Play interactive tourEdit tour

Analysis Report http://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3e

Overview

General Information

Sample URL:http://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3e
Analysis ID:346223

Most interesting Screenshot:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • iexplore.exe (PID: 2092 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596)
    • iexplore.exe (PID: 4176 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2092 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Compliance:

barindex
Uses new MSVCR Dlls
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dllJump to behavior
Uses secure TLS version for HTTPS connections
Source: unknownHTTPS traffic detected: 31.13.92.36:443 -> 192.168.2.5:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 31.13.92.36:443 -> 192.168.2.5:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 31.13.92.36:443 -> 192.168.2.5:49725 version: TLS 1.2
Source: imagestore.dat.2.drString found in binary or memory: $https://www.facebook.com/favicon.ico~ equals www.facebook.com (Facebook)
Source: msapplication.xml0.1.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
Source: msapplication.xml0.1.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
Source: msapplication.xml5.1.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
Source: msapplication.xml5.1.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
Source: msapplication.xml7.1.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x3a3f2dc2,0x01d6f6c7</date><accdate>0x3a3f2dc2,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
Source: msapplication.xml7.1.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x3a3f2dc2,0x01d6f6c7</date><accdate>0x3a3f2dc2,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
Source: ~DFBDADA6E59FDBD3D8.TMP.1.drString found in binary or memory: https://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3e equals www.facebook.com (Facebook)
Source: {64D42622-62BA-11EB-90E5-ECF4BB570DC9}.dat.1.drString found in binary or memory: https://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3eRoot Entry equals www.facebook.com (Facebook)
Source: unknownDNS traffic detected: queries for: www.facebook.com
Source: msapplication.xml.1.drString found in binary or memory: http://www.amazon.com/
Source: msapplication.xml1.1.drString found in binary or memory: http://www.google.com/
Source: msapplication.xml2.1.drString found in binary or memory: http://www.live.com/
Source: msapplication.xml3.1.drString found in binary or memory: http://www.nytimes.com/
Source: msapplication.xml4.1.drString found in binary or memory: http://www.reddit.com/
Source: msapplication.xml5.1.drString found in binary or memory: http://www.twitter.com/
Source: msapplication.xml6.1.drString found in binary or memory: http://www.wikipedia.com/
Source: msapplication.xml7.1.drString found in binary or memory: http://www.youtube.com/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 31.13.92.36:443 -> 192.168.2.5:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 31.13.92.36:443 -> 192.168.2.5:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 31.13.92.36:443 -> 192.168.2.5:49725 version: TLS 1.2
Source: classification engineClassification label: clean0.win@3/17@2/1
Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{64D42620-62BA-11EB-90E5-ECF4BB570DC9}.datJump to behavior
Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Temp\~DFAAF49A4794139171.TMPJump to behavior
Source: C:\Program Files\internet explorer\iexplore.exeFile read: C:\Users\desktop.iniJump to behavior
Source: unknownProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: unknownProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2092 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2092 CREDAT:17410 /prefetch:2Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dllJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 346223 URL: http://www.facebook.com/aja... Startdate: 29/01/2021 Architecture: WINDOWS Score: 0 11 www.facebook.com 2->11 13 star-mini.c10r.facebook.com 2->13 6 iexplore.exe 1 74 2->6         started        process3 process4 8 iexplore.exe 33 6->8         started        dnsIp5 15 star-mini.c10r.facebook.com 31.13.92.36, 443, 49722, 49723 FACEBOOKUS Ireland 8->15 17 www.facebook.com 8->17

