Windows Analysis Report 35N4PXWcmC.msi
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
No yara matches |
---|
Sigma Overview |
---|
No Sigma rule has matched |
---|
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Multi AV Scanner detection for submitted file | Show sources |
Source: | ReversingLabs: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | JA3 fingerprint: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary or memory string: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Static file information: |
Source: | Key value queried: | Jump to behavior |
Source: | Mutant created: |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window detected: |
Source: | Static file information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Replication Through Removable Media1 | Windows Management Instrumentation | DLL Side-Loading1 | Process Injection11 | Process Injection11 | OS Credential Dumping | Query Registry1 | Replication Through Removable Media1 | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel2 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | DLL Side-Loading1 | DLL Side-Loading1 | LSASS Memory | Peripheral Device Discovery11 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Non-Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | File and Directory Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Application Layer Protocol2 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | System Information Discovery12 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | Remote System Discovery1 | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
6% | Metadefender | Browse | ||
50% | ReversingLabs | Win32.Infostealer.ClipBanker |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
No Antivirus matches |
---|
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
edge-block-www-env.dropbox-dns.com | 162.125.65.15 | true | false | unknown | |
www-env.dropbox-dns.com | 162.125.65.18 | true | false | unknown | |
ucdd2fc710a0d9b0bc926ff3d256.dl.dropboxusercontent.com | unknown | unknown | false | high | |
www.dropbox.com | unknown | unknown | false | high |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.125.65.15 | edge-block-www-env.dropbox-dns.com | United States | 19679 | DROPBOXUS | false | |
162.125.65.18 | www-env.dropbox-dns.com | United States | 19679 | DROPBOXUS | false |
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 473965 |
Start date: | 30.08.2021 |
Start time: | 14:22:48 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | 35N4PXWcmC.msi |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.winMSI@5/0@2/2 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
14:23:47 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
No context |
---|
Domains |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
edge-block-www-env.dropbox-dns.com | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
www-env.dropbox-dns.com | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
DROPBOXUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
DROPBOXUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
ce5f3254611a8c095a3d821d44539877 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
No created / dropped files found |
---|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 7.461939743498868 |
TrID: |
|
File name: | 35N4PXWcmC.msi |
File size: | 9071616 |
MD5: | 82013cf110edfeac59808ca15fac2bee |
SHA1: | 1fa2db4a755db612f6385f325721eb324462de4b |
SHA256: | af5986b366517ffd2290fa47348243ea53b22105b6160d2a97d0512989feb1f7 |
SHA512: | 078c7bafb0e774e3a3d5ee61c679431f8a0599bee9912312e6d28beaf04b2614cf9be73c59c2323d088581fe2612317f96f6b6901ff3fc034664d559b50d397d |
SSDEEP: | 196608:dkxY9gQLJQLzQLIQLfQLtQLSowWSKf0K:dkxY9gks/qYBWSKf0K |
File Content Preview: | ........................>.......................................................w...x...y...z...{...|...}...~.................................................................................................................................................. |
File Icon |
---|
Icon Hash: | a2a0b496b2caca72 |
Static OLE Info |
---|
General | ||
---|---|---|
Document Type: | OLE | |
