Analysis Report http://icon-adc.realsh.xyz
Overview
General Information
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
Analysis Advice |
---|
Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later |
Some HTTP requests failed (404). It is likely the sample will exhibit less behavior |
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Source: | File opened: | Jump to behavior |
Networking: |
---|
Performs DNS queries to domains with low reputation |
Source: | DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Process Injection1 | Masquerading1 | OS Credential Dumping | File and Directory Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Non-Application Layer Protocol3 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Process Injection1 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Application Layer Protocol3 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Ingress Tool Transfer3 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
icon-adc.realsh.xyz | 104.21.20.18 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.20.18 | icon-adc.realsh.xyz | United States | 13335 | CLOUDFLARENETUS | true |
General Information |
---|
Joe Sandbox Version: | 32.0.0 Black Diamond |
Analysis ID: | 427162 |
Start date: | 31.05.2021 |
Start time: | 15:57:24 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 2m 43s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://icon-adc.realsh.xyz |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.troj.win@3/14@1/1 |
Cookbook Comments: |
|
Warnings: | Show All
|
Errors: |
|
No simulations |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 30296 |
Entropy (8bit): | 1.8530654022313717 |
Encrypted: | false |
SSDEEP: | 192:rwZTZc2yW2tlifDj9zMHz1BSvDKsfGjAjX:rg1rxWKKLQZD |
MD5: | CE1C7290190000C1FE9064542B61B02C |
SHA1: | F7E63975C43FE2DE26000EC7FCB2DD322E33683A |
SHA-256: | 9D4B9AC6795131D8C9810D663C2641D498C6AE6E128D4FB072A38980F11B56EC |
SHA-512: | 9CF6B6791D9608E3C89932CF417AB5B2C024F7A447FE3EE99CE259B7E4F74FCFCC89C8ED001BC0637FD3B4C6CC39D67D43FE0753AE997410BFEBF76992A3781E |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24164 |
Entropy (8bit): | 1.6272713599272883 |
Encrypted: | false |
SSDEEP: | 48:IwYGcpr9GwpaDG4pQHGrapbSmGQpBF4GHHpcFpTGUp8FxGzYpmFUSGopS3UXGmXg:rsZnQ16bBSejF32FrWF/MFj43mg |
MD5: | 9EF1FA1EAA5D55C0DA6609C05718E21C |
SHA1: | 374EA55E3EAB8023821A1CDEE8160CF29A9780C5 |
SHA-256: | 85B4B2C84AF9203808766A37972DBCDD24978433E3FD4955619A2FAB0D3D911C |
SHA-512: | 0EF1F1091C34E48BEDC60351B47D7F3F3D69AAFFB1567BC0FFB26D8628E97BC32E91347BCAC2777E5FD6994771FF91560C2CCC5C17EA0166516C95643FC8E4FB |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16984 |
Entropy (8bit): | 1.5644550010723464 |
Encrypted: | false |
SSDEEP: | 48:IwkGcprpGwpaMG4pQUGrapbSlGQpK7G7HpR7TGIpG:r4ZDQM6iBSPA6TxA |
MD5: | F4D6416579BB227BAB1A4ADAFBB93413 |
SHA1: | E822ED5E86C27F17114E10CAD869BA7569FBC748 |
SHA-256: | 0B82B05419AAAFD0219E35A6DC54F064CDD513CD7DAAEB770314EA7B8789989E |
SHA-512: | 0AB1B714F8543CB5064B8E00A82CF0ED29EF34427D021813EEDD021CC3C02055D1E1E91FB6E83DB17A7E8485E0FE80985D659F81CA73ECF74BF476DC7A4A5B7D |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2168 |
Entropy (8bit): | 5.207912016937144 |
Encrypted: | false |
SSDEEP: | 24:5+j5xU5k5N0ndgvoyeP0yyiyQCDr3nowMVworDtX3orKxWxDnCMA0da+hieyuSQK:5Q5K5k5pvFehWrrarrZIrHd3FIQfOS6 |
MD5: | F4FE1CB77E758E1BA56B8A8EC20417C5 |
SHA1: | F4EDA06901EDB98633A686B11D02F4925F827BF0 |
SHA-256: | 8D018639281B33DA8EB3CE0B21D11E1D414E59024C3689F92BE8904EB5779B5F |
SHA-512: | 62514AB345B6648C5442200A8E9530DFB88A0355E262069E0A694289C39A4A1C06C6143E5961074BFAC219949102A416C09733F24E8468984B96843DC222B436 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/ErrorPageTemplate.css |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 447 |
Entropy (8bit): | 7.304718288205936 |
Encrypted: | false |
SSDEEP: | 12:6v/71Cyt/JNTWxGdr+kZDWO7+4dKIv0b1GKuxu+R:/yBJNTqsSk9BTwE05su+R |
MD5: | 26F971D87CA00E23BD2D064524AEF838 |
SHA1: | 7440BEFF2F4F8FABC9315608A13BF26CABAD27D9 |
SHA-256: | 1D8E5FD3C1FD384C0A7507E7283C7FE8F65015E521B84569132A7EABEDC9D41D |
