: | 11_2_00B73D4E | |
Source: | Code function: | 11_2_00B7BF27 |
Source: | Code function: | 8_2_02C9F778 | |
Source: | Code function: | 8_2_02C9E431 | |
Source: | Code function: | 8_2_02C9E431 | |
Source: | Code function: | 8_2_02C9D7F0 | |
Source: | Code function: | 8_2_054E0D60 | |
Source: | Code function: | 8_2_054EC4B8 | |
Source: | Code function: | 8_2_054E11C0 | |
Source: | Code function: | 8_2_054ECD68 | |
Source: | Code function: | 8_2_054E1506 | |
Source: | Code function: | 8_2_054EBC08 | |
Source: | Code function: | 8_2_054EF480 | |
Source: | Code function: | 8_2_054E04A0 | |
Source: | Code function: | 8_2_054EE778 | |
Source: | Code function: | 8_2_054EAF00 | |
Source: | Code function: | 8_2_054EB7B0 | |
Source: | Code function: | 8_2_054ED618 | |
Source: | Code function: | 8_2_054EDEC8 | |
Source: | Code function: | 8_2_054E0900 | |
Source: | Code function: | 8_2_054EC910 | |
Source: | Code function: | 8_2_054ED1C0 | |
Source: | Code function: | 8_2_054E11B0 | |
Source: | Code function: | 8_2_054E0040 | |
Source: | Code function: | 8_2_054EC060 | |
Source: | Code function: | 8_2_054EF028 | |
Source: | Code function: | 8_2_054EF8D8 | |
Source: | Code function: | 8_2_054EB358 | |
Source: | Code function: | 8_2_054EE320 | |
Source: | Code function: | 8_2_054EEBD0 | |
Source: | Code function: | 8_2_054EDA70 | |
Source: | Code function: | 8_2_068E78B8 | |
Source: | Code function: | 8_2_068E61C8 | |
Source: | Code function: | 8_2_068E4790 | |
Source: | Code function: | 8_2_068E6758 | |
Source: | Code function: | 8_2_068E5498 | |
Source: | Code function: | 8_2_068E0498 | |
Source: | Code function: | 8_2_068E7460 | |
Source: | Code function: | 8_2_068E5D48 | |
Source: | Code function: | 8_2_068E6BB0 | |
Source: | Code function: | 8_2_068E4BE8 | |
Source: | Code function: | 8_2_068E4310 | |
Source: | Code function: | 8_2_068E58F0 | |
Source: | Code function: | 8_2_068E08F0 | |
Source: | Code function: | 8_2_068E7008 | |
Source: | Code function: | 8_2_068E0040 | |
Source: | Code function: | 8_2_068E5040 |
Networking |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 5_2_00D925E2 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Code function: | 5_2_00D9425A |
Source: | Code function: | 5_2_00D94458 | |
Source: | Code function: | 7_2_00B84458 | |
Source: | Code function: | 11_2_00B84458 |
Source: | Code function: | 5_2_00D9425A |
Source: | Code function: | 5_2_00D80219 |
Source: | Code function: | 5_2_00DACDAC | |
Source: | Code function: | 7_2_00B9CDAC | |
Source: | Code function: | 11_2_00B9CDAC |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 5_2_00D23B4C | |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_5a92bc8e-7 | |
Source: | String found in binary or memory: | memstr_9a68f3a4-2 | |
Source: | Code function: | 7_2_00B13B4C | |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_ea2221a6-6 | |
Source: | String found in binary or memory: | memstr_41b389bf-9 | |
Source: | Code function: | 11_2_00B13B4C | |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_4a03fbee-9 | |
Source: | String found in binary or memory: | memstr_4569a26f-9 |
Source: | COM Object queried: | Jump to behavior |
Source: | Code function: | 5_2_00D23633 | |
Source: | Code function: | 5_2_00DAC27C | |
Source: | Code function: | 5_2_00DAC220 | |
Source: | Code function: | 5_2_00DAC49C | |
Source: | Code function: | 5_2_00DAC788 | |
Source: | Code function: | 5_2_00DAC8EE | |
Source: | Code function: | 5_2_00DAC86D | |
Source: | Code function: | 5_2_00DACBF9 | |
Source: | Code function: | 5_2_00DACBAE | |
Source: | Code function: | 5_2_00DACB50 | |
Source: | Code function: | 5_2_00DACB7F | |
Source: | Code function: | 5_2_00DACC2E | |
Source: | Code function: | 5_2_00DACDAC | |
Source: | Code function: | 5_2_00DACD6C | |
Source: | Code function: | 5_2_00D21290 | |
Source: | Code function: | 5_2_00D21287 | |
Source: | Code function: | 5_2_00D216DE | |
Source: | Code function: | 5_2_00DAD6C6 | |
Source: | Code function: | 5_2_00D216B5 | |
Source: | Code function: | 5_2_00D2167D | |
Source: | Code function: | 5_2_00DAD74C | |
Source: | Code function: | 5_2_00D2189B | |
Source: | Code function: | 5_2_00DADA9A | |
Source: | Code function: | 5_2_00DABF4D | |
Source: | Code function: | 7_2_00B13633 | |
Source: | Code function: | 7_2_00B9C220 | |
Source: | Code function: | 7_2_00B9C27C | |
Source: | Code function: | 7_2_00B9C49C | |
Source: | Code function: | 7_2_00B9C788 | |
Source: | Code function: | 7_2_00B9C8EE | |
Source: | Code function: | 7_2_00B9C86D | |
Source: | Code function: | 7_2_00B9CBAE | |
Source: | Code function: | 7_2_00B9CBF9 | |
Source: | Code function: | 7_2_00B9CB7F | |
Source: | Code function: | 7_2_00B9CB50 | |
Source: | Code function: | 7_2_00B9CC2E | |
Source: | Code function: | 7_2_00B9CDAC | |
Source: | Code function: | 7_2_00B9CD6C | |
Source: | Code function: | 7_2_00B11290 | |
Source: | Code function: | 7_2_00B11287 | |
Source: | Code function: | 7_2_00B116B5 | |
Source: | Code function: | 7_2_00B116DE | |
Source: | Code function: | 7_2_00B9D6C6 | |
Source: | Code function: | 7_2_00B1167D | |
Source: | Code function: | 7_2_00B9D74C | |
Source: | Code function: | 7_2_00B1189B | |
Source: | Code function: | 7_2_00B9DA9A | |
Source: | Code function: | 7_2_00B9BF4D | |
Source: | Code function: | 11_2_00B13633 | |
Source: | Code function: | 11_2_00B9C220 | |
Source: | Code function: | 11_2_00B9C27C | |
Source: | Code function: | 11_2_00B9C49C | |
Source: | Code function: | 11_2_00B9C788 | |
Source: | Code function: | 11_2_00B9C8EE | |
Source: | Code function: | 11_2_00B9C86D | |
Source: | Code function: | 11_2_00B9CBAE | |
Source: | Code function: | 11_2_00B9CBF9 | |
Source: | Code function: | 11_2_00B9CB7F | |
Source: | Code function: | 11_2_00B9CB50 | |
Source: | Code function: | 11_2_00B9CC2E | |
Source: | Code function: | 11_2_00B9CDAC | |
Source: | Code function: | 11_2_00B9CD6C | |
Source: | Code function: | 11_2_00B11290 | |
Source: | Code function: | 11_2_00B11287 | |
Source: | Code function: | 11_2_00B116B5 | |
Source: | Code function: | 11_2_00B116DE | |
Source: | Code function: | 11_2_00B9D6C6 | |
Source: | Code function: | 11_2_00B1167D | |
Source: | Code function: | 11_2_00B9D74C | |
Source: | Code function: | 11_2_00B1189B | |
Source: | Code function: | 11_2_00B9DA9A | |
Source: | Code function: | 11_2_00B9BF4D |
Source: | Code function: | 5_2_00D840B1 |
Source: | Code function: | 5_2_00D78858 |
Source: | Code function: | 5_2_00D8545F | |
Source: | Code function: | 7_2_00B7545F | |
Source: | Code function: | 11_2_00B7545F |
Source: | Code function: | 5_2_00D2E800 | |
Source: | Code function: | 5_2_00D4DBB5 | |
Source: | Code function: | 5_2_00D2FE40 | |
Source: | Code function: | 5_2_00DA804A | |
Source: | Code function: | 5_2_00D2E060 | |
Source: | Code function: | 5_2_00D34140 | |
Source: | Code function: | 5_2_00D42405 | |
Source: | Code function: | 5_2_00D56522 | |
Source: | Code function: | 5_2_00D5267E | |
Source: | Code function: | 5_2_00DA0665 | |
Source: | Code function: | 5_2_00D36843 | |
Source: | Code function: | 5_2_00D4283A | |
Source: | Code function: | 5_2_00D589DF | |
Source: | Code function: | 5_2_00DA0AE2 | |
Source: | Code function: | 5_2_00D56A94 | |
Source: | Code function: | 5_2_00D38A0E | |
Source: | Code function: | 5_2_00D88B13 | |
Source: | Code function: | 5_2_00D7EB07 | |
Source: | Code function: | 5_2_00D4CD61 | |
Source: | Code function: | 5_2_00D57006 | |
Source: | Code function: | 5_2_00D33190 | |
Source: | Code function: | 5_2_00D3710E | |
Source: | Code function: | 5_2_00D21287 | |
Source: | Code function: | 5_2_00D433C7 | |
Source: | Code function: | 5_2_00D4F419 | |
Source: | Code function: | 5_2_00D416C4 | |
Source: | Code function: | 5_2_00D35680 | |
Source: | Code function: | 5_2_00D478D3 | |
Source: | Code function: | 5_2_00D358C0 | |
Source: | Code function: | 5_2_00D41BB8 | |
Source: | Code function: | 5_2_00D59D05 | |
Source: | Code function: | 5_2_00D41FD0 | |
Source: | Code function: | 5_2_00D4BFE6 | |
Source: | Code function: | 5_2_0122B4A8 | |