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand
SourceDetectionScannerLabelLink
http://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3e0%VirustotalBrowse
http://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3e0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.wikipedia.com/0%URL Reputationsafe
http://www.wikipedia.com/0%URL Reputationsafe
http://www.wikipedia.com/0%URL Reputationsafe
http://www.wikipedia.com/0%URL Reputationsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
star-mini.c10r.facebook.com
31.13.92.36
truefalse
    high
    www.facebook.com
    unknown
    unknownfalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      http://www.wikipedia.com/msapplication.xml6.1.drfalse
      • URL Reputation: safe
      • URL Reputation: safe
      • URL Reputation: safe
      • URL Reputation: safe
      unknown
      http://www.amazon.com/msapplication.xml.1.drfalse
        high
        http://www.nytimes.com/msapplication.xml3.1.drfalse
          high
          http://www.live.com/msapplication.xml2.1.drfalse
            high
            http://www.reddit.com/msapplication.xml4.1.drfalse
              high
              http://www.twitter.com/msapplication.xml5.1.drfalse
                high
                http://www.youtube.com/msapplication.xml7.1.drfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  31.13.92.36
                  unknownIreland
                  32934FACEBOOKUSfalse

                  General Information

                  Joe Sandbox Version:31.0.0 Emerald
                  Analysis ID:346223
                  Start date:29.01.2021
                  Start time:21:16:17
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 2m 57s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://www.facebook.com/ajax/bnzai?__a=1&__beoa=0&__ccg=GOOD&__comet_req=1&__hsi=6923245573667911923-0&__pc=EXP2:comet_pkg&__req=am&__rev=1003240513&__s=:dkokxu:u9vl6u&__spin_b=trunk&__spin_r=1003240513&__spin_t=1611943723&__user=686000159&dpr=1&fb_dtsg=AQEu0OP1QKud:AQHoZW_QMXU6&jazoest=22005&ph=C3e
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:15
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@3/17@2/1
                  Cookbook Comments:
                  • Adjust boot time
                  • Enable AMSI
                  Warnings:
                  • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, ielowutil.exe, backgroundTaskHost.exe, SgrmBroker.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 168.61.161.212, 40.88.32.150, 88.221.62.148, 23.210.248.85, 51.11.168.160, 152.199.19.161, 92.122.213.247, 92.122.213.194, 51.103.5.159
                  • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, arc.msn.com.nsatc.net, ie9comview.vo.msecnd.net, skypedataprdcolcus17.cloudapp.net, e1723.g.akamaiedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, wns.notify.windows.com.akadns.net, arc.msn.com, vip1-par02p.wns.notify.trafficmanager.net, e11290.dspg.akamaiedge.net, iecvlist.microsoft.com, skypedataprdcoleus15.cloudapp.net, go.microsoft.com, emea1.wns.notify.trafficmanager.net, blobcollector.events.data.trafficmanager.net, go.microsoft.com.edgekey.net, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, cs9.wpc.v0cdn.net
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{64D42620-62BA-11EB-90E5-ECF4BB570DC9}.dat
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:Microsoft Word Document
                  Category:dropped
                  Size (bytes):30296
                  Entropy (8bit):1.8592430237211452
                  Encrypted:false
                  SSDEEP:96:rvZUZm2Z9WoStoPbfo/gnKMo5/qotlQo4xfoggu6X:rvZUZm2Z9WoStoTfo/xMoco0o2fog8X
                  MD5:ED3E0478C01C8467D1A3A096982766C4
                  SHA1:5EB0608CC3C45C6EE1B24CA13B9FA541451C5797
                  SHA-256:1D4F3AEE74A1117E9E733AEA1D7717DFF6FCEC09358A779681A9AE3D578B08C5
