Analysis Report https://www.firmadigital.go.cr/Bccr.Firma.Fva.InstaladoresMultiplataforma/windows/setup.exe
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
No high impact signatures.
Classification
Analysis Advice |
---|
Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later |
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis |
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | File opened: | Jump to behavior |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Process Injection1 | Masquerading1 | OS Credential Dumping | File and Directory Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel2 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Process Injection1 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Non-Application Layer Protocol2 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Application Layer Protocol3 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Ingress Tool Transfer1 | SIM Card Swap | Carrier Billing Fraud |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
No Antivirus matches |
---|
No Antivirus matches |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.firmadigital.go.cr | 201.193.215.154 | true | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
201.193.215.154 | www.firmadigital.go.cr | Costa Rica | 11830 | InstitutoCostarricensedeElectricidadyTelecomCR | false | |
201.193.44.121 | unknown | Costa Rica | 11830 | InstitutoCostarricensedeElectricidadyTelecomCR | false |
General Information |
---|
Joe Sandbox Version: | 31.0.0 Emerald |
Analysis ID: | 387940 |
Start date: | 15.04.2021 |
Start time: | 18:14:55 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 2m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://www.firmadigital.go.cr/Bccr.Firma.Fva.InstaladoresMultiplataforma/windows/setup.exe |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 3 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | UNKNOWN |
Classification: | unknown0.win@3/18@2/2 |
Cookbook Comments: |
|
Warnings: | Show All
|
Errors: |
|
No simulations |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 117192 |
Entropy (8bit): | 7.995478615012125 |
Encrypted: | true |
SSDEEP: | 3072:F2qSSwIm1m/QEBbgb1om2qSSwIm1m/QEBbgb1oQ:FJdwIm1m/QEOb1omJdwIm1m/QEOb1oQ |
MD5: | 2FEBC5EB397A71B7A4862D0DCC21CA5E |
SHA1: | 5568FBD6D7DB899850D3AAFF95FEC08952361678 |
SHA-256: | 2E9BE05B763D01CB0CD6FDE8BC64432A012AD3ECD9A6F3099DDE740A2D148A13 |
SHA-512: | B7D42B634F3B0CDC81CB94F281C8BB743BB98421AE54E21005637F762292D865EB1D71D43C4FF96AEE824527E9F7FB94FE5F5A4D35A22363A2A86AF8ABE0C414 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2954 |
Entropy (8bit): | 7.649362245726357 |
Encrypted: | false |
SSDEEP: | 48:islQxyVtYBUrgpQzp9yxglqPDnZOTLP+slQxyVtYBUrgpQzp9yxglqPDnZOTLPr:vlQxyVYggChcPDZYLlQxyVYggChcPDZe |
MD5: | 687FDBE2FE4A4379C6F15F54754D1C4E |
SHA1: | 975D3C6574EA8974FF39721F6F1EBE48BE6D4ED4 |
SHA-256: | E933E28D1F2BD5480D9D6ED13BCE93F25E54286F8F109C17CFFD5641E6DFD2E9 |
SHA-512: | EC91AF4B07395BE5CC7121855C46AD3D35B882D34BCB4EA234CCC0A7614F09F52CA03470698EB667C955A238A8342CF599C16C1E6ABA486B0727E09678D7286D |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 652 |
Entropy (8bit): | 3.121740994276266 |
Encrypted: | false |
SSDEEP: | 12:wwTJ6HkPlE99SNxAhUe0h9ZqwTJ6HkPlE99SNxAhUe0ht:fokPcUQUPh9ZtokPcUQUPht |
MD5: | A62CBB277930BD577A86B1CB0F678A28 |
SHA1: | 23EE194A40698DFC62E47810D5526681824D9722 |
SHA-256: | F24E3C6EFA7D18CF07D59AFF6F01CBAD5958142AC93D16A995A8B341F85EDF1D |
SHA-512: | 9991707D1166B0BF4787BEFDEB59580E59F168CA0E0FA0459594AA567C7257D55E4F1F49ECFA52560B0B2321CE726A702E66C8C83FE536E51219C252AC624956 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 676 |
Entropy (8bit): | 3.2362349915513615 |
Encrypted: | false |
SSDEEP: | 12:e9Q3Za4Qu/YJ4GA0OtQ3Za4Qu/YJ4GA0y:eoZa4Q6F4Za4Q6B |