SHA-512: | C62EB51BE301BB96C80539D66A73CD17CA2021D5D816233853A37DB72E04050271E581CC99652F3D8469B390003CA6C62DAD2A9D57164C620B7777AE99AA1B15 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/bullet.png |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 748 |
Entropy (8bit): | 7.249606135668305 |
Encrypted: | false |
SSDEEP: | 12:6v/7/2QeZ7HVJ6o6yiq1p4tSQfAVFcm6R2HkZuU4fB4CsY4NJlrvMezoW2uONroc:GeZ6oLiqkbDuU4fqzTrvMeBBlE |
MD5: | C4F558C4C8B56858F15C09037CD6625A |
SHA1: | EE497CC061D6A7A59BB66DEFEA65F9A8145BA240 |
SHA-256: | 39E7DE847C9F731EAA72338AD9053217B957859DE27B50B6474EC42971530781 |
SHA-512: | D60353D3FBEA2992D96795BA30B20727B022B9164B2094B922921D33CA7CE1634713693AC191F8F5708954544F7648F4840BCD5B62CB6A032EF292A8B0E52A44 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/down.png |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4720 |
Entropy (8bit): | 5.164796203267696 |
Encrypted: | false |
SSDEEP: | 96:z9UUiqRxqH211CUIRgRLnRynjZbRXkRPRk6C87Apsat/5/+mhPcF+5g+mOQb7A9o:JsUOG1yNlX6ZzWpHOWLia16Cb7bk |
MD5: | D65EC06F21C379C87040B83CC1ABAC6B |
SHA1: | 208D0A0BB775661758394BE7E4AFB18357E46C8B |
SHA-256: | A1270E90CEA31B46432EC44731BF4400D22B38EB2855326BF934FE8F1B169A4F |
SHA-512: | 8A166D26B49A5D95AEA49BC649E5EA58786A2191F4D2ADAC6F5FBB7523940CE4482D6A2502AA870A931224F215CB2010A8C9B99A2C1820150E4D365CAB28299E |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/errorPageStrings.js |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6495 |
Entropy (8bit): | 3.8998802417135856 |
Encrypted: | false |
SSDEEP: | 48:up4d0yV4VkBXvLutC5N9J/1a5TI7kZ3GUXn3GFa7K083GJehBu01kptk7KwyBwpM:uKp6yN9JaKktZX36a7x05hwW7RM |
MD5: | F65C729DC2D457B7A1093813F1253192 |
SHA1: | 5006C9B50108CF582BE308411B157574E5A893FC |
SHA-256: | B82BFB6FA37FD5D56AC7C00536F150C0F244C81F1FC2D4FEFBBDC5E175C71B4F |
SHA-512: | 717AFF18F105F342103D36270D642CC17BD9921FF0DBC87E3E3C2D897F490F4ECFAB29CF998D6D99C4951C3EABB356FE759C3483A33704CE9FCC1F546EBCBBC7 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/http_404.htm |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4113 |
Entropy (8bit): | 7.9370830126943375 |
Encrypted: | false |
SSDEEP: | 96:WNTJL8szf79M8FUjE39KJoUUuJPnvmKacs6Uq7qDMj1XPL:WNrzFoQSJPnvzs6rL |
MD5: | 5565250FCC163AA3A79F0B746416CE69 |
SHA1: | B97CC66471FCDEE07D0EE36C7FB03F342C231F8F |
SHA-256: | 51129C6C98A82EA491F89857C31146ECEC14C4AF184517450A7A20C699C84859 |
SHA-512: | E60EA153B0FECE4D311769391D3B763B14B9A140105A36A13DAD23C2906735EAAB9092236DEB8C68EF078E8864D6E288BEF7EF1731C1E9F1AD9B0170B95AC134 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/info_48.png |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 453 |
Entropy (8bit): | 5.019973044227213 |
Encrypted: | false |
SSDEEP: | 6:3llVuiPjlXJYhg5suRd8PImMo23C/kHrJ8yA/NIeYoWg78C/vTFvbKLAh3:V/XPYhiPRd8j7+9LoIrobtHTdbKi |
MD5: | 20F0110ED5E4E0D5384A496E4880139B |
SHA1: | 51F5FC61D8BF19100DF0F8AADAA57FCD9C086255 |
SHA-256: | 1471693BE91E53C2640FE7BAEECBC624530B088444222D93F2815DFCE1865D5B |
SHA-512: | 5F52C117E346111D99D3B642926139178A80B9EC03147C00E27F07AAB47FE38E9319FE983444F3E0E36DEF1E86DD7C56C25E44B14EFDC3F13B45EDEDA064DB5A |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/background_gradient.jpg |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 12105 |
Entropy (8bit): | 5.451485481468043 |
Encrypted: | false |
SSDEEP: | 192:x20iniOciwd1BtvjrG8tAGGGVWnvyJVUrUiki3ayimi5ezLCvJG1gwm3z:xPini/i+1Btvjy815ZVUwiki3ayimi5f |
MD5: | 9234071287E637F85D721463C488704C |
SHA1: | CCA09B1E0FBA38BA29D3972ED8DCECEFDEF8C152 |
SHA-256: | 65CC039890C7CEB927CE40F6F199D74E49B8058C3F8A6E22E8F916AD90EA8649 |
SHA-512: | 87D691987E7A2F69AD8605F35F94241AB7E68AD4F55AD384F1F0D40DC59FFD1432C758123661EE39443D624C881B01DCD228A67AFB8700FE5E66FC794A6C0384 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/httpErrorPagesScripts.js |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13029 |
Entropy (8bit): | 0.4797051708082548 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9loh9loB9lWOraBcv:kBqoIKUOraBcv |
MD5: | 0BD5950F2D4A01AA44F9EF8E06CE224F |
SHA1: | 184654BFCD208AFA856BEB3C420838AF17DFD953 |