                  SHA-512:00D12AF64AC3E84FA2FDF752E6D8DB61DB48137A92A13265CEE614952A8B1521CDE8AF022B3ED234E570347B174578E9C0B1A3E0C4559B3DABB7417250D3F07E
                  Malicious:false
                  Reputation:low
                  Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{64D42622-62BA-11EB-90E5-ECF4BB570DC9}.dat
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:Microsoft Word Document
                  Category:dropped
                  Size (bytes):24712
                  Entropy (8bit):1.7397545234965146
                  Encrypted:false
                  SSDEEP:96:rRZSQG6oBSOFjx21akW1CM1FYBPj0o4abr4fHg:rRZSQG6okOFjx21akW1CM1FYBPjhBgg
                  MD5:9C3C84417123EDFD89A699CA96269B25
                  SHA1:E47BE888C49F0BC7735104D71475FDF607DD570E
                  SHA-256:76B9AB1E10EC181AB508B64EE71C61C93A161D467F11E6C7BA345C4A3EA1F4BC
                  SHA-512:03C125AC8DB29AB2C10623590C19B6FFF5DBF3B1FC882B34EBD95B7B3F7B9ADFD43F974814135FB2F430F24D5A10F3092C24ADFE170BBAFA3B4B1F8E12726B6C
                  Malicious:false
                  Reputation:low
                  Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{64D42623-62BA-11EB-90E5-ECF4BB570DC9}.dat
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:Microsoft Word Document
                  Category:dropped
                  Size (bytes):16984
                  Entropy (8bit):1.5640937166004127
                  Encrypted:false
                  SSDEEP:48:Iw9Gcpr4Gwpa1G4pQGGrapbS1rGQpKbG7HpR8sTGIpG:rjZgQn6IBS1FAaT84A
                  MD5:9D11C4AEAD3ABEDE23FF32FF6090BD8A
                  SHA1:8BAEF6746F75BBC239A764BDCCC91B64C014F9FD
                  SHA-256:4018EB9B511346E8525621D64CC2557FE4C3B588244905139D8ADCDB27E62B3B
                  SHA-512:FEFAED1506F5D7DD3067ABB5E0C22626D9A848F52E3E9A3F6110EEE6054BE5F16F840E6E012AB17F8740522633606EB3746C650430EF114BD1BA90036A5DD9A5
                  Malicious:false
                  Reputation:low
                  Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):657
                  Entropy (8bit):5.07212600329416
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxOEuuTuonWimI002EtM3MHdNMNxOEuuTuonWimI00ONVbkEtMb:2d6NxOMqoSZHKd6NxOMqoSZ7Qb
                  MD5:1DB11F3AAD54D8648ACD9CEFC2846232
                  SHA1:993542FC25939061135A1579CDC137023B6BE5A2
                  SHA-256:DB297CE7F1E614AD6D4FB62E98A27ACA411D30C42E2ECBA7A9E14B4019A785CB
                  SHA-512:E2ACF7C4B9CB918E2FC80DAB03F1EB8AF16B4DC4891665AD95DFD0EB9FFD8D47ADB0E03848F9F34818CC99FEB66E8FCC8CEC18B360A51FDBE43E0FD0FB031DF3
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):654
                  Entropy (8bit):5.0948841167433
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxe2kvBhnWimI002EtM3MHdNMNxe2kvBhnWimI00ONkak6EtMb:2d6NxryBhSZHKd6NxryBhSZ72a7b
                  MD5:5FA4F13AE302F045CA0F61785A2ECD53
                  SHA1:6FFF3DC73D00CA7CBA448CBACD751BD5D4E8144F
                  SHA-256:D0CC828BE951C1F049534EC2030FD3FA113E42C55450532F9D75C333E02A84D7
                  SHA-512:DD5404CE52D79850B2BEB18CB5C4AD09785B4E84D8A448BA8538F4DD2915CFA7E3898B2E0968F346A0E98EE4B493036DBE3B7F3557A490B4E8F5CD25E9A4A11D
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.amazon.com/"/><date>0x3a35a45c,0x01d6f6c7</date><accdate>0x3a35a45c,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.amazon.com/"/><date>0x3a35a45c,0x01d6f6c7</date><accdate>0x3a35a45c,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Amazon.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):663
                  Entropy (8bit):5.083014178847117
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxvL9nWimI002EtM3MHdNMNxvL9nWimI00ONmZEtMb:2d6NxvJSZHKd6NxvJSZ7Ub
                  MD5:964B35B4846B6A6ACF5FAA4BB54F03D8