Source: | Code function: | 7_2_00B3DBB5 | |
Source: | Code function: | 7_2_00B1E060 | |
Source: | Code function: | 7_2_00B9804A | |
Source: | Code function: | 7_2_00B24140 | |
Source: | Code function: | 7_2_00B32405 | |
Source: | Code function: | 7_2_00B46522 | |
Source: | Code function: | 7_2_00B4267E | |
Source: | Code function: | 7_2_00B90665 | |
Source: | Code function: | 7_2_00B3283A | |
Source: | Code function: | 7_2_00B1E800 | |
Source: | Code function: | 7_2_00B26843 | |
Source: | Code function: | 7_2_00B489DF | |
Source: | Code function: | 7_2_00B46A94 | |
Source: | Code function: | 7_2_00B90AE2 | |
Source: | Code function: | 7_2_00B28A0E | |
Source: | Code function: | 7_2_00B78B13 | |
Source: | Code function: | 7_2_00B6EB07 | |
Source: | Code function: | 7_2_00B3CD61 | |
Source: | Code function: | 7_2_00B47006 | |
Source: | Code function: | 7_2_00B23190 | |
Source: | Code function: | 7_2_00B2710E | |
Source: | Code function: | 7_2_00B11287 | |
Source: | Code function: | 7_2_00B333C7 | |
Source: | Code function: | 7_2_00B3F419 | |
Source: | Code function: | 7_2_00B25680 | |
Source: | Code function: | 7_2_00B316C4 | |
Source: | Code function: | 7_2_00B378D3 | |
Source: | Code function: | 7_2_00B258C0 | |
Source: | Code function: | 7_2_00B31BB8 | |
Source: | Code function: | 7_2_00B49D05 | |
Source: | Code function: | 7_2_00B1FE40 | |
Source: | Code function: | 7_2_00B3BFE6 | |
Source: | Code function: | 7_2_00B31FD0 | |
Source: | Code function: | 7_2_0184BD78 | |
Source: | Code function: | 8_2_02C9B328 | |
Source: | Code function: | 8_2_02C9C190 | |
Source: | Code function: | 8_2_02C96108 | |
Source: | Code function: | 8_2_02C9C752 | |
Source: | Code function: | 8_2_02C9F778 | |
Source: | Code function: | 8_2_02C9C470 | |
Source: | Code function: | 8_2_02C9E431 | |
Source: | Code function: | 8_2_02C94AD9 | |
Source: | Code function: | 8_2_02C9CA32 | |
Source: | Code function: | 8_2_02C9BBB8 | |
Source: | Code function: | 8_2_02C96880 | |
Source: | Code function: | 8_2_02C99858 | |
Source: | Code function: | 8_2_02C9BEB0 | |
Source: | Code function: | 8_2_02C9D7E0 | |
Source: | Code function: | 8_2_02C9D7F0 | |
Source: | Code function: | 8_2_02C9B4F2 | |
Source: | Code function: | 8_2_02C93572 | |
Source: | Code function: | 8_2_054E0D60 | |
Source: | Code function: | 8_2_054EC4B8 | |
Source: | Code function: | 8_2_054E77A8 | |
Source: | Code function: | 8_2_054E7E78 | |
Source: | Code function: | 8_2_054E3288 | |
Source: | Code function: | 8_2_054ECD58 | |
Source: | Code function: | 8_2_054E0D50 | |
Source: | Code function: | 8_2_054ECD68 | |
Source: | Code function: | 8_2_054E6DF6 | |
Source: | Code function: | 8_2_054EF471 | |
Source: | Code function: | 8_2_054EBC08 | |
Source: | Code function: | 8_2_054EF480 | |
Source: | Code function: | 8_2_054E0491 | |
Source: | Code function: | 8_2_054EC4A8 | |
Source: | Code function: | 8_2_054E04A0 | |
Source: | Code function: | 8_2_054EE768 | |
Source: | Code function: | 8_2_054EE778 | |
Source: | Code function: | 8_2_054EAF00 | |
Source: | Code function: | 8_2_054EB7A0 | |
Source: | Code function: | 8_2_054EB7B0 | |
Source: | Code function: | 8_2_054ED609 | |
Source: | Code function: | 8_2_054E7E02 | |
Source: | Code function: | 8_2_054E6E00 | |
Source: | Code function: | 8_2_054ED618 | |
Source: | Code function: | 8_2_054EDEC8 | |
Source: | Code function: | 8_2_054EAEEF | |
Source: | Code function: | 8_2_054EDEB8 | |
Source: | Code function: | 8_2_054EC902 | |
Source: | Code function: | 8_2_054E0900 | |
Source: | Code function: | 8_2_054EC910 | |
Source: | Code function: | 8_2_054ED1C0 | |
Source: | Code function: | 8_2_054ED1B0 | |
Source: | Code function: | 8_2_054E0040 | |
Source: | Code function: | 8_2_054EC050 | |
Source: | Code function: | 8_2_054EC060 | |
Source: | Code function: | 8_2_054E0006 | |
Source: | Code function: | 8_2_054EF018 | |
Source: | Code function: | 8_2_054EF028 | |
Source: | Code function: | 8_2_054EF8C9 | |
Source: | Code function: | 8_2_054EF8D8 | |
Source: | Code function: | 8_2_054E08F0 | |
Source: | Code function: | 8_2_054EB348 | |
Source: | Code function: | 8_2_054EB358 | |
Source: | Code function: | 8_2_054EE310 | |
Source: | Code function: | 8_2_054EE320 | |
Source: | Code function: | 8_2_054EEBC1 | |
Source: | Code function: | 8_2_054EEBD0 | |
Source: | Code function: | 8_2_054EBBF8 | |
Source: | Code function: | 8_2_054EDA61 | |
Source: | Code function: | 8_2_054E327E | |
Source: | Code function: | 8_2_054EDA70 | |
Source: | Code function: | 8_2_068E7EB2 | |
Source: | Code function: | 8_2_068EA6B0 | |
Source: | Code function: | 8_2_068EBFE8 | |
Source: | Code function: | 8_2_068E8D80 | |
Source: | Code function: | 8_2_068EAD00 | |
Source: | Code function: | 8_2_068E0D48 | |
Source: | Code function: | 8_2_068E9A18 | |
Source: | Code function: | 8_2_068E93D0 | |
Source: | Code function: | 8_2_068EB350 | |
Source: | Code function: | 8_2_068E78B8 | |
Source: | Code function: | 8_2_068EA060 | |
Source: | Code function: | 8_2_068EB9A0 | |
Source: | Code function: | 8_2_068E61C8 | |
Source: | Code function: | 8_2_068EA6A4 | |
Source: | Code function: | 8_2_068E4782 | |
Source: | Code function: | 8_2_068E4790 | |
Source: | Code function: | 8_2_068EBFD8 | |
Source: | Code function: | 8_2_068E6FF9 | |
Source: | Code function: | 8_2_068E7F00 | |
Source: | Code function: | 8_2_068E6748 | |
Source: | Code function: | 8_2_068E6758 | |
Source: | Code function: | 8_2_068E548A | |
Source: | Code function: | 8_2_068E0488 | |
Source: | Code function: | 8_2_068E5498 | |
Source: | Code function: | 8_2_068E0498 | |
Source: | Code function: | 8_2_068EACF0 | |
Source: | Code function: | 8_2_068E7450 | |
Source: | Code function: | 8_2_068E7460 | |
Source: | Code function: | 8_2_068E35A8 | |
Source: | Code function: | 8_2_068E5D3A | |
Source: | Code function: | 8_2_068E5D48 | |
Source: | Code function: | 8_2_068E8D6F | |
Source: | Code function: | 8_2_068E9A07 | |
Source: | Code function: | 8_2_068E6BA0 | |
Source: | Code function: | 8_2_068E6BB0 | |
Source: | Code function: | 8_2_068E93C0 | |
Source: | Code function: | 8_2_068E4BD8 | |
Source: | Code function: | 8_2_068E4BE8 | |
Source: | Code function: | 8_2_068E4300 | |
Source: | Code function: | 8_2_068E4310 | |
Source: | Code function: | 8_2_068EB340 | |
Source: | Code function: | 8_2_068E28A8 | |
Source: | Code function: | 8_2_068E78A8 | |
Source: | Code function: | 8_2_068E58E0 | |
Source: | Code function: | 8_2_068E08E1 | |
Source: | Code function: | 8_2_068E58F0 | |
Source: | Code function: | 8_2_068E08F0 | |
Source: | Code function: | 8_2_068E7008 | |
Source: | Code function: | 8_2_068E0006 | |
Source: | Code function: | 8_2_068E5032 | |
Source: | Code function: | 8_2_068E0040 | |
Source: | Code function: | 8_2_068E5040 | |
Source: | Code function: | 8_2_068EA050 | |
Source: | Code function: | 8_2_068EB99B | |
Source: | Code function: | 8_2_068E61B8 | |
Source: | Code function: | 11_2_00B1E800 | |
Source: | Code function: | 11_2_00B3DBB5 | |
Source: | Code function: | 11_2_00B1FE40 | |
Source: | Code function: | 11_2_00B1E060 | |
Source: | Code function: | 11_2_00B9804A | |
Source: | Code function: | 11_2_00B24140 | |
Source: | Code function: | 11_2_00B32405 | |
Source: | Code function: | 11_2_00B46522 | |
Source: | Code function: | 11_2_00B4267E | |
Source: | Code function: | 11_2_00B90665 | |
Source: | Code function: | 11_2_00B3283A | |
Source: | Code function: | 11_2_00B26843 | |
Source: | Code function: | 11_2_00B489DF | |
Source: | Code function: | 11_2_00B46A94 | |
Source: | Code function: | 11_2_00B90AE2 | |
Source: | Code function: | 11_2_00B28A0E | |
Source: | Code function: | 11_2_00B78B13 | |
Source: | Code function: | 11_2_00B6EB07 | |
Source: | Code function: | 11_2_00B3CD61 | |
Source: | Code function: | 11_2_00B47006 | |
Source: | Code function: | 11_2_00B23190 | |
Source: | Code function: | 11_2_00B2710E | |
Source: | Code function: | 11_2_00B11287 | |
Source: | Code function: | 11_2_00B333C7 | |
Source: | Code function: | 11_2_00B3F419 | |
