Analysis Report http://mout.perfora.net
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
Analysis Advice |
---|
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work |
Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later |
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | File opened: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Process Injection1 | Masquerading1 | OS Credential Dumping | File and Directory Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Non-Application Layer Protocol1 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Process Injection1 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe |
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
No Antivirus matches |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
mout.perfora.net | 74.208.4.196 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
74.208.4.197 | unknown | United States | 8560 | ONEANDONE-ASBrauerstrasse48DE | false | |
74.208.4.194 | unknown | United States | 8560 | ONEANDONE-ASBrauerstrasse48DE | false | |
74.208.4.196 | mout.perfora.net | United States | 8560 | ONEANDONE-ASBrauerstrasse48DE | false | |
74.208.4.195 | unknown | United States | 8560 | ONEANDONE-ASBrauerstrasse48DE | false |
General Information |
---|
Joe Sandbox Version: | 32.0.0 Black Diamond |
Analysis ID: | 429888 |
Start date: | 04.06.2021 |
Start time: | 22:41:25 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 2m 36s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://mout.perfora.net |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | UNKNOWN |
Classification: | unknown0.win@3/11@2/4 |
Cookbook Comments: |
|
Warnings: | Show All
|
Errors: |
|
No simulations |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 30296 |
Entropy (8bit): | 1.843851685842563 |
Encrypted: | false |
SSDEEP: | 192:rcZ3Zao2a7bWa7tOta7tC/fa7tCOLhMa7t6mOBa7t6ZOsa7t6ZNOxfa7t6ZNONkQ:rcJYZnV3//IU |
MD5: | 492D73AAAF6951AD98EE3858F5847736 |
SHA1: | F822F7D8C5CD3D21DF5F4041B8FAEF8B7FBB8847 |
SHA-256: | 70AF133F9236497C45FE03127E0A840E5BBC384E564E04A6AB93BB8276E91CF6 |
SHA-512: | F55F4AA162F4D65CE92B4837C348C01F1D4A748521C45B6F10BD9F592EB569B357403D6ED13CDD86640FF1CFA8594A2EADF0F9D641C7D490D9D1583AEDD4E426 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24160 |
Entropy (8bit): | 1.6262689423837005 |
Encrypted: | false |
SSDEEP: | 48:IwmGcprzGwpafG4pQnGrapbSfZGQpByGHHpcQaTGUp8kWGzYpmIZOGopG2V1WGyw:r6ZtQx67BS7jJ2dWRMts82g |
MD5: | 42943E684A5807830B62EB9FFB8DA7E3 |
SHA1: | 866FCD04994E3B7D4BC16F66E2EB9FE919298A12 |
SHA-256: | ABAC683C0DB75ED71DD68BD48E0936F6CDAD00BFAAE7C079AEACE65000BFB69E |
SHA-512: | 52FA7C7098BD14E282FCFF4AA78E47592625D92CC6EFB324BF3084B679EA3CE2182AE6ABB640ED67358D0A0ED9B131D5C751A1D8305396D3013B29852B03F782 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16984 |
Entropy (8bit): | 1.5650531810780535 |
Encrypted: | false |
SSDEEP: | 48:IwtGcproGwpaMG4pQsGrapbSnZGQpKRG7HpRLaTGIpG:rzZwQM6qBSzAATSA |
MD5: | 30C76876D2E4CA36B49BBED059878BC1 |
SHA1: | 13E77603DF2144C5050E8BDA1FB92223277C977B |
SHA-256: | C21C0F94546EB65CFCFFAF1EFC5C0F492BB62E24202CA13C388E6350285E69B3 |
SHA-512: | 4F25EE3F30B1C1B7CABB37706DE72049F73D510AC44BE2F541A4162FD73811A23CF69E10812D335DA0FC49BB343BF373FB58BC64B101C3D1617DADB7DF1F0DFE |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4720 |
Entropy (8bit): | 5.164796203267696 |
Encrypted: | false |
SSDEEP: | 96:z9UUiqRxqH211CUIRgRLnRynjZbRXkRPRk6C87Apsat/5/+mhPcF+5g+mOQb7A9o:JsUOG1yNlX6ZzWpHOWLia16Cb7bk |
MD5: | D65EC06F21C379C87040B83CC1ABAC6B |
SHA1: | 208D0A0BB775661758394BE7E4AFB18357E46C8B |
SHA-256: | A1270E90CEA31B46432EC44731BF4400D22B38EB2855326BF934FE8F1B169A4F |
SHA-512: | 8A166D26B49A5D95AEA49BC649E5EA58786A2191F4D2ADAC6F5FBB7523940CE4482D6A2502AA870A931224F215CB2010A8C9B99A2C1820150E4D365CAB28299E |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/errorPageStrings.js |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1612 |
Entropy (8bit): | 4.869554560514657 |
Encrypted: | false |
SSDEEP: | 24:5Y0bQ573pHpACtUZtJD0lFBopZleqw87xTe4D8FaFJ/Doz9AtjJgbCzg:5m73jcJqQep89TEw7Uxkk |
MD5: | DFEABDE84792228093A5A270352395B6 |
SHA1: | E41258C9576721025926326F76063C2305586F76 |
SHA-256: | 77B138AB5D0A90FF04648C26ADDD5E414CC178165E3B54A4CB3739DA0F58E075 |
SHA-512: | E256F603E67335151BB709294749794E2E3085F4063C623461A0B3DECBCCA8E620807B707EC9BCBE36DCD7D639C55753DA0495BE85B4AE5FB6BFC52AB4B284FD |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/NewErrorPageTemplate.css |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 12105 |