                  SHA1:D15E20E72F251750A6B72F125E45D751D98E9DD2
                  SHA-256:02A4AD70268FC59F613171C5C0BE8198C30EFE5C00DF208CEFE4A4520D7065EB
                  SHA-512:2DE47B057E9A8C9C25194D23F61AA0BF4D1836B298A241E1A2C7653D3B9CC69406A8463103F7257E42A06A9D67EA7C8B7A4A76747C4C70760CF501951F9814F8
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.wikipedia.com/"/><date>0x3a3f2dc2,0x01d6f6c7</date><accdate>0x3a3f2dc2,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.wikipedia.com/"/><date>0x3a3f2dc2,0x01d6f6c7</date><accdate>0x3a3f2dc2,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Wikipedia.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):648
                  Entropy (8bit):5.071036164220223
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxi0xbxonWimI002EtM3MHdNMNxi0xbxonWimI00ONd5EtMb:2d6NxfB+SZHKd6NxfB+SZ7njb
                  MD5:BC681CB60CC7B51E6729F7A127419D9B
                  SHA1:4EB16ACD47065908DCDF9FD1E32EF50C41ADEA92
                  SHA-256:83ADEE0761A7485AA173ECDF6D59E876073275957ACDF4E929C5A82BC562ABB0
                  SHA-512:D60C55C1DF73F554C5E3E080E654315CE98E9DA2ECD496138CD412C0A9F9C866BC8DD032769FAF4788BF01A363F1E417A739113D6330A82916FAC95F961989E1
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.live.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.live.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Live.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):657
                  Entropy (8bit):5.0991278075972675
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxhGw9nWimI002EtM3MHdNMNxhGw9nWimI00ON8K075EtMb:2d6NxQISZHKd6NxQISZ7uKajb
                  MD5:265199DD1469BADEF1841269A6F3BE27
                  SHA1:C59DD74F240FA0D0B02BE6CEE21DE4A633C156E0
                  SHA-256:E8DC1DA532F9636B6E2BE09274CCE4200CE3761F0B5C9EA7D2BC181979A5AD79
                  SHA-512:2C8E931227528EC3BCB7F389F92C6A9F9984C08A895B235BFA3B982131EA689DC6E7DD3A0CDBAC6998463EE4DD9B7199021D49C2FCC9787FCE9FD3E6311563A7
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x3a3f2dc2,0x01d6f6c7</date><accdate>0x3a3f2dc2,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x3a3f2dc2,0x01d6f6c7</date><accdate>0x3a3f2dc2,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):654
                  Entropy (8bit):5.075772359320338
                  Encrypted:false
                  SSDEEP:12:TMHdNMNx0nuuTuonWimI002EtM3MHdNMNx0nuuTuonWimI00ONxEtMb:2d6Nx0BqoSZHKd6Nx0BqoSZ7Vb
                  MD5:E1AEE9A8A3E60091AD9F1DD3AE8957E1
                  SHA1:5EA99FDF523D5D71200B761B3A282D2BEBA88C78
                  SHA-256:F36CB9E9823FECEF603103B33171C1ED4D43E4435220F965D4E2EC05E7770922
                  SHA-512:CA4889461BC583718391A312EECB561179A0DDE132B753339917F81DD851F37B6B53093872E72D8432B53811A5D21E6655EEFE7514CCB1034328CE12F5D5F27A
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.reddit.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.reddit.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Reddit.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):657
                  Entropy (8bit):5.111700954951745
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxxuuTuonWimI002EtM3MHdNMNxxuuTuonWimI00ON6Kq5EtMb:2d6NxvqoSZHKd6NxvqoSZ7ub
                  MD5:E51FEFF218691AA0EA7615FDC85A5216
                  SHA1:01C114253BCCA323D8BB9AF1FE48B3FE25191967
                  SHA-256:032E47305051CD127CD714F6B5C8E2E61DBC90D438A76EF0D74EFDFA7A70BBF9
                  SHA-512:42C5F0D1996D41388A6BACDDD0E172A4E5DD95DA2487276088AC9D8415C483947E6E58BF327CCA6B8B7BEE96558BD6FAABDC3CCC265D0570352D3270E1101961
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.nytimes.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.nytimes.com/"/><date>0x3a3ccb54,0x01d6f6c7</date><accdate>0x3a3ccb54,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\NYTimes.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):660