Source: | Code function: | 11_2_00B25680 | |
Source: | Code function: | 11_2_00B316C4 | |
Source: | Code function: | 11_2_00B378D3 | |
Source: | Code function: | 11_2_00B258C0 | |
Source: | Code function: | 11_2_00B31BB8 | |
Source: | Code function: | 11_2_00B49D05 | |
Source: | Code function: | 11_2_00B3BFE6 | |
Source: | Code function: | 11_2_00B31FD0 | |
Source: | Code function: | 11_2_016BD530 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 5_2_00D8A2D5 |
Source: | Code function: | 5_2_00D78713 | |
Source: | Code function: | 5_2_00D78CC3 | |
Source: | Code function: | 7_2_00B68713 | |
Source: | Code function: | 7_2_00B68CC3 | |
Source: | Code function: | 11_2_00B68713 | |
Source: | Code function: | 11_2_00B68CC3 |
Source: | Code function: | 5_2_00D8B59E |
Source: | Code function: | 5_2_00D9F121 |
Source: | Code function: | 5_2_00D986D0 |
Source: | Code function: | 5_2_00D24FE9 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 5_2_00E37080 |
Source: | Code function: | 5_2_00D48B98 | |
Source: | Code function: | 7_2_00B38B98 | |
Source: | Code function: | 7_2_0184CF1A | |
Source: | Code function: | 8_2_054E2F01 | |
Source: | Code function: | 8_2_054E2891 | |
Source: | Code function: | 8_2_068EDA35 | |
Source: | Code function: | 8_2_068EDA39 | |
Source: | Code function: | 11_2_00B38B98 | |
Source: | Code function: | 11_2_016BDB42 | |
Source: | Code function: | 11_2_016B9EB9 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Code function: | 5_2_00D24A35 | |
Source: | Code function: | 5_2_00DA55FD | |
Source: | Code function: | 7_2_00B14A35 | |
Source: | Code function: | 7_2_00B955FD | |
Source: | Code function: | 11_2_00B14A35 | |
Source: | Code function: | 11_2_00B955FD |
Source: | Code function: | 5_2_00D433C7 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_5-100435 | ||
Source: | Evasive API call chain: |
Source: | API coverage: | ||
Source: | API coverage: | ||
Source: | API coverage: |
Source: | Code function: | 5_2_00D84696 | |
Source: | Code function: | 5_2_00D8C9C7 | |
Source: | Code function: | 5_2_00D8C93C | |
Source: | Code function: | 5_2_00D8F200 | |
Source: | Code function: | 5_2_00D8F35D | |
Source: | Code function: | 5_2_00D8F65E | |
Source: | Code function: | 5_2_00D83A2B | |
Source: | Code function: | 5_2_00D83D4E | |
Source: | Code function: | 5_2_00D8BF27 | |
Source: | Code function: | 7_2_00B74696 | |
Source: | Code function: | 7_2_00B7C9C7 | |
Source: | Code function: | 7_2_00B7C93C | |
Source: | Code function: | 7_2_00B7F200 | |
Source: | Code function: | 7_2_00B7F35D | |
Source: | Code function: | 7_2_00B7F65E | |
Source: | Code function: | 7_2_00B73A2B | |
Source: | Code function: | 7_2_00B73D4E | |
Source: | Code function: | 7_2_00B7BF27 | |
Source: | Code function: | 11_2_00B74696 | |
Source: | Code function: | 11_2_00B7C9C7 | |
Source: | Code function: | 11_2_00B7C93C | |
Source: | Code function: | 11_2_00B7F200 | |
Source: | Code function: | 11_2_00B7F35D | |
Source: | Code function: | 11_2_00B7F65E | |
Source: | Code function: | 11_2_00B73A2B | |
Source: | Code function: | 11_2_00B73D4E | |
Source: | Code function: | 11_2_00B7BF27 |
Source: | Code function: | 5_2_00D24AFE |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_5-98909 | ||
Source: | API call chain: | graph_5-99143 | ||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: |
Source: | Code function: | 8_2_054E77A8 |
Source: | Code function: | 5_2_00D941FD |
Source: | Code function: | 5_2_00D23B4C |
Source: | Code function: | 5_2_00D55CCC |
Source: | Code function: | 5_2_00E37080 |
Source: | Code function: | 5_2_0122B338 | |
Source: | Code function: | 5_2_0122B398 | |
Source: | Code function: | 5_2_01229CD8 | |
Source: | Code function: | 7_2_0184A5A8 | |
Source: | Code function: | 7_2_0184BC08 | |
Source: | Code function: | 7_2_0184BC68 | |
Source: | Code function: | 11_2_016BD3C0 | |
Source: | Code function: | 11_2_016BD420 | |
Source: | Code function: | 11_2_016BBD60 |
Source: | Code function: | 5_2_00D781F7 |
Source: | Code function: | 5_2_00D4A395 | |
Source: | Code function: | 5_2_00D4A364 | |
Source: | Code function: | 7_2_00B3A395 | |
Source: | Code function: | 7_2_00B3A364 | |
Source: | Code function: | 11_2_00B3A395 | |
Source: | Code function: | 11_2_00B3A364 |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 5_2_00D78C93 |
Source: | Code function: | 5_2_00D23B4C |
Source: | Code function: | 5_2_00D24A35 |
Source: | Code function: | 5_2_00D84EC9 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 5_2_00D781F7 |
Source: | Code function: | 5_2_00D84C03 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 5_2_00D4886B |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 5_2_00D550D7 |
Source: | Code function: | 5_2_00D62230 |
Source: | Code function: | 5_2_00D5418A |
Source: | Code function: | 5_2_00D24AFE |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 5_2_00D96596 | |
Source: | Code function: | 5_2_00D96A5A | |
Source: | Code function: | 7_2_00B86596 | |
Source: | Code function: | 7_2_00B86A5A | |
Source: | Code function: | 11_2_00B86596 | |
Source: | Code function: | 11_2_00B86A5A |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 111 Scripting | 2 Valid Accounts | 2 Native API | 111 Scripting | 1 Exploitation for Privilege Escalation | 11 Disable or Modify Tools | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 1 Archive Collected Data | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | 21 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 1 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 2 Valid Accounts | 2 Valid Accounts | 31 Obfuscated Files or Information | Security Account Manager | 2 File and Directory Discovery | SMB/Windows Admin Shares | 1 Email Collection | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Registry Run Keys / Startup Folder | 21 Access Token Manipulation | 1 Software Packing | NTDS | 127 System Information Discovery | Distributed Component Object Model | 21 Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 212 Process Injection | 1 DLL Side-Loading | LSA Secrets | 231 Security Software Discovery | SSH | 3 Clipboard Data | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | 2 Registry Run Keys / Startup Folder | 1 Masquerading | Cached Domain Credentials | 11 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Valid Accounts | DCSync | 2 Process Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 11 Virtualization/Sandbox Evasion | Proc Filesystem | 11 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 21 Access Token Manipulation | /etc/passwd and /etc/shadow | 1 System Owner/User Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 212 Process Injection | Network Sniffing | 1 System Network Configuration Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
73% | Virustotal | Browse | ||
61% | ReversingLabs | Win32.Spyware.Snakekeylogger | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
61% | ReversingLabs | Win32.Spyware.Snakekeylogger | ||
73% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
reallyfreegeoip.org | 104.21.112.1 | true | false | high | |
checkip.dyndns.com | 193.122.6.168 | true | false | high | |
checkip.dyndns.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.112.1 | reallyfreegeoip.org | United States | 13335 | CLOUDFLARENETUS | false | |
193.122.6.168 | checkip.dyndns.com | United States | 31898 | ORACLE-BMC-31898US | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588806 |
Start date and time: | 2025-01-11 05:43:11 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 24s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | prgNb8YFEA.exerenamed because original name is a hash value |
Original Sample Name: | e248994d1154ecc091a72040543631f6faf42e980b524193b6ea207262a374a7.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.expl.evad.winEXE@10/6@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 13.107.246.45, 52.149.20.212
- Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report creation exceeded maximum time and may have missing disassembly code information.