MD5: | F168AA7277BFAA7472C4F71D844A9953 |
SHA1: | 357949FE2ECAF13BAAB9180ECEBEA938EF61F08B |
SHA-256: | 33BBFCC95A5955D76F3967C7F1F610E29F2B2029FA69D346AF9D1D150B29FA9F |
SHA-512: | 6788FEA0C72BA35690E2E37AF1908A489BE1CB1DD969A61984CED9CA44793380B7E0F87FADDDD9AC1954A86B00A85F0B51337B3DB88CD84F9AF20A28C9B5B6ED |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 30296 |
Entropy (8bit): | 1.8510662336982482 |
Encrypted: | false |
SSDEEP: | 192:r5ZyZJ2fW3t2ifUp3zM8PB5l1D5Lsf5zpWjX:rvuYudHFg5X5W5M |
MD5: | 47246D334B2B5F98285D70C34E0D6EFE |
SHA1: | 0E4E63C834FC0E2D24CAD8C483EEB10298B070F5 |
SHA-256: | C7EDF8D7D3E0A7D9725167FB9AD59699D6A8C794142E28C64A71D926B7D46B2D |
SHA-512: | 66080B9D7ED1A35D179FDEC637BDDB0D94DA9D9EB4D777F1BA56E43BF0D67F4B6545AA3F87554317B5A169BB91ACD63A58BC131AC8B763AD0968E92967E1765C |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24292 |
Entropy (8bit): | 1.6559201028610695 |
Encrypted: | false |
SSDEEP: | 48:IwVGcprsGwpaMG4pQQGrapbS6GQpBMBGHHpcnTGUp8iGzYpm9UGopD1jK9EVYtuO:rLZEQM6uBSCjx2xWeMqXScqsg |
MD5: | FAADD285F6B6C6DD183654BC37C860F2 |
SHA1: | AFA4BE7B9B1EC63E05BCD5D7B3B3333D63831B1E |
SHA-256: | D7A0CE7F14AF726454C2FB1294B60F0A854C1809BE97A27D3F5008A6311D5B28 |
SHA-512: | A6D14DDE9C0DB0384357F19D61CD43384A3F30599D6B37F89F2796F2ED0A041A4675E8539DEE9FC9E965C1B21283DB450CC5DBE935F79F2F00CEA39CA60D6DA3 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16984 |
Entropy (8bit): | 1.5630405197409787 |
Encrypted: | false |
SSDEEP: | 48:IwpGcprsGwpaIG4pQkGrapbSfGQpKRG7HpRmTGIpG:rvZEQY6yBSJAATSA |
MD5: | 6E6C3FBF28A8702EF2D3D970F9E008C7 |
SHA1: | 956411CF1600D152B33AC5A3A0B1EFEBEDE997FC |
SHA-256: | 3BB2C043208C1C380B6A943180B7E9B753DB5483E5BFFE7DC20132718408B7CA |
SHA-512: | 6CAA17EF07BF506948ED94B9AAB7B7922CBBD7B0FF052F5A2BAFDA4D442A2F3C7DD938CAAB960B0FF278DF7A3F95187DFEA222A9E94CC4EB221B947C3A2232E7 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 12105 |
Entropy (8bit): | 5.451485481468043 |
Encrypted: | false |
SSDEEP: | 192:x20iniOciwd1BtvjrG8tAGGGVWnvyJVUrUiki3ayimi5ezLCvJG1gwm3z:xPini/i+1Btvjy815ZVUwiki3ayimi5f |
MD5: | 9234071287E637F85D721463C488704C |
SHA1: | CCA09B1E0FBA38BA29D3972ED8DCECEFDEF8C152 |
SHA-256: | 65CC039890C7CEB927CE40F6F199D74E49B8058C3F8A6E22E8F916AD90EA8649 |
SHA-512: | 87D691987E7A2F69AD8605F35F94241AB7E68AD4F55AD384F1F0D40DC59FFD1432C758123661EE39443D624C881B01DCD228A67AFB8700FE5E66FC794A6C0384 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/httpErrorPagesScripts.js |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2747 |
Entropy (8bit): | 4.6225918717514975 |
Encrypted: | false |
SSDEEP: | 48:u7IEcY3V4VboHFmpsAgXtRkpNc7KaAkOtjH9gl:MioHsUXEG7XrOtul |
MD5: | B57B31E5FF628B5C319C902C1388164D |
SHA1: | 33E30D7CC1BC64D8C966B65F8701A3473CBF9A40 |
SHA-256: | 5F6258FE7C308635635E500903D767572372A0AEA4947C1A4BD61B4687F14036 |
SHA-512: | 077B400E107BD83A18AE46416658AD36561B2FEB87D967A957D8E67DDCB34AF83D198C5C1C422EC80803CC8B3DD70A788DD983F275B78B937FF3ECF89919C378 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/invalidcert.htm?SSLError=16777216 |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 748 |
Entropy (8bit): | 7.249606135668305 |
Encrypted: | false |
SSDEEP: | 12:6v/7/2QeZ7HVJ6o6yiq1p4tSQfAVFcm6R2HkZuU4fB4CsY4NJlrvMezoW2uONroc:GeZ6oLiqkbDuU4fqzTrvMeBBlE |
MD5: | C4F558C4C8B56858F15C09037CD6625A |
SHA1: | EE497CC061D6A7A59BB66DEFEA65F9A8145BA240 |
SHA-256: | 39E7DE847C9F731EAA72338AD9053217B957859DE27B50B6474EC42971530781 |
SHA-512: | D60353D3FBEA2992D96795BA30B20727B022B9164B2094B922921D33CA7CE1634713693AC191F8F5708954544F7648F4840BCD5B62CB6A032EF292A8B0E52A44 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/down.png |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2865 |
Entropy (8bit): | 5.408065735824215 |