                  Entropy (8bit):5.072615260383952
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxc0xbxonWimI002EtM3MHdNMNxc0xbxonWimI00ONVEtMb:2d6NxBB+SZHKd6NxBB+SZ71b
                  MD5:979CE5F3B3A5CCA71FEF64C89F5C36E8
                  SHA1:AF5A9675C0308824D70829B2EF1EAFC8E9F966EE
                  SHA-256:DCCA7891E2AFDC4C8CFF0E30993DAB094AFE357C5087D754DFD0ADE69FC8BF88
                  SHA-512:7E51D1B4254ABFD8636F19E510D96677932B7740D366884C79B6B0E92D38F62F2FBFE62A0BDD5E89B73C725DEA33A0AF7A4A09B8627DD8F1F38F4EBA70699830
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                  Category:dropped
                  Size (bytes):654
                  Entropy (8bit):5.056663683735949
                  Encrypted:false
                  SSDEEP:12:TMHdNMNxfn0xbxonWimI002EtM3MHdNMNxfn0xbxonWimI00ONe5EtMb:2d6Nx8B+SZHKd6Nx8B+SZ7Ejb
                  MD5:E6F76EA7567E1422F58144047FD0A67B
                  SHA1:8C127E789D99BE98D135342213338E84F382E4AC
                  SHA-256:30B32C930210CCF376DF21BAF204C48120E52CD948CC5F6F7FD25EF2081902F3
                  SHA-512:B90DD035BA88BBBEFC2AEF4538558DB8BF2E27280DA912A03607B4CE642850DD4A93745807F233EE59A22EDEC601E0E83E3B05BB73FA2E290406AE746AB14196
                  Malicious:false
                  Reputation:low
                  Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.google.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.google.com/"/><date>0x3a3a690f,0x01d6f6c7</date><accdate>0x3a3a690f,0x01d6f6c7</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Google.url"/></tile></msapplication></browserconfig>..
                  C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
                  Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                  File Type:data
                  Category:modified
                  Size (bytes):1260
                  Entropy (8bit):3.298934685955963
                  Encrypted:false
                  SSDEEP:6:mYFMGuBicAMlGR2G6RjVChRj/tjRj/tjRj/tjRj/t9ZItjRc8tjROctjRIMtPCbo:HapplOgCrZvxRHtS5t
                  MD5:F24ED075BFEA86412792EC4A6E8FF38E
                  SHA1:23A0AF42BE1371F9A6D544A73E27D4F0E3FD90AC
                  SHA-256:A7794DCE46366D0DB776EF637998EBE452DE4954552487CD9F7ABF6953459D0C
                  SHA-512:49B74FD2E189E4CECF0ABBCA1BAC070BAEF8D0A57BAA07C40DA3619448E91132DCEF8E60B9908148FB1882851BD2846FC43AC6CDA66BBECE018FA883F36AD1BD
                  Malicious:false
                  Reputation:low
                  Preview: $.h.t.t.p.s.:././.w.w.w...f.a.c.e.b.o.o.k...c.o.m./.f.a.v.i.c.o.n...i.c.o.~............... .h.......(....... ..... ..............................................................................................`E.bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..`G..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..N:..N:..........N:..N:..X@..bH..bH..........bH..bH..bH..bH..bH.............................bH..bH..........bH..bH..bH..bH..bH..............................bH..bH..........bH..bH..bH..bH..bH..bH..bH..........]D..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........~o..N:..N:..bH..bH..........bH..bH..bH..bH..bH..bH..bH.....................bH..bH..........bH..bH..bH..bH..bH..bH..bH..mV..................bH..bH..........]D..bH..bH..bH..bH..bH.
                  C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\favicon[1].png
                  Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                  File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                  Category:downloaded
                  Size (bytes):1150
                  Entropy (8bit):3.096842379312471
                  Encrypted:false
                  SSDEEP:6:9G6RjVChRj/tjRj/tjRj/tjRj/t9ZItjRc8tjROctjRIMtPCbtHuOvt7H+tqt5bH:jCrZvxRHn