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
05:44:10 | Autostart | |
23:44:12 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.21.112.1 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | CMSBrute | Browse |
| ||
193.122.6.168 | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
checkip.dyndns.com | Get hash | malicious | MassLogger RAT | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| ||
reallyfreegeoip.org | Get hash | malicious | MassLogger RAT | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ORACLE-BMC-31898US | Get hash | malicious | MassLogger RAT | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HawkEye, MailPassView | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | MassLogger RAT | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
|
Process: | C:\Users\user\Desktop\prgNb8YFEA.exe |
File Type: | |
Category: | modified |
Size (bytes): | 609280 |
Entropy (8bit): | 7.586046761793758 |
Encrypted: | false |
SSDEEP: | 12288:oYV6MorX7qzuC3QHO9FQVHPF51jgc7nbUwhIZLBZE:HBXu9HGaVH7nbUwGfE |
MD5: | 5314DC731381DE014B294374B0EB7666 |
SHA1: | 9E3577F1495FDBB76115231A8A6680DB0BED3632 |
SHA-256: | E248994D1154ECC091A72040543631F6FAF42E980B524193B6EA207262A374A7 |
SHA-512: | 0EB21211A73870D1D9681CD236BCB6EDFE5E2049477FC4773C8F7E3F9868352DAC55BD95DF8B3547BDAD060AE2EE05B8E8A7280B904F273DEFF0C2881B431F44 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\prgNb8YFEA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 87750 |
Entropy (8bit): | 7.904845056128631 |
Encrypted: | false |
SSDEEP: | 1536:QI8LaSvhGSW7QlGOn4xlomSt9lVynGSTUAJ/kEFCuDJg0DHCvrVmXA:pSvhGz71On+lomafUGSTNJfPW0mvYA |
MD5: | 080F0A7871A4B2664AE741D4AA16D99C |
SHA1: | BB6008B3B45BCA6DD65DD22A76F2DB85AB12F06B |
SHA-256: | 94B2EF3D6075BB2D32D96F0FD6F844D9F6A171757025569D5C9B7B49BF200086 |
SHA-512: | 7576F61F3EF4017125B78A652EB16FF582DF3740B16373AFBD85BE41E04DA97EA6954F78F568FFC9E9A2565A29A90722063B8946FEDCF04CCD7138CA9AC10A86 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Local\Milburr\brontothere.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 87750 |
Entropy (8bit): | 7.904845056128631 |
Encrypted: | false |
SSDEEP: | 1536:QI8LaSvhGSW7QlGOn4xlomSt9lVynGSTUAJ/kEFCuDJg0DHCvrVmXA:pSvhGz71On+lomafUGSTNJfPW0mvYA |
MD5: | 080F0A7871A4B2664AE741D4AA16D99C |
SHA1: | BB6008B3B45BCA6DD65DD22A76F2DB85AB12F06B |
SHA-256: | 94B2EF3D6075BB2D32D96F0FD6F844D9F6A171757025569D5C9B7B49BF200086 |
SHA-512: | 7576F61F3EF4017125B78A652EB16FF582DF3740B16373AFBD85BE41E04DA97EA6954F78F568FFC9E9A2565A29A90722063B8946FEDCF04CCD7138CA9AC10A86 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Local\Milburr\brontothere.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 87750 |
Entropy (8bit): | 7.904845056128631 |
Encrypted: | false |
SSDEEP: | 1536:QI8LaSvhGSW7QlGOn4xlomSt9lVynGSTUAJ/kEFCuDJg0DHCvrVmXA:pSvhGz71On+lomafUGSTNJfPW0mvYA |
MD5: | 080F0A7871A4B2664AE741D4AA16D99C |
SHA1: | BB6008B3B45BCA6DD65DD22A76F2DB85AB12F06B |
SHA-256: | 94B2EF3D6075BB2D32D96F0FD6F844D9F6A171757025569D5C9B7B49BF200086 |
SHA-512: | 7576F61F3EF4017125B78A652EB16FF582DF3740B16373AFBD85BE41E04DA97EA6954F78F568FFC9E9A2565A29A90722063B8946FEDCF04CCD7138CA9AC10A86 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\prgNb8YFEA.exe |
File Type: | |
Category: | modified |
Size (bytes): | 131072 |
Entropy (8bit): | 6.998701347678074 |
Encrypted: | false |
SSDEEP: | 3072:uWsp4sHRAyqrjGwVtZOtaJ5YyYage3Vjd3KCAPdtvCin:UpVHivmwLJ5t9KNn |
MD5: | CDD378F43140DDD4B4487EE7459D98D7 |
SHA1: | 8EEF98A4C9DE80E461125304D25F62D7CF27B777 |
SHA-256: | A5D1AA75FD07BFEC093BA72CEC8BE5A1F5537774A3BCC96D06426F56B5554EFE |
SHA-512: | 9A18EE8BC2C6E07F72EDEB236C9EC57812F63D4131B8841871627C7855A91FDC2A99E475A4BB663CA9057771C77EFC914BA4DB32AFC2CF13F38F0BBB0F979D56 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\brontothere.vbs
Download File
Process: | C:\Users\user\AppData\Local\Milburr\brontothere.exe |
File Type: | |
Category: | modified |
Size (bytes): | 286 |
Entropy (8bit): | 3.4247564872866394 |
Encrypted: | false |
SSDEEP: | 6:DMM8lfm3OOQdUfclMMlW8g1UEZ+lX1olFe3CnDdnriIM8lfQVn:DsO+vNlMkXg1Q1olE3AmA2n |
MD5: | 724591EB75B9AC723085FFDCA4749631 |
SHA1: | 2C143E8A219D5B916760B5BA7540F81E32D56A5E |
SHA-256: | 10AA83853CAEC24F1B4B51495B37C33DA7E918A07AE1AA213FC3DE2877DE853A |
SHA-512: | 3CE7F7690C533893C4533BBE68B9B3B263C98B36218FF01BDE7AD36D6F3A117B09BFF15CC0FE94F42F8FACAA816BB78E718C6A75A209C68A5D6E032E45AAD20D |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.586046761793758 |
TrID: |
|
File name: | prgNb8YFEA.exe |
File size: | 609'280 bytes |
MD5: | 5314dc731381de014b294374b0eb7666 |
SHA1: | 9e3577f1495fdbb76115231a8a6680db0bed3632 |
SHA256: | e248994d1154ecc091a72040543631f6faf42e980b524193b6ea207262a374a7 |
SHA512: | 0eb21211a73870d1d9681cd236bcb6edfe5e2049477fc4773c8f7e3f9868352dac55bd95df8b3547bdad060ae2ee05b8e8a7280b904f273deff0c2881b431f44 |
SSDEEP: | 12288:oYV6MorX7qzuC3QHO9FQVHPF51jgc7nbUwhIZLBZE:HBXu9HGaVH7nbUwGfE |
TLSH: | 90D401877680556BC425FEB784371D20E397AD99A5B87206298F7D24A3B76E3303318F |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........s..R...R...R....C..P.....;.S..._@#.a..._@......_@..g...[j..[...[jo.w...R...r.............#.S..._@'.S...R.k.S.....".S...RichR.. |
Icon Hash: | 0d2d0d1723293133 |
Entrypoint: | 0x517080 |
Entrypoint Section: | UPX1 |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x676A9DB0 [Tue Dec 24 11:40:32 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | fc6683d30d9f25244a50fd5357825e79 |
Instruction |
---|
pushad |
mov esi, 004C1000h |
lea edi, dword ptr [esi-000C0000h] |
push edi |
jmp 00007F47ACE6CAFDh |
nop |
mov al, byte ptr [esi] |
inc esi |
mov byte ptr [edi], al |
inc edi |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007F47ACE6CADFh |
mov eax, 00000001h |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc eax, eax |
add ebx, ebx |
jnc 00007F47ACE6CAFDh |
jne 00007F47ACE6CB1Ah |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007F47ACE6CB11h |
dec eax |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc eax, eax |
jmp 00007F47ACE6CAC6h |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc ecx, ecx |
jmp 00007F47ACE6CB44h |
xor ecx, ecx |
sub eax, 03h |
jc 00007F47ACE6CB03h |
shl eax, 08h |
mov al, byte ptr [esi] |
inc esi |
xor eax, FFFFFFFFh |
je 00007F47ACE6CB67h |
sar eax, 1 |
mov ebp, eax |
jmp 00007F47ACE6CAFDh |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007F47ACE6CABEh |
inc ecx |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jc 00007F47ACE6CAB0h |
add ebx, ebx |
jne 00007F47ACE6CAF9h |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
adc ecx, ecx |
add ebx, ebx |
jnc 00007F47ACE6CAE1h |
jne 00007F47ACE6CAFBh |
mov ebx, dword ptr [esi] |
sub esi, FFFFFFFCh |
adc ebx, ebx |
jnc 00007F47ACE6CAD6h |
add ecx, 02h |
cmp ebp, FFFFFB00h |
adc ecx, 02h |
lea edx, dword ptr [edi+ebp] |
cmp ebp, FFFFFFFCh |
jbe 00007F47ACE6CB00h |
mov al, byte ptr [edx] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x155dec | 0x424 | .rsrc |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x118000 | 0x3ddec | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x156210 | 0xc | .rsrc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x117264 | 0x48 | UPX1 |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
UPX0 | 0x1000 | 0xc0000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
UPX1 | 0xc1000 | 0x57000 | 0x56400 | 257d01144382bba87ae8e16daa6f23b4 | False | 0.9873018568840579 | data | 7.935347181695601 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x118000 | 0x3f000 | 0x3e400 | 0ee25dbab1e18e2c7cb8f7d79f892599 | False | 0.6623329254518072 | data | 6.716918087091885 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x11851c | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.7466216216216216 |
RT_ICON | 0x118648 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | Great Britain | 0.3277027027027027 |
RT_ICON | 0x118774 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.3885135135135135 |
RT_ICON | 0x1188a0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | English | Great Britain | 0.45567375886524825 |
RT_ICON | 0x118d0c | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | English | Great Britain | 0.299953095684803 |
RT_ICON | 0x119db8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | English | Great Britain | 0.2274896265560166 |
RT_ICON | 0x11c364 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16384 | English | Great Britain | 0.18865139348134152 |
RT_ICON | 0x120590 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 65536 | English | Great Britain | 0.13214243463858985 |
RT_MENU | 0xe0d98 | 0x50 | data | English | Great Britain | 1.1375 |
RT_STRING | 0xe0de8 | 0x594 | data | English | Great Britain | 1.007703081232493 |
RT_STRING | 0xe137c | 0x68a | data | English | Great Britain | 1.0065710872162486 |
RT_STRING | 0xe1a08 | 0x490 | data | English | Great Britain | 1.009417808219178 |
RT_STRING | 0xe1e98 | 0x5fc | data | English | Great Britain | 1.0071801566579635 |
RT_STRING | 0xe2494 | 0x65c | data | English | Great Britain | 1.0067567567567568 |
RT_STRING | 0xe2af0 | 0x466 | data | English | Great Britain | 1.0097690941385435 |
RT_STRING | 0xe2f58 | 0x158 | data | English | Great Britain | 1.0319767441860466 |
RT_RCDATA | 0x130dbc | 0x24ac3 | data | 1.0003728089154589 | ||
RT_GROUP_ICON | 0x155884 | 0x4c | data | English | Great Britain | 0.8157894736842105 |
RT_GROUP_ICON | 0x1558d4 | 0x14 | data | English | Great Britain | 1.25 |
RT_GROUP_ICON | 0x1558ec | 0x14 | data | English | Great Britain | 1.15 |
RT_GROUP_ICON | 0x155904 | 0x14 | data | English | Great Britain | 1.25 |
RT_VERSION | 0x15591c | 0xdc | data | English | Great Britain | 0.6181818181818182 |
RT_MANIFEST | 0x1559fc | 0x3ef | ASCII text, with CRLF line terminators | English | Great Britain | 0.5074478649453823 |
DLL | Import |
---|---|
KERNEL32.DLL | LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess |
ADVAPI32.dll | GetAce |
COMCTL32.dll | ImageList_Remove |
COMDLG32.dll | GetOpenFileNameW |
GDI32.dll | LineTo |
IPHLPAPI.DLL | IcmpSendEcho |
MPR.dll | WNetUseConnectionW |
ole32.dll | CoGetObject |
OLEAUT32.dll | VariantInit |
PSAPI.DLL | GetProcessMemoryInfo |
SHELL32.dll | DragFinish |
USER32.dll | GetDC |
USERENV.dll | LoadUserProfileW |
UxTheme.dll | IsThemeActive |
VERSION.dll | VerQueryValueW |
WININET.dll | FtpOpenFileW |
WINMM.dll | timeGetTime |
WSOCK32.dll | connect |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | Great Britain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T05:44:12.839145+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49701 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:13.792316+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49701 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:14.428651+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49703 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:15.432902+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49704 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:16.698738+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49707 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:17.317027+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49713 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:18.661966+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49725 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:21.524781+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49744 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:24.089423+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49762 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:24.964350+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49762 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:25.519627+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49776 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:26.214397+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49783 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:27.448861+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49791 | 193.122.6.168 | 80 | TCP |
2025-01-11T05:44:30.694284+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49817 | 104.21.112.1 | 443 | TCP |
2025-01-11T05:44:31.996574+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49823 | 104.21.112.1 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 05:44:11.956439018 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:11.961349010 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:11.961441994 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:11.965744972 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:11.970561028 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:12.597281933 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:12.601984024 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:12.606765985 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:12.788983107 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:12.839144945 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:12.844633102 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:12.844656944 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:12.847904921 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:12.858766079 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:12.858783007 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.343553066 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.343748093 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.350959063 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.350981951 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.351289034 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.401638985 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.414532900 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.455334902 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.534130096 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.534195900 CET | 443 | 49702 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.535898924 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.554713964 CET | 49702 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.559809923 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:13.564593077 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:13.746769905 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:13.792315960 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:13.826977015 CET | 49703 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.827102900 CET | 443 | 49703 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:13.827193975 CET | 49703 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.828111887 CET | 49703 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:13.828140020 CET | 443 | 49703 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:14.282782078 CET | 443 | 49703 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:14.305496931 