Number of OLE Files: | 1 |
OLE File "35N4PXWcmC.msi" |
---|
Indicators | |
---|---|
Has Summary Info: | True |
Application Name: | Advanced Installer 18.1.1 build 4b2255d8 |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | False |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | |
Flash Objects Count: | |
Contains VBA Macros: | False |
Summary | |
---|---|
Code Page: | 1252 |
Title: | |
Subject: | |
Author: | |
Keywords: | |
Comments: | |
Template: | |
Last Saved By: | |
Revion Number: | {D30C6F8A-FA01-4532-941E-23CD4836B0B1} |
Last Printed: | 2009-12-11 11:47:44.850000 |
Create Time: | 2009-12-11 11:47:44.850000 |
Last Saved Time: | 2020-09-18 14:06:51.913000 |
Number of Pages: | 200 |
Number of Words: | 10 |
Creating Application: | |
Security: | 0 |
Streams |
---|
Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 556 |
---|
General | |
---|---|
Stream Path: | \x5SummaryInformation |
File Type: | data |
Stream Size: | 556 |
Entropy: | 4.53537473067 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . T . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . @ . . . # . . W z . . @ . . . # . . W z . . @ . . . . _ . . . . . . . . . . . . . . . . . . . . . . . . . . ' . . . { D 3 0 C 6 F 8 A - F A |
Data Raw: | fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 fc 01 00 00 10 00 00 00 0b 00 00 00 88 00 00 00 0c 00 00 00 94 00 00 00 0d 00 00 00 a0 00 00 00 13 00 00 00 ac 00 00 00 01 00 00 00 b4 00 00 00 09 00 00 00 bc 00 00 00 0f 00 00 00 ec 00 00 00 03 00 00 00 f4 00 00 00 04 00 00 00 24 01 00 00 |
Stream Path: \x17163\x16689\x18229\x15870\x18088, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x15870\x18088 |
File Type: | MS Windows icon resource - 1 icon, 16x16, 16 colors |
Stream Size: | 318 |
Entropy: | 2.03444158006 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . ( . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00 |
Stream Path: \x17163\x16689\x18229\x16318\x18483, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16318\x18483 |
File Type: | MS Windows icon resource - 1 icon, 16x16, 16 colors |
Stream Size: | 318 |
Entropy: | 2.03693614652 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . ( . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00 |
Stream Path: \x17163\x16689\x18229\x16702\x16812\x17848\x16695\x17894\x16894\x17391, File Type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, Stream Size: 385960 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16702\x16812\x17848\x16695\x17894\x16894\x17391 |
File Type: | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
Stream Size: | 385960 |
Entropy: | 6.40538671056 |
Base64 Encoded: | True |
Data ASCII: | M Z . . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . L . ! T h i s p r o g r a m c a n n o t b e r u n i n D O S m o d e . . . . $ . . . . . . . . . { . . . . . . . . . . . . . . . . . . . . . . . . . ? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C . . . . . . . C . . . . . . . C . . . . . . . . . . . . . . . C . . . . . . . |
Data Raw: | 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16766\x17508\x16945\x18485 |
File Type: | JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 500x59, frames 3 |
Stream Size: | 2818 |
Entropy: | 7.55703063679 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . J F I F . . . . . . . . . . . . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . ' " , # . . ( 7 ) , 0 1 4 4 4 . ' 9 = 8 2 < . 3 4 2 . . . C . . . . . . . . . . . 2 ! . ! 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 . . . . . . ; . . . . " . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . } . . . . . . . . ! 1 A . . Q a . " q . 2 . . . . # |
Data Raw: | ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12 13 0f 14 1d 1a 1f 1e 1d 1a 1c 1c 20 24 2e 27 20 22 2c 23 1c 1c 28 37 29 2c 30 31 34 34 34 1f 27 39 3d 38 32 3c 2e 33 34 32 ff db 00 43 01 09 09 09 0c 0b 0c 18 0d 0d 18 32 21 1c 21 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 |
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16830\x16880\x17199\x17329\x17764\x17589\x18490 |
File Type: | MS Windows icon resource - 3 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel |
Stream Size: | 2862 |