                  MD5:7E765F1C4CB20568118ED55C0B6FFA91
                  SHA1:F93262E997539B566510FF749C97CA8A4768D8C9
                  SHA-256:5678EE6A1F605D6ADA6230003A8D9C182869E1F40D02D414B368CC820C9A97B8
                  SHA-512:0072228254406F41CE31EA036A36FBCF0E01A2886AE07DDB93E89C9E69830C83FFD16475088ECE9CB0A3A3344B983141577749EE0C8E05C943AE67786F9F1ECB
                  Malicious:false
                  Reputation:low
                  IE Cache URL:https://www.facebook.com/favicon.ico
                  Preview: ............ .h.......(....... ..... ..............................................................................................`E.bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..`G..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..........bH..bH..bH..bH..bH..N:..N:..........N:..N:..X@..bH..bH..........bH..bH..bH..bH..bH.............................bH..bH..........bH..bH..bH..bH..bH..............................bH..bH..........bH..bH..bH..bH..bH..bH..bH..........]D..bH..bH..bH..bH..........bH..bH..bH..bH..bH..bH..bH..........~o..N:..N:..bH..bH..........bH..bH..bH..bH..bH..bH..bH.....................bH..bH..........bH..bH..bH..bH..bH..bH..bH..mV..................bH..bH..........]D..bH..bH..bH..bH..bH..bH..bH..bH..bH..bH..bH..bH..]D..........M6.N:..N:..N:..N:..N:..N:..N:..N:..N
                  C:\Users\user\AppData\Local\Temp\~DF231DE0EA67C2E21F.TMP
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):25441
                  Entropy (8bit):0.27918767598683664
                  Encrypted:false
                  SSDEEP:24:c9lLh9lLh9lIn9lIn9lRx/9lRJ9lTb9lTb9lSSU9lSSU9laAa/9laA:kBqoxxJhHWSVSEab
                  MD5:AB889A32AB9ACD33E816C2422337C69A
                  SHA1:1190C6B34DED2D295827C2A88310D10A8B90B59B
                  SHA-256:4D6EC54B8D244E63B0F04FBE2B97402A3DF722560AD12F218665BA440F4CEFDA
                  SHA-512:BD250855747BB4CEC61814D0E44F810156D390E3E9F120A12935EFDF80ACA33C4777AD66257CCA4E4003FEF0741692894980B9298F01C4CDD2D8A9C7BB522FB6
                  Malicious:false
                  Reputation:low
                  Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  C:\Users\user\AppData\Local\Temp\~DFAAF49A4794139171.TMP
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):13029
                  Entropy (8bit):0.4812253803031642
                  Encrypted:false
                  SSDEEP:24:c9lLh9lLh9lIn9lIn9loST9loST9lWSHZjl0Zj0C0CzR0ZzRE:kBqoISUSKSHZjlAj0C0ClAlE
                  MD5:E8C2F01B6ED0A422C112D9FEAC193212
                  SHA1:F9E567097090520FCB4A4EF4279D72C562182ECE
                  SHA-256:DC1635FF340D9B4BAD7104E4061EEB0F7E5EAB1C959FCD8C3D885D9935E3A299
                  SHA-512:4AA80902FA28FD3FAE70EA927E3C2501CE78B02AF3DD831D4A892B426C8E473E7E5BF917CCED2AF584FD4FC76C8CB04D623145687936DAA8C1B8F5F3CC68B4E5
                  Malicious:false
                  Reputation:low
                  Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                  C:\Users\user\AppData\Local\Temp\~DFBDADA6E59FDBD3D8.TMP
                  Process:C:\Program Files\internet explorer\iexplore.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):34905
                  Entropy (8bit):0.4438650500958105
                  Encrypted:false
                  SSDEEP:96:kBqoxKAuvScS+mg1A1h1K1DPj0o4abr4fO:kBqoxKAuqR+mg1A1h1K1DPjhBd
                  MD5:96CF1BB0AD7B8760F29F6ED1CE8A9EBC
                  SHA1:E54828DB9F6393F333EAF2F4939FB3EDCA6271DE
                  SHA-256:22B80B68116FF136F85D7599089CB92E717640159192F0C5F2C133D0AC0AF3CA
                  SHA-512:C3B5AE569DE3D5737A29F7F389E9B008633CC4118A169A989AFBE6313F478EB2B96549BEBD758E53EE733BCE7EB7A97D57B570FC7BD9D774C9B005993249CD79
                  Malicious:false
                  Reputation:low
                  Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................