CET | 49703 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:14.305583000 CET | 443 | 49703 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:14.428663969 CET | 443 | 49703 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:14.428752899 CET | 443 | 49703 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:14.428864002 CET | 49703 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:14.433964014 CET | 49703 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:14.752917051 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:14.758573055 CET | 80 | 49701 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:14.758645058 CET | 49701 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:14.760576010 CET | 49704 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:14.766767025 CET | 80 | 49704 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:14.766843081 CET | 49704 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:14.767126083 CET | 49704 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:14.772177935 CET | 80 | 49704 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:15.390126944 CET | 80 | 49704 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:15.392182112 CET | 49706 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:15.392242908 CET | 443 | 49706 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:15.392317057 CET | 49706 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:15.392640114 CET | 49706 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:15.392657042 CET | 443 | 49706 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:15.432902098 CET | 49704 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:15.846970081 CET | 443 | 49706 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:15.849306107 CET | 49706 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:15.849351883 CET | 443 | 49706 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:15.979640961 CET | 443 | 49706 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:15.979708910 CET | 443 | 49706 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:15.980150938 CET | 49706 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:15.980401993 CET | 49706 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:15.985378981 CET | 49704 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:15.985384941 CET | 49707 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:15.990216017 CET | 80 | 49707 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:15.990329981 CET | 80 | 49704 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:15.990341902 CET | 49707 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:15.990463972 CET | 49704 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:15.990464926 CET | 49707 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:15.995505095 CET | 80 | 49707 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:16.657473087 CET | 80 | 49707 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:16.662161112 CET | 49713 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:16.662267923 CET | 443 | 49713 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:16.662837982 CET | 49713 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:16.663203001 CET | 49713 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:16.663238049 CET | 443 | 49713 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:16.698738098 CET | 49707 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:17.170401096 CET | 443 | 49713 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:17.172174931 CET | 49713 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:17.172218084 CET | 443 | 49713 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:17.317064047 CET | 443 | 49713 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:17.317141056 CET | 443 | 49713 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:17.317214012 CET | 49713 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:17.331295013 CET | 49713 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:17.383300066 CET | 49719 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:17.388258934 CET | 80 | 49719 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:17.388329983 CET | 49719 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:17.388576031 CET | 49719 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:17.393394947 CET | 80 | 49719 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:18.014130116 CET | 80 | 49719 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:18.017250061 CET | 49725 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:18.017297983 CET | 443 | 49725 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:18.017682076 CET | 49725 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:18.018654108 CET | 49725 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:18.018671036 CET | 443 | 49725 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:18.059957027 CET | 49719 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:18.502624035 CET | 443 | 49725 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:18.516778946 CET | 49725 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:18.516817093 CET | 443 | 49725 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:18.661982059 CET | 443 | 49725 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:18.662043095 CET | 443 | 49725 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:18.663703918 CET | 49725 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:18.688072920 CET | 49725 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:18.863374949 CET | 49719 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:18.864835024 CET | 49729 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:18.868491888 CET | 80 | 49719 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:18.868571043 CET | 49719 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:18.869688034 CET | 80 | 49729 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:18.869756937 CET | 49729 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:18.869885921 CET | 49729 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:18.874716997 CET | 80 | 49729 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:19.514828920 CET | 80 | 49729 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:19.516427040 CET | 49732 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:19.516474962 CET | 443 | 49732 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:19.516546965 CET | 49732 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:19.516845942 CET | 49732 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:19.516858101 CET | 443 | 49732 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:19.558001995 CET | 49729 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:19.988450050 CET | 443 | 49732 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:19.990497112 CET | 49732 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:19.990525007 CET | 443 | 49732 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:20.129419088 CET | 443 | 49732 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:20.129487038 CET | 443 | 49732 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:20.129559040 CET | 49732 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:20.130132914 CET | 49732 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:20.133616924 CET | 49729 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:20.134984970 CET | 49738 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:20.138657093 CET | 80 | 49729 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:20.139727116 CET | 80 | 49738 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:20.139789104 CET | 49729 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:20.139832020 CET | 49738 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:20.139964104 CET | 49738 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:20.144711018 CET | 80 | 49738 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:20.794580936 CET | 80 | 49738 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:20.797094107 CET | 49744 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:20.797143936 CET | 443 | 49744 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:20.797213078 CET | 49744 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:20.797540903 CET | 49744 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:20.797550917 CET | 443 | 49744 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:20.839260101 CET | 49738 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:21.267030001 CET | 443 | 49744 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:21.272135973 CET | 49744 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:21.272185087 CET | 443 | 49744 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:21.524806023 CET | 443 | 49744 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:21.524878025 CET | 443 | 49744 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:21.525074005 CET | 49744 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:21.538628101 CET | 49744 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:21.617753029 CET | 49738 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:21.622900963 CET | 80 | 49738 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:21.626138926 CET | 49750 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:21.626179934 CET | 49738 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:21.630959988 CET | 80 | 49750 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:21.631052017 CET | 49750 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:21.635050058 CET | 49750 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:21.639909029 CET | 80 | 49750 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:22.285343885 CET | 80 | 49750 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:22.303031921 CET | 49756 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:22.303086996 CET | 443 | 49756 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:22.303162098 CET | 49756 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:22.304168940 CET | 49756 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:22.304187059 CET | 443 | 49756 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:22.339327097 CET | 49750 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:22.767189980 CET | 443 | 49756 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:22.769936085 CET | 49756 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:22.769974947 CET | 443 | 49756 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:22.896955013 CET | 443 | 49756 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:22.897152901 CET | 443 | 49756 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:22.897200108 CET | 49756 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:22.897697926 CET | 49756 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:23.201390028 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:23.206480026 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:23.206563950 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:23.206820965 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:23.211653948 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:23.845026016 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:23.852066040 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:23.856983900 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:24.038342953 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:24.075109959 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.075151920 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.075582027 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.079547882 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.079564095 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.089422941 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:24.532954931 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.533994913 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.534842014 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.534851074 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.535183907 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.589359999 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.609777927 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.651334047 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.715065002 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.715152025 CET | 443 | 49769 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.716131926 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.719923019 CET | 49769 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.723336935 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:24.728147030 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:24.912143946 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:24.914706945 CET | 49776 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.914751053 CET | 443 | 49776 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.914813995 CET | 49776 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.915138960 CET | 49776 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:24.915152073 CET | 443 | 49776 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:24.964349985 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:25.371685028 CET | 443 | 49776 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:25.382870913 CET | 49776 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:25.382909060 CET | 443 | 49776 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:25.519721031 CET | 443 | 49776 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:25.519887924 CET | 443 | 49776 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:25.519943953 CET | 49776 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:25.520410061 CET | 49776 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:25.526714087 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:25.530977011 CET | 49783 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:25.531713963 CET | 80 | 49762 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:25.531779051 CET | 49762 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:25.535866022 CET | 80 | 49783 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:25.535948992 CET | 49783 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:25.536076069 CET | 49783 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:25.541567087 CET | 80 | 49783 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:26.162110090 CET | 80 | 49783 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:26.163671970 CET | 49788 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:26.163723946 CET | 443 | 49788 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:26.168150902 CET | 49788 