Entropy (8bit): | 5.451485481468043 |
Encrypted: | false |
SSDEEP: | 192:x20iniOciwd1BtvjrG8tAGGGVWnvyJVUrUiki3ayimi5ezLCvJG1gwm3z:xPini/i+1Btvjy815ZVUwiki3ayimi5f |
MD5: | 9234071287E637F85D721463C488704C |
SHA1: | CCA09B1E0FBA38BA29D3972ED8DCECEFDEF8C152 |
SHA-256: | 65CC039890C7CEB927CE40F6F199D74E49B8058C3F8A6E22E8F916AD90EA8649 |
SHA-512: | 87D691987E7A2F69AD8605F35F94241AB7E68AD4F55AD384F1F0D40DC59FFD1432C758123661EE39443D624C881B01DCD228A67AFB8700FE5E66FC794A6C0384 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/httpErrorPagesScripts.js |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2997 |
Entropy (8bit): | 4.4885437940628465 |
Encrypted: | false |
SSDEEP: | 48:u7u5V4VyhhV2lFUW29vj0RkpNc7KpAP8Rra:vIlJ6G7Ao8Ra |
MD5: | 2DC61EB461DA1436F5D22BCE51425660 |
SHA1: | E1B79BCAB0F073868079D807FAEC669596DC46C1 |
SHA-256: | ACDEB4966289B6CE46ECC879531F85E9C6F94B718AAB521D38E2E00F7F7F7993 |
SHA-512: | A88BECB4FBDDC5AFC55E4DC0135AF714A3EEC4A63810AE5A989F2CECB824A686165D3CEDB8CBD8F35C7E5B9F4136C29DEA32736AABB451FE8088B978B493AC6D |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/dnserror.htm?ErrorStatus=0x800C0005&DNSError=0 |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 748 |
Entropy (8bit): | 7.249606135668305 |
Encrypted: | false |
SSDEEP: | 12:6v/7/2QeZ7HVJ6o6yiq1p4tSQfAVFcm6R2HkZuU4fB4CsY4NJlrvMezoW2uONroc:GeZ6oLiqkbDuU4fqzTrvMeBBlE |
MD5: | C4F558C4C8B56858F15C09037CD6625A |
SHA1: | EE497CC061D6A7A59BB66DEFEA65F9A8145BA240 |
SHA-256: | 39E7DE847C9F731EAA72338AD9053217B957859DE27B50B6474EC42971530781 |
SHA-512: | D60353D3FBEA2992D96795BA30B20727B022B9164B2094B922921D33CA7CE1634713693AC191F8F5708954544F7648F4840BCD5B62CB6A032EF292A8B0E52A44 |
Malicious: | false |
Reputation: | low |
IE Cache URL: | res://ieframe.dll/down.png |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34353 |
Entropy (8bit): | 0.34658404180935204 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRg9lRA9lTS9lTy9lSSd9lSSd9lw2f9lw2f9l22B9l22Bs:kBqoxKAuvScS+5XF0III42/ |
MD5: | 16FA68B32C9AE8D49CC111DDBE8BF532 |
SHA1: | 68E0A27B46D83E715FEC5B8AA68677661FD838E1 |
SHA-256: | 1860EC5C7E576DB2A4657B7D01C6C6BD114B17BECCABB769AF6E99547583C785 |
SHA-512: | F0F04813AB4A977C7D1320F722D4ED6D2D461284D648A635B1150CA34EB6CCE79521409F4E40254B77296967A32FEB8F267E684D9A59BDD5623D2728488BD109 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25441 |
Entropy (8bit): | 0.39573800375597756 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRx/9lRJ9lTb9lTb9lSSU9lSSU9laAa/9laAggCZf2BmQ:kBqoxxJhHWSVSEab2+ |
MD5: | 42FDDC900EA7E321A763A28104701987 |
SHA1: | 6C593C456B95DF3EACF4391A17D91796004C9484 |
SHA-256: | C9A0E1E878616F08E1198F5669D05CFCAD6D12FABE0489CBF83266E2021DAA0B |
SHA-512: | 9DAF569087EA682DC4F7664597EEB64636E97D4E7631719C438E228E08ABB5BE85B6164C1F5D9C895380FD955287455789518BA58E99615EA74F67224668CBB9 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13029 |
Entropy (8bit): | 0.4768473089486685 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9loaDF9loaJ9lWa7tGROtGJlGJZNON2:kBqoIaSaMa7tGROtGJlGJZNON2 |
MD5: | DD1F0B2BA0945E78A47C76A1A02256DF |
SHA1: | B20C292C2FB566D24A42AD92B86CD12B9A203591 |
SHA-256: | 3173E65F24D618B041FC2BA8B2D68900C75BCEC5C579C0EB6D7F3A11329B0A87 |
SHA-512: | B76B2F8A92CBD78F52C507131679987AEF54D19098627C6F1D20131C60F1A1EFCE4101850B1385233BF89A0843066E5B20F8827D71005F32E8CEAFB539F1D8E7 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
No static file info |
---|
Network Behavior |
---|
Network Port Distribution |
---|
- Total Packets: 59
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 4, 2021 22:42:13.068175077 CEST | 49728 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:13.070015907 CEST | 49729 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:14.069029093 CEST | 49728 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:14.069052935 CEST | 49729 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:16.069367886 CEST | 49728 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:16.069403887 CEST | 49729 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:20.072400093 CEST | 49736 | 80 | 192.168.2.3 | 74.208.4.197 |
Jun 4, 2021 22:42:20.073312998 CEST | 49737 | 80 | 192.168.2.3 | 74.208.4.197 |
Jun 4, 2021 22:42:21.085459948 CEST | 49736 | 80 | 192.168.2.3 | 74.208.4.197 |
Jun 4, 2021 22:42:21.085485935 CEST | 49737 | 80 | 192.168.2.3 | 74.208.4.197 |