                  Static File Info

                  No static file info

                  Network Behavior

                  Download Network PCAP: filteredfull

                  Network Port Distribution

                  • Total Packets: 62
                  • 443 (HTTPS)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 29, 2021 21:17:08.607692957 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.608632088 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.647797108 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.647993088 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.648369074 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.648449898 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.653548002 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.653564930 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.693473101 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.693938017 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694181919 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694224119 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694248915 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694282055 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.694288015 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694323063 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694334030 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.694339037 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.694348097 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.694360971 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.694381952 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.694400072 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.733381987 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.733486891 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.739300966 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.739371061 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.739463091 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.773281097 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.773344040 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.773464918 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.773477077 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.773561001 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.773633957 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.773663998 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.773703098 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.773720026 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.773778915 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.774688005 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.774768114 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.779228926 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.779249907 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.779371977 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.779387951 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.779401064 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.779441118 CET49723443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.779546022 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.779647112 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.779726028 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:08.854598045 CET4434972331.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.857219934 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.874695063 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:08.874842882 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:09.064620018 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:09.105551004 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:09.105576992 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:09.105910063 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:09.201278925 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:09.201428890 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:09.201478958 CET4434972231.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:09.201550007 CET49722443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.067066908 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.109169960 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.109325886 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.128354073 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.168292999 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.169001102 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.169047117 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.169078112 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.169086933 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.169116020 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.169131041 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.201261997 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.241473913 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.241542101 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.241631985 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.250866890 CET49725443192.168.2.531.13.92.36
                  Jan 29, 2021 21:17:25.290735960 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.392071962 CET4434972531.13.92.36192.168.2.5
                  Jan 29, 2021 21:17:25.392184973 CET49725443192.168.2.531.13.92.36
                  TimestampSource PortDest PortSource IPDest IP