Entropy: | 3.16043065194 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . ( . . . 6 . . . . . . . . . . . h . . . ^ . . . . . . . . . . h . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w v . . . . . " " " " " o . . " " " " " o . . w w w " " . . . . . . " / . . . . |
Data Raw: | 00 00 01 00 03 00 10 10 10 00 00 00 04 00 28 01 00 00 36 00 00 00 10 10 00 00 00 00 08 00 68 05 00 00 5e 01 00 00 10 10 00 00 00 00 20 00 68 04 00 00 c6 06 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 80 80 80 00 c0 c0 |
Stream Path: \x17163\x16689\x18229\x16830\x17458\x17395\x17896\x18476, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16830\x17458\x17395\x17896\x18476 |
File Type: | MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32 |
Stream Size: | 2998 |
Entropy: | 4.35906224297 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . . . . p . . . . . . . . . . x . { . w p . . . . . . . . . . . . { . w . . . . . . . . |
Data Raw: | 00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 |
Stream Path: \x17163\x16689\x18229\x16830\x17848\x17207\x17574\x18481, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16830\x17848\x17207\x17574\x18481 |
File Type: | MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32 |
Stream Size: | 2998 |
Entropy: | 4.29856879699 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . . . . p . . . . . . . . . . x . { . w p . . . . . . . . . . . . { . w . . . . . . . . |
Data Raw: | 00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 |
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16894\x16684\x17583\x18474 |
File Type: | JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x316, frames 3 |
Stream Size: | 11791 |
Entropy: | 7.71486251579 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . J F I F . . . . . . . . . . . . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . s . |
Data Raw: | ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 04 02 03 03 03 02 04 03 03 03 04 04 04 04 05 09 06 05 05 05 05 0b 08 08 06 09 0d 0b 0d 0d 0d 0b 0c 0c 0e 10 14 11 0e 0f 13 0f 0c 0c 12 18 12 13 15 16 17 17 17 0e 11 19 1b 19 16 1a 14 16 17 16 ff db 00 43 01 04 04 04 05 05 05 0a 06 06 0a 16 0f 0c 0f 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 |
Stream Path: \x17163\x16689\x18229\x16958\x16827\x16687\x17200\x18470, File Type: MS Windows icon resource - 1 icon, 32x32, 16 colors, Stream Size: 766 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x16958\x16827\x16687\x17200\x18470 |
File Type: | MS Windows icon resource - 1 icon, 32x32, 16 colors |
Stream Size: | 766 |
Entropy: | 3.3484862649 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 3 1 . . . . . . . . . . . . 3 3 2 3 3 3 3 3 3 3 3 3 3 3 3 . 3 3 $ D D D D D D D D D D D @ 1 . 2 D D D D D D D D D D D D D . . 2 D D D D D D @ D D D D D D C . 2 D D D D D D 3 4 D D D D D C . 2 D D D D D @ 3 0 D D D D D . . 3 $ D D D D D 3 4 D D D D D 1 . 3 $ |
Data Raw: | 00 00 01 00 01 00 20 20 10 00 00 00 00 00 e8 02 00 00 16 00 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 c0 c0 00 80 80 80 00 00 80 80 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 33 33 |
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x17150\x14528\x14965\x17667\x17195\x17383\x14378\x17075\x17779\x16894\x17391 |
File Type: | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
Stream Size: | 8458240 |
Entropy: | 7.52105426672 |
Base64 Encoded: | True |
Data ASCII: | M Z P . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . L . ! . . T h i s p r o g r a m m u s t b e r u n u n d e r W i n 3 2 . . $ 7 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 |
Stream Path: \x17163\x16689\x18229\x17214\x17009\x18482, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors, Stream Size: 1078 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x17214\x17009\x18482 |
File Type: | MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors |
Stream Size: | 1078 |
Entropy: | 2.86422695486 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . & . . . . . . . . . . . ( . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . w p . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . p . . . . . . . . . . w w . . . w w . . . . . . |