Jun 4, 2021 22:42:23.085478067 CEST | 49736 | 80 | 192.168.2.3 | 74.208.4.197 |
Jun 4, 2021 22:42:23.086229086 CEST | 49737 | 80 | 192.168.2.3 | 74.208.4.197 |
Jun 4, 2021 22:42:27.162080050 CEST | 49742 | 80 | 192.168.2.3 | 74.208.4.195 |
Jun 4, 2021 22:42:27.162467957 CEST | 49743 | 80 | 192.168.2.3 | 74.208.4.195 |
Jun 4, 2021 22:42:28.148389101 CEST | 49742 | 80 | 192.168.2.3 | 74.208.4.195 |
Jun 4, 2021 22:42:28.163981915 CEST | 49743 | 80 | 192.168.2.3 | 74.208.4.195 |
Jun 4, 2021 22:42:30.148507118 CEST | 49742 | 80 | 192.168.2.3 | 74.208.4.195 |
Jun 4, 2021 22:42:30.351716995 CEST | 49743 | 80 | 192.168.2.3 | 74.208.4.195 |
Jun 4, 2021 22:42:34.150160074 CEST | 49744 | 80 | 192.168.2.3 | 74.208.4.194 |
Jun 4, 2021 22:42:34.353146076 CEST | 49745 | 80 | 192.168.2.3 | 74.208.4.194 |
Jun 4, 2021 22:42:35.164561033 CEST | 49744 | 80 | 192.168.2.3 | 74.208.4.194 |
Jun 4, 2021 22:42:35.367710114 CEST | 49745 | 80 | 192.168.2.3 | 74.208.4.194 |
Jun 4, 2021 22:42:37.164699078 CEST | 49744 | 80 | 192.168.2.3 | 74.208.4.194 |
Jun 4, 2021 22:42:37.383503914 CEST | 49745 | 80 | 192.168.2.3 | 74.208.4.194 |
Jun 4, 2021 22:42:41.425333023 CEST | 49750 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:42.587146997 CEST | 49750 | 80 | 192.168.2.3 | 74.208.4.196 |
Jun 4, 2021 22:42:44.587264061 CEST | 49750 | 80 | 192.168.2.3 | 74.208.4.196 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 4, 2021 22:42:04.195569038 CEST | 53 | 60831 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:05.085366011 CEST | 60100 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:05.128602982 CEST | 53 | 60100 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:06.448530912 CEST | 53195 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:06.491110086 CEST | 53 | 53195 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:07.621665955 CEST | 50141 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:07.665184021 CEST | 53 | 50141 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:08.723162889 CEST | 53023 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:08.766402960 CEST | 53 | 53023 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:09.933060884 CEST | 49563 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:09.975385904 CEST | 53 | 49563 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:11.049700975 CEST | 51352 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:11.095976114 CEST | 53 | 51352 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:11.789376020 CEST | 59349 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:11.836126089 CEST | 53 | 59349 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:12.264071941 CEST | 57084 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:12.308161974 CEST | 53 | 57084 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:13.011154890 CEST | 58823 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:13.054007053 CEST | 53 | 58823 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:13.481853008 CEST | 57568 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:13.524102926 CEST | 53 | 57568 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:14.652160883 CEST | 50540 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:14.694508076 CEST | 53 | 50540 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:16.355297089 CEST | 54366 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:16.397902012 CEST | 53 | 54366 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:17.664153099 CEST | 53034 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:17.706309080 CEST | 53 | 53034 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:18.593507051 CEST | 57762 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:18.635684967 CEST | 53 | 57762 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:19.907933950 CEST | 55435 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:19.950073004 CEST | 53 | 55435 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:21.215626001 CEST | 50713 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:21.258100033 CEST | 53 | 50713 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:22.457612991 CEST | 56132 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:22.500333071 CEST | 53 | 56132 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:23.690339088 CEST | 58987 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:23.733340025 CEST | 53 | 58987 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:24.936685085 