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:26.168530941 CET | 49788 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:26.168545961 CET | 443 | 49788 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:26.214396954 CET | 49783 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:26.628144026 CET | 443 | 49788 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:26.640300035 CET | 49788 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:26.640346050 CET | 443 | 49788 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:26.756067991 CET | 443 | 49788 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:26.756143093 CET | 443 | 49788 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:26.756225109 CET | 49788 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:26.756757021 CET | 49788 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:26.760546923 CET | 49783 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:26.761990070 CET | 49791 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:26.765597105 CET | 80 | 49783 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:26.765707016 CET | 49783 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:26.766896009 CET | 80 | 49791 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:26.766984940 CET | 49791 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:26.767137051 CET | 49791 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:26.771986008 CET | 80 | 49791 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:27.394572973 CET | 80 | 49791 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:27.396373034 CET | 49797 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:27.396451950 CET | 443 | 49797 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:27.396687984 CET | 49797 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:27.397027969 CET | 49797 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:27.397047043 CET | 443 | 49797 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:27.448860884 CET | 49791 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:27.874036074 CET | 443 | 49797 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:27.876177073 CET | 49797 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:27.876204014 CET | 443 | 49797 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:28.010452032 CET | 443 | 49797 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:28.010528088 CET | 443 | 49797 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:28.010644913 CET | 49797 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:28.011158943 CET | 49797 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:28.030122995 CET | 49801 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:28.035037994 CET | 80 | 49801 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:28.040177107 CET | 49801 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:28.040343046 CET | 49801 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:28.046664000 CET | 80 | 49801 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:28.751349926 CET | 80 | 49801 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:28.755548954 CET | 49807 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:28.755615950 CET | 443 | 49807 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:28.755721092 CET | 49807 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:28.755996943 CET | 49807 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:28.756016016 CET | 443 | 49807 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:28.808243036 CET | 49801 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:29.238116980 CET | 443 | 49807 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:29.241491079 CET | 49807 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:29.241516113 CET | 443 | 49807 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:29.393687963 CET | 443 | 49807 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:29.393937111 CET | 443 | 49807 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:29.394012928 CET | 49807 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:29.394412994 CET | 49807 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:29.398542881 CET | 49801 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:29.399596930 CET | 49813 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:29.403630018 CET | 80 | 49801 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:29.403723955 CET | 49801 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:29.404529095 CET | 80 | 49813 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:29.404601097 CET | 49813 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:29.418751001 CET | 49813 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:29.423813105 CET | 80 | 49813 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:30.040564060 CET | 80 | 49813 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:30.074724913 CET | 49817 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:30.074762106 CET | 443 | 49817 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:30.074837923 CET | 49817 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:30.075165987 CET | 49817 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:30.075180054 CET | 443 | 49817 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:30.089428902 CET | 49813 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:30.553752899 CET | 443 | 49817 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:30.586169958 CET | 49817 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:30.586200953 CET | 443 | 49817 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:30.694407940 CET | 443 | 49817 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:30.694582939 CET | 443 | 49817 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:30.694659948 CET | 49817 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:30.698523998 CET | 49817 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:30.737224102 CET | 49813 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:30.738900900 CET | 49820 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:30.742345095 CET | 80 | 49813 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:30.742412090 CET | 49813 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:30.743801117 CET | 80 | 49820 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:30.743864059 CET | 49820 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:30.743983030 CET | 49820 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:30.748764992 CET | 80 | 49820 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:31.369410992 CET | 80 | 49820 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:31.374655008 CET | 49823 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:31.374703884 CET | 443 | 49823 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:31.374771118 CET | 49823 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:31.375082970 CET | 49823 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:31.375098944 CET | 443 | 49823 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:31.417591095 CET | 49820 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:31.829736948 CET | 443 | 49823 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:31.831444025 CET | 49823 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:31.831535101 CET | 443 | 49823 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:31.996584892 CET | 443 | 49823 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:31.996640921 CET | 443 | 49823 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:31.996792078 CET | 49823 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:31.997312069 CET | 49823 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:32.000883102 CET | 49820 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:32.002036095 CET | 49829 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:32.006001949 CET | 80 | 49820 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:32.006920099 CET | 80 | 49829 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:32.006997108 CET | 49820 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:32.007035971 CET | 49829 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:32.007167101 CET | 49829 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:32.011996031 CET | 80 | 49829 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:32.641592026 CET | 80 | 49829 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:44:32.643150091 CET | 49835 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:32.643193960 CET | 443 | 49835 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:32.643291950 CET | 49835 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:32.643624067 CET | 49835 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:32.643640041 CET | 443 | 49835 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:32.683260918 CET | 49829 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:44:33.117435932 CET | 443 | 49835 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:33.138479948 CET | 49835 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:33.138516903 CET | 443 | 49835 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:33.265141010 CET | 443 | 49835 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:33.265233040 CET | 443 | 49835 | 104.21.112.1 | 192.168.2.7 |
Jan 11, 2025 05:44:33.265346050 CET | 49835 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:44:33.268115044 CET | 49835 | 443 | 192.168.2.7 | 104.21.112.1 |
Jan 11, 2025 05:45:21.658471107 CET | 80 | 49707 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:45:21.658806086 CET | 49707 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:45:27.287617922 CET | 80 | 49750 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:45:27.287769079 CET | 49750 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:45:32.506222963 CET | 80 | 49791 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:45:32.509315014 CET | 49791 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:45:37.642745972 CET | 80 | 49829 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:45:37.642904043 CET | 49829 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:46:02.313404083 CET | 49750 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:46:02.318360090 CET | 80 | 49750 | 193.122.6.168 | 192.168.2.7 |
Jan 11, 2025 05:46:12.654488087 CET | 49829 | 80 | 192.168.2.7 | 193.122.6.168 |
Jan 11, 2025 05:46:12.659276962 CET | 80 | 49829 | 193.122.6.168 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 05:44:11.896862030 CET | 49608 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 11, 2025 05:44:11.903780937 CET | 53 | 49608 | 1.1.1.1 | 192.168.2.7 |
Jan 11, 2025 05:44:12.834908009 CET | 61900 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 11, 2025 05:44:12.842525005 CET | 53 | 61900 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 05:44:11.896862030 CET | 192.168.2.7 | 1.1.1.1 | 0x3b90 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 05:44:12.834908009 CET | 192.168.2.7 | 1.1.1.1 | 0xbeaf | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 05:44:11.903780937 CET | 1.1.1.1 | 192.168.2.7 | 0x3b90 | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:11.903780937 CET | 1.1.1.1 | 192.168.2.7 | 0x3b90 | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:11.903780937 CET | 1.1.1.1 | 192.168.2.7 | 0x3b90 | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:11.903780937 CET | 1.1.1.1 | 192.168.2.7 | 0x3b90 | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:11.903780937 CET | 1.1.1.1 | 192.168.2.7 | 0x3b90 | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:11.903780937 CET | 1.1.1.1 | 192.168.2.7 | 0x3b90 | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 05:44:12.842525005 CET | 1.1.1.1 | 192.168.2.7 | 0xbeaf | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49701 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:11.965744972 CET | 151 | OUT | |
Jan 11, 2025 05:44:12.597281933 CET | 273 | IN | |
Jan 11, 2025 05:44:12.601984024 CET | 127 | OUT | |
Jan 11, 2025 05:44:12.788983107 CET | 273 | IN | |
Jan 11, 2025 05:44:13.559809923 CET | 127 | OUT | |
Jan 11, 2025 05:44:13.746769905 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49704 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:14.767126083 CET | 127 | OUT | |
Jan 11, 2025 05:44:15.390126944 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49707 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:15.990464926 CET | 127 | OUT | |
Jan 11, 2025 05:44:16.657473087 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49719 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:17.388576031 CET | 151 | OUT | |
Jan 11, 2025 05:44:18.014130116 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49729 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:18.869885921 CET | 151 | OUT | |
Jan 11, 2025 05:44:19.514828920 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49738 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:20.139964104 CET | 151 | OUT | |
Jan 11, 2025 05:44:20.794580936 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49750 | 193.122.6.168 | 80 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:21.635050058 CET | 151 | OUT | |
Jan 11, 2025 05:44:22.285343885 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49762 | 193.122.6.168 | 80 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:23.206820965 CET | 151 | OUT | |
Jan 11, 2025 05:44:23.845026016 CET | 273 | IN | |
Jan 11, 2025 05:44:23.852066040 CET | 127 | OUT | |
Jan 11, 2025 05:44:24.038342953 CET | 273 | IN | |
Jan 11, 2025 05:44:24.723336935 CET | 127 | OUT | |
Jan 11, 2025 05:44:24.912143946 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49783 | 193.122.6.168 | 80 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:25.536076069 CET | 127 | OUT | |
Jan 11, 2025 05:44:26.162110090 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49791 | 193.122.6.168 | 80 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:26.767137051 CET | 127 | OUT | |
Jan 11, 2025 05:44:27.394572973 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49801 | 193.122.6.168 | 80 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:28.040343046 CET | 151 | OUT | |
Jan 11, 2025 05:44:28.751349926 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
11 | 192.168.2.7 | 49813 | 193.122.6.168 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:29.418751001 CET | 151 | OUT | |
Jan 11, 2025 05:44:30.040564060 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49820 | 193.122.6.168 | 80 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:30.743983030 CET | 151 | OUT | |
Jan 11, 2025 05:44:31.369410992 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49829 | 193.122.6.168 | 80 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 05:44:32.007167101 CET | 151 | OUT | |