Encrypted: | false |
SSDEEP: | 48:mPntofz4/i5DjktylVDJltwNWwzyRpigHAQLWnMxTUfMAbitRpigWYTGJywzwy/z:SE4a5HlVDJANSpiCWn5fmpiee1 |
MD5: | B8889E2796DD23C19DAA9BD263AE3C26 |
SHA1: | 3B0E097ADED1C821665DA56D72909A7DB5B922E4 |
SHA-256: | 8772217BBD9517BE03DD209D1323FC2D46108D39C97DF590F2C05BF53A173C7C |
SHA-512: | 24591C6428A90ACD22688989ED340068A3D977B2F7280D8BD002A6A43FBD1C22203FC34D24E1A3D7C6AAC7865BE36C50223563CDE31CED36F4324C5AF05016FB |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/invalidcert.js |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4720 |
Entropy (8bit): | 5.164796203267696 |
Encrypted: | false |
SSDEEP: | 96:z9UUiqRxqH211CUIRgRLnRynjZbRXkRPRk6C87Apsat/5/+mhPcF+5g+mOQb7A9o:JsUOG1yNlX6ZzWpHOWLia16Cb7bk |
MD5: | D65EC06F21C379C87040B83CC1ABAC6B |
SHA1: | 208D0A0BB775661758394BE7E4AFB18357E46C8B |
SHA-256: | A1270E90CEA31B46432EC44731BF4400D22B38EB2855326BF934FE8F1B169A4F |
SHA-512: | 8A166D26B49A5D95AEA49BC649E5EA58786A2191F4D2ADAC6F5FBB7523940CE4482D6A2502AA870A931224F215CB2010A8C9B99A2C1820150E4D365CAB28299E |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/errorPageStrings.js |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 29926 |
Entropy (8bit): | 5.629688416465816 |
Encrypted: | false |
SSDEEP: | 768:2ztZurROSBfIWD9UAv5OUcl2RCaNZ383b/gmBXqPsdEL:ld1mWJbROUclm9L8romBXqPbL |
MD5: | A6696B2897CA69CFE271504ADCC37E72 |
SHA1: | ABD3EA2B0D0A345E148A8F3503C1C30D221EE98B |
SHA-256: | F0F08719B27A039C0E9D402AD84AFC2CD8E6E9072A7D90FA0F8E33F47B9F7CEA |
SHA-512: | 857DBBBC33551CCBF63BFCD2DD03DEB8FE67E85B7753C31A82BC57028139692466D843AB1288896007CBD0BA994DDF1C80C0ACEDF1763EED0D0FC29F5AF2847B |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/shieldcritical.ico |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1612 |
Entropy (8bit): | 4.869554560514657 |
Encrypted: | false |
SSDEEP: | 24:5Y0bQ573pHpACtUZtJD0lFBopZleqw87xTe4D8FaFJ/Doz9AtjJgbCzg:5m73jcJqQep89TEw7Uxkk |
MD5: | DFEABDE84792228093A5A270352395B6 |
SHA1: | E41258C9576721025926326F76063C2305586F76 |
SHA-256: | 77B138AB5D0A90FF04648C26ADDD5E414CC178165E3B54A4CB3739DA0F58E075 |
SHA-512: | E256F603E67335151BB709294749794E2E3085F4063C623461A0B3DECBCCA8E620807B707EC9BCBE36DCD7D639C55753DA0495BE85B4AE5FB6BFC52AB4B284FD |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/newErrorPageTemplate.css |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17542 |
Entropy (8bit): | 5.098535207562026 |
Encrypted: | false |
SSDEEP: | 192:y0lg+tOJclE3toiTKNJP8TWhmikcl9DppA2ecyg39u3RwXx1hWrERtSb:yEtOJ5NS0TSkEVeKKRwXxTWriSb |
MD5: | 7AC3FA54ED226CA44CEB994249E5C306 |
SHA1: | 5FB7BE5D722DA876F62F0ADEF5C9A7D86D05688C |
SHA-256: | AA2C5D165A9D1C383EB954B2BAFD118B6FE5200AA7EE3D83501D6F08149B825F |
SHA-512: | B64351D281939F5B65C9BF0076C228182B86BDAC09959B8B2D530919AA747C840779EEA877B99938F2D33F359BB766095940974606D18C56B574B4691AE81BFF |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/shieldcheck.ico |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34485 |
Entropy (8bit): | 0.37324265468424395 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRg9lRA9lTS9lTy9lSSd9lSSd9lwT9lwMk9l2l9l2l9l/J:kBqoxKAuvScS+sMJQx9I9x1jKKVYtuMj |
MD5: | C060B77A44001D5E077E898D199FE108 |
SHA1: | 2529AF811E2BBC6076745FD2BD8A4959E7B64B89 |
SHA-256: | 70E1F25E0D6ACF1463E74B9130DACF3DB702061EAD764C95D92C6EA3DD150A5B |
SHA-512: | 15828D5359520C43FAF9584F21BBF9CDC1706DA23DF7C2392564D984C5B987CC0BDF8F0585C073CDB8564F5FEAD6FB2D11A929945035D28D88A87ACB4987D996 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25441 |
Entropy (8bit): | 0.27918767598683664 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRx/9lRJ9lTb9lTb9lSSU9lSSU9laAa/9laA:kBqoxxJhHWSVSEab |
MD5: | AB889A32AB9ACD33E816C2422337C69A |
SHA1: | 1190C6B34DED2D295827C2A88310D10A8B90B59B |