CEST | 56579 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:24.979149103 CEST | 53 | 56579 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:40.669689894 CEST | 60633 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:40.726269960 CEST | 53 | 60633 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:41.972810984 CEST | 61292 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:42.017586946 CEST | 53 | 61292 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:42.666070938 CEST | 63619 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:42.708756924 CEST | 53 | 63619 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:42.770394087 CEST | 64938 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:42.814811945 CEST | 53 | 64938 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:43.010900974 CEST | 61292 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:43.055969954 CEST | 53 | 61292 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:43.683413982 CEST | 63619 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:43.727495909 CEST | 53 | 63619 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:44.072868109 CEST | 61292 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:44.116214037 CEST | 53 | 61292 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:44.728168011 CEST | 63619 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:44.773350954 CEST | 53 | 63619 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:46.118829966 CEST | 61292 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:46.164201021 CEST | 53 | 61292 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:46.728266001 CEST | 63619 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:46.770653009 CEST | 53 | 63619 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:48.602102041 CEST | 61946 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:48.646265030 CEST | 53 | 61946 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:50.166062117 CEST | 61292 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:50.209271908 CEST | 53 | 61292 | 8.8.8.8 | 192.168.2.3 |
Jun 4, 2021 22:42:50.775557995 CEST | 63619 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 4, 2021 22:42:50.817785025 CEST | 53 | 63619 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Jun 4, 2021 22:42:13.011154890 CEST | 192.168.2.3 | 8.8.8.8 | 0xf67b | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 4, 2021 22:42:48.602102041 CEST | 192.168.2.3 | 8.8.8.8 | 0xed72 | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Jun 4, 2021 22:42:13.054007053 CEST | 8.8.8.8 | 192.168.2.3 | 0xf67b | No error (0) | 74.208.4.196 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:13.054007053 CEST | 8.8.8.8 | 192.168.2.3 | 0xf67b | No error (0) | 74.208.4.197 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:13.054007053 CEST | 8.8.8.8 | 192.168.2.3 | 0xf67b | No error (0) | 74.208.4.195 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:13.054007053 CEST | 8.8.8.8 | 192.168.2.3 | 0xf67b | No error (0) | 74.208.4.194 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:48.646265030 CEST | 8.8.8.8 | 192.168.2.3 | 0xed72 | No error (0) | 74.208.4.197 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:48.646265030 CEST | 8.8.8.8 | 192.168.2.3 | 0xed72 | No error (0) | 74.208.4.195 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:48.646265030 CEST | 8.8.8.8 | 192.168.2.3 | 0xed72 | No error (0) | 74.208.4.196 | A (IP address) | IN (0x0001) | ||
Jun 4, 2021 22:42:48.646265030 CEST | 8.8.8.8 | 192.168.2.3 | 0xed72 | No error (0) | 74.208.4.194 | A (IP address) | IN (0x0001) |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
Behavior |
---|
Click to jump to process
System Behavior |
---|
Start time: | 22:42:10 |
Start date: | 04/06/2021 |
Path: | C:\Program Files\internet explorer\iexplore.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff614180000 |
File size: | 823560 bytes |
MD5 hash: | 6465CB92B25A7BC1DF8E01D8AC5E7596 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
Network Activities
Object Security Activities
LPC Port Activities
Start time: | 22:42:11 |
Start date: | 04/06/2021 |
Path: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1020000 |
File size: | 822536 bytes |
MD5 hash: | 071277CC2E3DF41EEEA8013E2AB58D5A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
Network Activities
Object Security Activities
LPC Port Activities
Disassembly |
---|