Jan 11, 2025 05:44:32.641592026 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49702 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:13 UTC | 85 | OUT | |
2025-01-11 04:44:13 UTC | 849 | IN | |
2025-01-11 04:44:13 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49703 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:14 UTC | 61 | OUT | |
2025-01-11 04:44:14 UTC | 855 | IN | |
2025-01-11 04:44:14 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49706 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:15 UTC | 85 | OUT | |
2025-01-11 04:44:15 UTC | 857 | IN | |
2025-01-11 04:44:15 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49713 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:17 UTC | 61 | OUT | |
2025-01-11 04:44:17 UTC | 855 | IN | |
2025-01-11 04:44:17 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49725 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:18 UTC | 61 | OUT | |
2025-01-11 04:44:18 UTC | 855 | IN | |
2025-01-11 04:44:18 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49732 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:19 UTC | 85 | OUT | |
2025-01-11 04:44:20 UTC | 851 | IN | |
2025-01-11 04:44:20 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49744 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:21 UTC | 61 | OUT | |
2025-01-11 04:44:21 UTC | 851 | IN | |
2025-01-11 04:44:21 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49756 | 104.21.112.1 | 443 | 6952 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:22 UTC | 85 | OUT | |
2025-01-11 04:44:22 UTC | 861 | IN | |
2025-01-11 04:44:22 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49769 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:24 UTC | 85 | OUT | |
2025-01-11 04:44:24 UTC | 853 | IN | |
2025-01-11 04:44:24 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49776 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:25 UTC | 61 | OUT | |
2025-01-11 04:44:25 UTC | 863 | IN | |
2025-01-11 04:44:25 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49788 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:26 UTC | 85 | OUT | |
2025-01-11 04:44:26 UTC | 862 | IN | |
2025-01-11 04:44:26 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.7 | 49797 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:27 UTC | 85 | OUT | |
2025-01-11 04:44:28 UTC | 861 | IN | |
2025-01-11 04:44:28 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49807 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:29 UTC | 85 | OUT | |
2025-01-11 04:44:29 UTC | 863 | IN | |
2025-01-11 04:44:29 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49817 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:30 UTC | 61 | OUT | |
2025-01-11 04:44:30 UTC | 853 | IN | |
2025-01-11 04:44:30 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.7 | 49823 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:31 UTC | 61 | OUT | |
2025-01-11 04:44:31 UTC | 855 | IN | |
2025-01-11 04:44:31 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.7 | 49835 | 104.21.112.1 | 443 | 6480 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 04:44:33 UTC | 85 | OUT | |
2025-01-11 04:44:33 UTC | 853 | IN | |
2025-01-11 04:44:33 UTC | 362 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 5 |
Start time: | 23:44:06 |
Start date: | 10/01/2025 |
Path: | C:\Users\user\Desktop\prgNb8YFEA.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd20000 |
File size: | 609'280 bytes |
MD5 hash: | 5314DC731381DE014B294374B0EB7666 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 23:44:07 |
Start date: | 10/01/2025 |
Path: | C:\Users\user\AppData\Local\Milburr\brontothere.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb10000 |
File size: | 609'280 bytes |
MD5 hash: | 5314DC731381DE014B294374B0EB7666 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 23:44:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb90000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 23:44:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76b730000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 23:44:19 |
Start date: | 10/01/2025 |
Path: | C:\Users\user\AppData\Local\Milburr\brontothere.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb10000 |
File size: | 609'280 bytes |
MD5 hash: | 5314DC731381DE014B294374B0EB7666 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 12 |
Start time: | 23:44:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x310000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 3.6% |
Dynamic/Decrypted Code Coverage: | 0.4% |
Signature Coverage: | 8.6% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 169 |
Graph
Function 00D23B4C Relevance: 17.7, APIs: 8, Strings: 2, Instructions: 153windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D23633 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 151timewindowregistryCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24AFE Relevance: 10.7, APIs: 7, Instructions: 223COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E37080 Relevance: 7.7, APIs: 5, Instructions: 206librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2FE40 Relevance: 5.5, APIs: 3, Instructions: 1040COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D84696 Relevance: 4.5, APIs: 3, Instructions: 25fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2E800 Relevance: 2.4, Strings: 1, Instructions: 1102COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D30B30 Relevance: 57.3, APIs: 27, Strings: 5, Instructions: 1300windowsleeptimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D893DF Relevance: 19.8, APIs: 13, Instructions: 322fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D271EB Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 201registryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D23A58 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 71windowregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D23015 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 73registrywindowclipboardCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D23041 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 54registrywindowclipboardCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01228758 Relevance: 10.7, APIs: 7, Instructions: 151fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2410D Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 88windowCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0122A218 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 158fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D235B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 59registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D897E5 Relevance: 6.2, APIs: 4, Instructions: 155COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4493A Relevance: 6.1, APIs: 4, Instructions: 136COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D40FF6 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 44COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01228E38 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 41processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D9CDF1 Relevance: 4.9, APIs: 3, Instructions: 392COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2F8CF Relevance: 4.7, APIs: 3, Instructions: 168comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D243DB Relevance: 4.6, APIs: 3, Instructions: 77windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4594C Relevance: 4.6, APIs: 3, Instructions: 59memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D88F97 Relevance: 4.5, APIs: 3, Instructions: 22COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D27BB1 Relevance: 3.1, APIs: 2, Instructions: 97COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2492E Relevance: 3.1, APIs: 2, Instructions: 59COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01228EA8 Relevance: 1.7, APIs: 1, Instructions: 167COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D40E48 Relevance: 1.6, APIs: 1, Instructions: 94memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D600D6 Relevance: 1.6, APIs: 1, Instructions: 88COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D27CB3 Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24F3D Relevance: 1.6, APIs: 1, Instructions: 64libraryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D601AF Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D44A93 Relevance: 1.5, APIs: 1, Instructions: 36COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24FAA Relevance: 1.5, APIs: 1, Instructions: 28COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D409D5 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D89129 Relevance: 1.5, APIs: 1, Instructions: 22COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01228718 Relevance: 1.5, APIs: 1, Instructions: 20COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012286E8 Relevance: 1.5, APIs: 1, Instructions: 15COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4548B Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0122A104 Relevance: 1.3, APIs: 1, Instructions: 21sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0122A108 Relevance: 1.3, APIs: 1, Instructions: 18sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACDAC Relevance: 68.9, APIs: 37, Strings: 2, Instructions: 637windowkeyboardnativeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA804A Relevance: 60.1, APIs: 33, Strings: 1, Instructions: 571windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24A35 Relevance: 43.9, APIs: 24, Strings: 1, Instructions: 131keyboardthreadwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8C9C7 Relevance: 28.3, APIs: 13, Strings: 3, Instructions: 280timefileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8F200 Relevance: 28.1, APIs: 15, Strings: 1, Instructions: 119fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA0AE2 Relevance: 26.7, APIs: 9, Strings: 6, Instructions: 477registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAC8EE Relevance: 24.7, APIs: 11, Strings: 3, Instructions: 181windowfilenativeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8F35D Relevance: 24.6, APIs: 13, Strings: 1, Instructions: 112fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAC49C Relevance: 21.2, APIs: 11, Strings: 1, Instructions: 229windownativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D36843 Relevance: 18.4, Strings: 14, Instructions: 883COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D986D0 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 197comCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D94458 Relevance: 15.1, APIs: 10, Instructions: 83clipboardmemoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D83A2B Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 167fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8F65E Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 120filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7EB07 Relevance: 11.1, APIs: 1, Strings: 6, Instructions: 561stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D358C0 Relevance: 11.0, APIs: 7, Instructions: 532COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAC27C Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 149nativewindowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8545F Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 59shutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D96596 Relevance: 9.1, APIs: 6, Instructions: 84networkCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D35680 Relevance: 8.0, APIs: 5, Instructions: 516COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D21287 Relevance: 7.9, APIs: 5, Instructions: 379nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA55FD Relevance: 7.6, APIs: 5, Instructions: 69windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D33190 Relevance: 6.6, APIs: 4, Instructions: 587COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D840B1 Relevance: 6.1, APIs: 4, Instructions: 65fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D21290 Relevance: 6.1, APIs: 4, Instructions: 59nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8B59E Relevance: 4.6, APIs: 3, Instructions: 73COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78CC3 Relevance: 4.6, APIs: 3, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D84C03 Relevance: 4.5, APIs: 3, Instructions: 43memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2E060 Relevance: 3.5, APIs: 2, Instructions: 539COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D216DE Relevance: 3.1, APIs: 2, Instructions: 83nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8C93C Relevance: 3.1, APIs: 2, Instructions: 52fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACC2E Relevance: 3.0, APIs: 2, Instructions: 33nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8A2D5 Relevance: 3.0, APIs: 2, Instructions: 31windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACD6C Relevance: 3.0, APIs: 2, Instructions: 23nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78713 Relevance: 3.0, APIs: 2, Instructions: 22COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4F419 Relevance: 2.1, APIs: 1, Instructions: 645COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D5267E Relevance: 1.8, APIs: 1, Instructions: 294COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D88B13 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DADA9A Relevance: 1.6, APIs: 1, Instructions: 66nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAD6C6 Relevance: 1.5, APIs: 1, Instructions: 47nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAC220 Relevance: 1.5, APIs: 1, Instructions: 31nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2189B Relevance: 1.5, APIs: 1, Instructions: 29nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACBAE Relevance: 1.5, APIs: 1, Instructions: 24nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D84EC9 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78C93 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACBF9 Relevance: 1.5, APIs: 1, Instructions: 18nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2167D Relevance: 1.5, APIs: 1, Instructions: 18nativeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACB50 Relevance: 1.5, APIs: 1, Instructions: 14nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DACB7F Relevance: 1.5, APIs: 1, Instructions: 14nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D216B5 Relevance: 1.5, APIs: 1, Instructions: 14nativeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D62230 Relevance: 1.5, APIs: 1, Instructions: 7COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4A364 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D38A0E Relevance: .6, Instructions: 608COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D42405 Relevance: .3, Instructions: 345COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4283A Relevance: .3, Instructions: 341COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D41BB8 