SHA-256: | 4D6EC54B8D244E63B0F04FBE2B97402A3DF722560AD12F218665BA440F4CEFDA |
SHA-512: | BD250855747BB4CEC61814D0E44F810156D390E3E9F120A12935EFDF80ACA33C4777AD66257CCA4E4003FEF0741692894980B9298F01C4CDD2D8A9C7BB522FB6 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13029 |
Entropy (8bit): | 0.4770103065047515 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9loZ9lo59lWqgK1KR4:kBqoIicqgK1KR4 |
MD5: | 4408A403469730F33F341CF9B62CE7C3 |
SHA1: | 0631305863598D735C6C87C95BAC8A4E075D9096 |
SHA-256: | 21C2D9A638DE15B5E4D7136DBDB1E082385DC80E5EE02D96062F08E6FF4521FD |
SHA-512: | 70D7782AB035E6D1BF5600790229EEC09B6AE343EA389A21540365A17FAFDD1828EBFEFDDAF2F9F4F0DB67D482D7A9C1D17F1B1DCFFDB0F8FA7BC29797DE60A2 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
No static file info |
---|
Network Behavior |
---|
Network Port Distribution |
---|
- Total Packets: 38
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 15, 2021 18:15:39.821194887 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:39.821320057 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.033006907 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.033054113 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.033202887 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.033230066 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.045227051 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.045310974 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.256097078 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.256123066 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259351015 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259370089 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259386063 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259406090 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259428978 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259447098 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259454966 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.259460926 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.259506941 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.259515047 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.259519100 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.259524107 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.260193110 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260215044 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260234118 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260247946 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.260251045 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260272026 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.260272980 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260282993 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.260296106 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260301113 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.260312080 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:40.260318995 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.260364056 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:40.879971981 CEST | 49706 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:40.880939007 CEST | 49707 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:41.094810963 CEST | 80 | 49706 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.095056057 CEST | 49706 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:41.096584082 CEST | 80 | 49707 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.096676111 CEST | 49707 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:41.096739054 CEST | 49706 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:41.097265005 CEST | 49707 