SHA-256: | 7B79413A4ADCCA3FDCA01CE1581789E934F44E10E66E99C0A4433699B92381CB |
SHA-512: | 4BD19504FEFAC1ECFCA2A1DD88623B80D05FB3E53EAB73C8DC15BE14591D566E65CAE7D9B27CD93C655DD4AC11F383BE3CDCB4FA8681D4C1687196318D19EF40 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | modified |
Size (bytes): | 25441 |
Entropy (8bit): | 0.4010301486997805 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRx/9lRJ9lTb9lTb9lSSU9lSSU9laAa/9laAvHRV3i9Ms0:kBqoxxJhHWSVSEab/eycgV |
MD5: | 05DBC1DDC01B0E420E1E22E152078A50 |
SHA1: | 04E6DB39331A903BA2FE8D6872DA74A2906BE41E |
SHA-256: | 4C8F9F71067302C9617DBAD532E230F8435905F74D50BC4DB16C8B8B995FDD97 |
SHA-512: | 5FDC2E17A28E0EC662670B3F7AA2BB87BD5A8513AD30780A1B0E170102A6C547DC77418B2A211C96BDDEBF78F61663E802F85656C60BE95EE43F464A40ABEE1F |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34357 |
Entropy (8bit): | 0.34839932707624066 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRg9lRA9lTS9lTy9lSSd9lSSd9lwFi9lwFy9l2FE9l2Fk8:kBqoxKAuvScS+FlFLFpFYFUIFUs3U5 |
MD5: | B4561F7D86660688331C775840AB9275 |
SHA1: | 5CEEFA2D5AEDA7E7599CE884E6FFD03E1FEB43A9 |
SHA-256: | 9A7DF7A491D9AE9767224FD5F15AAA4F09D0C647DE27B7CABE713510B143D7E1 |
SHA-512: | 9799B5EAB3D2C2918001AD7A65C0F52281FCE00B8A24F8C4860B0DC8EEC20D6D2B86CFEC6D89CBB48CDBA59A6EBB505149BF358653E329A186B6C21A696A08F3 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
No static file info |
---|
Network Behavior |
---|
Network Port Distribution |
---|
- Total Packets: 33
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 31, 2021 15:58:16.540416002 CEST | 49706 | 80 | 192.168.2.7 | 104.21.20.18 |
May 31, 2021 15:58:16.540565968 CEST | 49705 | 80 | 192.168.2.7 | 104.21.20.18 |
May 31, 2021 15:58:16.587264061 CEST | 80 | 49705 | 104.21.20.18 | 192.168.2.7 |
May 31, 2021 15:58:16.587286949 CEST | 80 | 49706 | 104.21.20.18 | 192.168.2.7 |
May 31, 2021 15:58:16.587420940 CEST | 49705 | 80 | 192.168.2.7 | 104.21.20.18 |
May 31, 2021 15:58:16.587470055 CEST | 49706 | 80 | 192.168.2.7 | 104.21.20.18 |
May 31, 2021 15:58:16.588399887 CEST | 49706 | 80 | 192.168.2.7 | 104.21.20.18 |
May 31, 2021 15:58:16.630254984 CEST | 80 | 49706 | 104.21.20.18 | 192.168.2.7 |
May 31, 2021 15:58:16.657947063 CEST | 80 | 49706 | 104.21.20.18 | 192.168.2.7 |
May 31, 2021 15:58:16.658099890 CEST | 49706 | 80 | 192.168.2.7 | 104.21.20.18 |
May 31, 2021 15:58:31.629406929 CEST | 80 | 49705 | 104.21.20.18 | 192.168.2.7 |
May 31, 2021 15:58:31.629652023 CEST | 49705 | 80 | 192.168.2.7 | 104.21.20.18 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 31, 2021 15:58:07.884614944 CEST | 50848 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:07.943236113 CEST | 53 | 50848 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:08.710858107 CEST | 61242 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:08.764168978 CEST | 53 | 61242 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:09.617620945 CEST | 58562 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:09.670308113 CEST | 53 | 58562 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:09.711627960 CEST | 56590 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:09.774082899 CEST | 53 | 56590 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:10.528496027 CEST | 60501 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:10.581490040 CEST | 53 | 60501 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:11.883735895 CEST | 53775 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:11.933859110 CEST | 53 | 53775 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:13.188494921 CEST | 51837 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:13.239372969 CEST | 53 | 51837 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:14.131186008 CEST | 55411 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:14.183830023 CEST | 53 | 55411 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:15.092104912 CEST | 63668 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:15.154937029 CEST | 53 | 63668 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:15.267641068 CEST | 54640 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:15.319046974 CEST | 53 | 54640 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:16.465588093 CEST | 58739 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:16.471141100 CEST | 60338 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:16.522440910 CEST | 53 | 60338 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:16.528285980 CEST | 53 | 58739 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:18.424937963 CEST | 58717 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:18.474817991 CEST | 53 | 58717 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:19.456778049 CEST | 59762 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:19.506824970 CEST | 53 | 59762 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:20.573663950 CEST | 54329 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:20.631525993 CEST | 53 | 54329 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:21.388722897 CEST | 58052 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:21.440161943 CEST | 53 | 58052 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:22.177382946 CEST | 54008 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:22.230392933 CEST | 53 | 54008 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:23.109534979 CEST | 59451 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:23.159667015 CEST | 53 | 59451 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:24.240298986 CEST | 52914 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:24.290793896 CEST | 53 | 52914 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:25.106616974 CEST | 64569 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:25.156824112 CEST | 53 | 64569 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:26.260088921 CEST | 52816 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:26.313030958 CEST | 53 | 52816 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:27.424837112 CEST | 50781 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:27.474828959 CEST | 53 | 50781 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:28.775496960 CEST | 54230 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:28.833463907 CEST | 53 | 54230 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:33.130688906 CEST | 54911 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:33.190706015 CEST | 53 | 54911 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:33.580945015 CEST | 49958 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:33.633944988 CEST | 53 | 49958 | 8.8.8.8 | 192.168.2.7 |
May 31, 2021 15:58:43.945601940 CEST | 50860 | 53 | 192.168.2.7 | 8.8.8.8 |
May 31, 2021 15:58:44.012011051 CEST | 53 | 50860 | 8.8.8.8 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
May 31, 2021 15:58:16.465588093 CEST | 192.168.2.7 | 8.8.8.8 | 0x866c | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
May 31, 2021 15:58:16.528285980 CEST | 8.8.8.8 | 192.168.2.7 | 0x866c | No error (0) | 104.21.20.18 | A (IP address) | IN (0x0001) | ||
May 31, 2021 15:58:16.528285980 CEST | 8.8.8.8 | 192.168.2.7 | 0x866c | No error (0) | 172.67.190.209 | A (IP address) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.7 | 49706 | 104.21.20.18 | 80 | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
May 31, 2021 15:58:16.588399887 CEST | 1057 | OUT | |
May 31, 2021 15:58:16.657947063 CEST | 1058 | IN |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
Behavior |
---|
Click to jump to process
System Behavior |
---|
Start time: | 15:58:13 |
Start date: | 31/05/2021 |
Path: | C:\Program Files\internet explorer\iexplore.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3c60000 |
File size: | 823560 bytes |
MD5 hash: | 6465CB92B25A7BC1DF8E01D8AC5E7596 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
Network Activities
Object Security Activities
LPC Port Activities
Start time: | 15:58:14 |
Start date: | 31/05/2021 |
Path: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1060000 |
File size: | 822536 bytes |
MD5 hash: | 071277CC2E3DF41EEEA8013E2AB58D5A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
Network Activities
Object Security Activities
LPC Port Activities
Disassembly |
---|