Relevance: .3, Instructions: 323COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0122B4A8 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0122B338 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0122B398 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01229CD8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA37F3 Relevance: 51.1, APIs: 6, Strings: 23, Instructions: 365windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAA849 Relevance: 49.8, APIs: 33, Instructions: 274COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D977BE Relevance: 45.8, APIs: 22, Strings: 4, Instructions: 284windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D22C18 Relevance: 42.5, APIs: 23, Strings: 1, Instructions: 486windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA8C44 Relevance: 38.9, APIs: 21, Strings: 1, Instructions: 401windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA4B16 Relevance: 37.0, APIs: 18, Strings: 3, Instructions: 290windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D227D9 Relevance: 33.5, APIs: 18, Strings: 1, Instructions: 286windowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA4069 Relevance: 28.3, APIs: 3, Strings: 13, Instructions: 283windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D952F0 Relevance: 27.1, APIs: 18, Instructions: 124COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7AA64 Relevance: 26.5, APIs: 14, Strings: 1, Instructions: 273windowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAA428 Relevance: 24.7, APIs: 12, Strings: 2, Instructions: 205windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA4619 Relevance: 23.0, APIs: 2, Strings: 11, Instructions: 251windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DABAB8 Relevance: 22.9, APIs: 10, Strings: 3, Instructions: 197windowlibraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8A45A Relevance: 22.9, APIs: 10, Strings: 3, Instructions: 102fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D9762D Relevance: 21.2, APIs: 11, Strings: 1, Instructions: 160windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D848F3 Relevance: 19.3, APIs: 10, Strings: 1, Instructions: 73networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D85217 Relevance: 19.3, APIs: 10, Strings: 1, Instructions: 72sleepwindowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8D7F8 Relevance: 18.3, APIs: 12, Instructions: 283comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7C72A Relevance: 18.2, APIs: 12, Instructions: 174COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D221A5 Relevance: 18.1, APIs: 12, Instructions: 132COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA73C1 Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 103windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA772A Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 101windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D47040 Relevance: 16.8, APIs: 11, Instructions: 258COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D95A45 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 163networkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D79471 Relevance: 15.8, APIs: 7, Strings: 2, Instructions: 82windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7955C Relevance: 15.8, APIs: 7, Strings: 2, Instructions: 81windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D79645 Relevance: 15.8, APIs: 4, Strings: 5, Instructions: 72windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D98BC0 Relevance: 15.3, APIs: 10, Instructions: 324fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D22E26 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 186windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA6FEF Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 143windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D98F5B Relevance: 13.9, APIs: 9, Instructions: 438COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2201B Relevance: 13.7, APIs: 9, Instructions: 170timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA88B4 Relevance: 13.7, APIs: 9, Instructions: 168COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D83226 Relevance: 12.3, APIs: 2, Strings: 5, Instructions: 82windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D84534 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 47windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D22A5B Relevance: 12.1, APIs: 8, Instructions: 129COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D87368 Relevance: 12.1, APIs: 8, Instructions: 101fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA6442 Relevance: 12.1, APIs: 8, Instructions: 95windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7C072 Relevance: 12.1, APIs: 8, Instructions: 92COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D21424 Relevance: 10.7, APIs: 7, Instructions: 219COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8589F Relevance: 10.6, APIs: 7, Instructions: 138timeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D838AD Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 111filestringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA7500 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 103windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA653C Relevance: 10.6, APIs: 7, Instructions: 99windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7E0B5 Relevance: 10.6, APIs: 7, Instructions: 90memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA783C Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 75windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D441C9 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 24libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D4429E Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 19libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8675A Relevance: 9.2, APIs: 6, Instructions: 205COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA5A20 Relevance: 9.2, APIs: 6, Instructions: 160windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7F3DD Relevance: 9.2, APIs: 6, Instructions: 159COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D826F9 Relevance: 9.1, APIs: 6, Instructions: 138windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D21765 Relevance: 9.1, APIs: 6, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAB958 Relevance: 9.1, APIs: 6, Instructions: 109windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D973B1 Relevance: 9.1, APIs: 6, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78D5B Relevance: 9.1, APIs: 6, Instructions: 69memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAC19A Relevance: 9.0, APIs: 6, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D874D2 Relevance: 9.0, APIs: 6, Instructions: 33synchronizationthreadCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D82F86 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 195windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7DA5D Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 121comlibraryloaderCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D82C42 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 114windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D79372 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 94windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA6656 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 80windowlibraryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8703E Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 79filepipeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8710C Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 79filepipeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7A52F Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 68windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D9EE69 Relevance: 7.7, APIs: 5, Instructions: 247COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8E7DC Relevance: 7.6, APIs: 5, Instructions: 135COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAA2C5 Relevance: 7.6, APIs: 5, Instructions: 130COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D76920 Relevance: 7.6, APIs: 5, Instructions: 97windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7B6AF Relevance: 7.6, APIs: 5, Instructions: 88windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAB405 Relevance: 7.6, APIs: 5, Instructions: 85COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D797E9 Relevance: 7.6, APIs: 5, Instructions: 84windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D212F3 Relevance: 7.6, APIs: 5, Instructions: 67COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7C161 Relevance: 7.6, APIs: 5, Instructions: 61COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D84D35 Relevance: 7.6, APIs: 5, Instructions: 56synchronizationthreadwindowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7874A Relevance: 7.5, APIs: 5, Instructions: 49memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D854E6 Relevance: 7.5, APIs: 5, Instructions: 48sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D77652 Relevance: 7.5, APIs: 5, Instructions: 48stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D785F1 Relevance: 7.5, APIs: 5, Instructions: 45memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78652 Relevance: 7.5, APIs: 5, Instructions: 45memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D213B0 Relevance: 7.5, APIs: 5, Instructions: 29COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78E74 Relevance: 7.5, APIs: 5, Instructions: 23memorysynchronizationCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA7648 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 90windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA6F1F Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA797D Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 66windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D9C304 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 19libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24C95 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 18libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24D94 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 18libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24D61 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 18libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA1072 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 18libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D993F5 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 18libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D776C5 Relevance: 6.3, APIs: 4, Instructions: 333COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D9E33E Relevance: 6.3, APIs: 4, Instructions: 307memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D983A8 Relevance: 6.3, APIs: 4, Instructions: 267COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D77A78 Relevance: 6.2, APIs: 4, Instructions: 231COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D76DF3 Relevance: 6.2, APIs: 4, Instructions: 202memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA9A63 Relevance: 6.1, APIs: 4, Instructions: 140COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8BA5F Relevance: 6.1, APIs: 4, Instructions: 111fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA8AC0 Relevance: 6.1, APIs: 4, Instructions: 109COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAADF1 Relevance: 6.1, APIs: 4, Instructions: 106windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA5175 Relevance: 6.1, APIs: 4, Instructions: 95COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D40BD0 Relevance: 6.1, APIs: 4, Instructions: 79COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78B9E Relevance: 6.1, APIs: 4, Instructions: 79memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D91A5B Relevance: 6.1, APIs: 4, Instructions: 78networkCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D7E1AF Relevance: 6.1, APIs: 3, Strings: 1, Instructions: 68stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78AF9 Relevance: 6.1, APIs: 4, Instructions: 65processCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D9667C Relevance: 6.1, APIs: 4, Instructions: 61networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D79023 Relevance: 6.1, APIs: 4, Instructions: 59windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D81652 Relevance: 6.1, APIs: 4, Instructions: 51sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAB57F Relevance: 6.0, APIs: 4, Instructions: 47COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAB8EF Relevance: 6.0, APIs: 4, Instructions: 40processCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D86E7C Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAC00C Relevance: 6.0, APIs: 4, Instructions: 31COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D22218 Relevance: 6.0, APIs: 4, Instructions: 23COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D78C5A Relevance: 6.0, APIs: 4, Instructions: 23threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D62187 Relevance: 6.0, APIs: 4, Instructions: 20COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D6219B Relevance: 6.0, APIs: 4, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D8B217 Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 201shareCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D32AB7 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 144sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D92882 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 97networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D82D91 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 88windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA6943 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 72windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA6B8F Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 64windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D82E9E Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 63windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D924CA Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 62networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D980A0 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 55networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D792E7 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 52windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D791DF Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 50windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D79264 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 49windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D781BC Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 22windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA5BEB Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 15windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|