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:41.311973095 CEST | 80 | 49706 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.312705994 CEST | 80 | 49706 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.312735081 CEST | 80 | 49706 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.312844038 CEST | 49706 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:41.312980890 CEST | 80 | 49707 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.313885927 CEST | 80 | 49707 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.313905954 CEST | 80 | 49707 | 201.193.44.121 | 192.168.2.4 |
Apr 15, 2021 18:15:41.313988924 CEST | 49707 | 80 | 192.168.2.4 | 201.193.44.121 |
Apr 15, 2021 18:15:42.139261961 CEST | 49705 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:42.140939951 CEST | 49704 | 443 | 192.168.2.4 | 201.193.215.154 |
Apr 15, 2021 18:15:42.349740982 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:42.349766970 CEST | 443 | 49705 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:42.351505995 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Apr 15, 2021 18:15:42.352361917 CEST | 443 | 49704 | 201.193.215.154 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 15, 2021 18:15:30.714750051 CEST | 59042 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:30.772171974 CEST | 53 | 59042 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:31.032641888 CEST | 56483 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:31.081615925 CEST | 53 | 56483 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:31.251046896 CEST | 51025 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:31.300293922 CEST | 53 | 51025 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:38.363951921 CEST | 61516 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:38.437588930 CEST | 53 | 61516 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:39.414232016 CEST | 49182 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:39.796711922 CEST | 53 | 49182 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:40.443454027 CEST | 59920 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:40.878665924 CEST | 53 | 59920 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:41.553719044 CEST | 57458 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:41.618272066 CEST | 53 | 57458 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:57.587415934 CEST | 50579 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:57.647579908 CEST | 53 | 50579 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:15:59.222127914 CEST | 51703 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:15:59.273767948 CEST | 53 | 51703 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:16:00.183634043 CEST | 65248 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:16:00.232521057 CEST | 53 | 65248 | 8.8.8.8 | 192.168.2.4 |
Apr 15, 2021 18:16:01.575390100 CEST | 53723 | 53 | 192.168.2.4 | 8.8.8.8 |
Apr 15, 2021 18:16:01.625521898 CEST | 53 | 53723 | 8.8.8.8 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Apr 15, 2021 18:15:39.414232016 CEST | 192.168.2.4 | 8.8.8.8 | 0x1da5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Apr 15, 2021 18:15:40.443454027 CEST | 192.168.2.4 | 8.8.8.8 | 0xe934 | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Apr 15, 2021 18:15:39.796711922 CEST | 8.8.8.8 | 192.168.2.4 | 0x1da5 | No error (0) | 201.193.215.154 | A (IP address) | IN (0x0001) | ||
Apr 15, 2021 18:15:40.878665924 CEST | 8.8.8.8 | 192.168.2.4 | 0xe934 | No error (0) | 201.193.44.121 | A (IP address) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.4 | 49706 | 201.193.44.121 | 80 | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Apr 15, 2021 18:15:41.096739054 CEST | 233 | OUT | |
Apr 15, 2021 18:15:41.312705994 CEST | 235 | IN |