                  Jan 29, 2021 21:17:02.086458921 CET6529653192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:02.137259960 CET53652968.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:03.049823999 CET6318353192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:03.097990990 CET53631838.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:04.019006968 CET6015153192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:04.067162037 CET53601518.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:04.972074986 CET5696953192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:05.020090103 CET53569698.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:07.397732973 CET5516153192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:07.455259085 CET53551618.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:08.540086985 CET5475753192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:08.598112106 CET53547578.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:25.003170013 CET4999253192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:25.062213898 CET53499928.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:27.194133043 CET6007553192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:27.251593113 CET53600758.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:29.206895113 CET5501653192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:29.254760027 CET53550168.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:37.409466982 CET6434553192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:37.457647085 CET53643458.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:38.114922047 CET5712853192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:38.174447060 CET53571288.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:38.406128883 CET6434553192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:38.454150915 CET53643458.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:39.124264956 CET5712853192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:39.175045967 CET53571288.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:39.420466900 CET6434553192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:39.477210045 CET53643458.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:39.546163082 CET5479153192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:39.603600025 CET53547918.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:40.139206886 CET5712853192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:40.189946890 CET53571288.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:41.420794964 CET6434553192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:41.468982935 CET53643458.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:42.139328957 CET5712853192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:42.198407888 CET53571288.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:45.436489105 CET6434553192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:45.484390974 CET53643458.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:46.155288935 CET5712853192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:46.206090927 CET53571288.8.8.8192.168.2.5
                  Jan 29, 2021 21:17:51.308775902 CET5046353192.168.2.58.8.8.8
                  Jan 29, 2021 21:17:51.360008955 CET53504638.8.8.8192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                  Jan 29, 2021 21:17:08.540086985 CET192.168.2.58.8.8.80x8f34Standard query (0)www.facebook.comA (IP address)IN (0x0001)
                  Jan 29, 2021 21:17:25.003170013 CET192.168.2.58.8.8.80x53a5Standard query (0)www.facebook.comA (IP address)IN (0x0001)
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                  Jan 29, 2021 21:17:08.598112106 CET8.8.8.8192.168.2.50x8f34No error (0)www.facebook.comstar-mini.c10r.facebook.comCNAME (Canonical name)IN (0x0001)
                  Jan 29, 2021 21:17:08.598112106 CET8.8.8.8192.168.2.50x8f34No error (0)star-mini.c10r.facebook.com31.13.92.36A (IP address)IN (0x0001)
                  Jan 29, 2021 21:17:25.062213898 CET8.8.8.8192.168.2.50x53a5No error (0)www.facebook.comstar-mini.c10r.facebook.comCNAME (Canonical name)IN (0x0001)
                  Jan 29, 2021 21:17:25.062213898 CET8.8.8.8192.168.2.50x53a5No error (0)star-mini.c10r.facebook.com31.13.92.36A (IP address)IN (0x0001)
                  TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                  Jan 29, 2021 21:17:08.694248915 CET31.13.92.36443192.168.2.549723CN=*.facebook.com, O="Facebook, Inc.", L=Menlo Park, ST=California, C=US CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Dec 22 01:00:00 CET 2020 Tue Oct 22 14:00:00 CEST 2013Mon Mar 22 00:59:59 CET 2021 Sun Oct 22 14:00:00 CEST 2028771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                  CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Oct 22 14:00:00 CEST 2013Sun Oct 22 14:00:00 CEST 2028
                  Jan 29, 2021 21:17:08.694348097 CET31.13.92.36443192.168.2.549722CN=*.facebook.com, O="Facebook, Inc.", L=Menlo Park, ST=California, C=US CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Dec 22 01:00:00 CET 2020 Tue Oct 22 14:00:00 CEST 2013Mon Mar 22 00:59:59 CET 2021 Sun Oct 22 14:00:00 CEST 2028771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                  CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Oct 22 14:00:00 CEST 2013Sun Oct 22 14:00:00 CEST 2028
                  Jan 29, 2021 21:17:25.169078112 CET31.13.92.36443192.168.2.549725CN=*.facebook.com, O="Facebook, Inc.", L=Menlo Park, ST=California, C=US CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Dec 22 01:00:00 CET 2020 Tue Oct 22 14:00:00 CEST 2013Mon Mar 22 00:59:59 CET 2021 Sun Oct 22 14:00:00 CEST 2028771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
                  CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Oct 22 14:00:00 CEST 2013Sun Oct 22 14:00:00 CEST 2028

                  Code Manipulations

                  Statistics

                  CPU Usage

                  01020304050s020406080100

                  Click to jump to process

                  Memory Usage

                  01020304050s0.0010203040MB

                  Click to jump to process

                  Behavior

                  Click to jump to process

                  System Behavior

                  Start time:21:17:06
                  Start date:29/01/2021
                  Path:C:\Program Files\internet explorer\iexplore.exe
                  Wow64 process (32bit):false
                  Commandline:'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
                  Imagebase:0x7ff73c2e0000
                  File size:823560 bytes
                  MD5 hash:6465CB92B25A7BC1DF8E01D8AC5E7596
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Start time:21:17:07
                  Start date:29/01/2021
                  Path:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                  Wow64 process (32bit):true
                  Commandline:'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2092 CREDAT:17410 /prefetch:2
                  Imagebase:0xeb0000
                  File size:822536 bytes
                  MD5 hash:071277CC2E3DF41EEEA8013E2AB58D5A
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Disassembly