Data Raw: | 00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 10 10 10 00 00 00 00 00 28 01 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 80 80 80 00 c0 c0 c0 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 |
Stream Path: \x17163\x16689\x18229\x17214\x17841\x17207\x17574\x18481, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x17214\x17841\x17207\x17574\x18481 |
File Type: | MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32 |
Stream Size: | 2998 |
Entropy: | 4.40653521205 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . w . . . . . . . . . . p . . x . . . . w . . . . . . . . x . . . w . . w . . . . . . . p . . x x . . w ~ . . . . . . . . x . . . . . ~ . . . . . . . |
Data Raw: | 00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 |
Stream Path: \x17163\x16689\x18229\x17790\x17448\x18034\x16812\x18482, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x17790\x17448\x18034\x16812\x18482 |
File Type: | MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32 |
Stream Size: | 2998 |
Entropy: | 4.92283562852 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . w w . . . . . . . . . . . . w . f . w . . . . . . w . . . . . v v f . w . . . . . . . . . . . n f f l . w . . . . |
Data Raw: | 00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 |
Stream Path: \x17163\x16689\x18229\x17790\x17640\x17188\x17205\x18470, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x17790\x17640\x17188\x17205\x18470 |
File Type: | MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32 |
Stream Size: | 2998 |
Entropy: | 4.6676615263 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . . . . p . . . . . . . . . . x . { . w p . . . . . . . . ( . . . { . w . . . . . . . . . ( x x x . . . . . . . . . . . |
Data Raw: | 00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 |
Stream Path: \x17163\x16689\x18229\x17918\x16740\x16677\x17318, File Type: PC bitmap, Windows 3.x format, 1 x 200 x 24, Stream Size: 854 |
---|
General | |
---|---|
Stream Path: | \x17163\x16689\x18229\x17918\x16740\x16677\x17318 |
File Type: | PC bitmap, Windows 3.x format, 1 x 200 x 24 |
Stream Size: | 854 |
Entropy: | 3.80253159876 |
Base64 Encoded: | False |
Data ASCII: | B M V . . . . . . . 6 . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 42 4d 56 03 00 00 00 00 00 00 36 00 00 00 28 00 00 00 01 00 00 00 c8 00 00 00 01 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ef f3 f4 00 ef f3 f4 00 ef f3 f4 00 ef f4 f4 00 ef f4 f4 00 ef f4 f5 00 ef f4 f5 00 ef f4 f5 00 ef f4 |
Stream Path: \x18496\x15167\x17394\x17464\x17841, File Type: data, Stream Size: 1312 |
---|
General | |
---|---|
Stream Path: | \x18496\x15167\x17394\x17464\x17841 |
File Type: | data |
Stream Size: | 1312 |
Entropy: | 4.86814231206 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % . % . % . % . % . % . % . % . % . % . / . / . 4 . 4 . 8 . 8 . 8 . 8 . 8 . 8 . 8 . ; . ; . @ . @ . @ . B . B . B . E . E . E . G . G . G . G . G . G . G . G . G . K . K . K . K . K . P . P . P . Q . Q . Q . Q . S . S . S . T . T . V . V . V . V . V . W . W . W . W . W . W . Z . Z . Z . Z . Z . Z . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ` . ` . ` . ` . ` . b . b . b . b . f . f . f . m . m . m . |
Data Raw: | 04 00 04 00 04 00 04 00 04 00 04 00 07 00 07 00 07 00 11 00 11 00 11 00 1b 00 1b 00 20 00 20 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 2f 00 2f 00 34 00 34 00 38 00 38 00 38 00 38 00 38 00 38 00 38 00 3b 00 3b 00 40 00 40 00 40 00 42 00 42 00 42 00 45 00 45 00 45 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 4b 00 4b 00 4b 00 4b 00 4b 00 50 00 50 00 |
Stream Path: \x18496\x15518\x16925\x17915, File Type: data, Stream Size: 444 |
---|
General | |
---|---|
Stream Path: | \x18496\x15518\x16925\x17915 |
File Type: | data |
Stream Size: | 444 |
Entropy: | 5.13282930045 |
Base64 Encoded: | False |
Data ASCII: | ! . E . G . H . J . L . N . O . Q . R . S . U . V . X . Z . [ . ] . _ . a . c . e . g . h . j . l . n . p . r . t . v . x . z . | . } . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . . I . K . M . N . P . Q . . . T . U . W . Y . Z . \\ . ^ . |
Data Raw: | 21 01 45 06 47 06 48 06 4a 06 4c 06 4e 06 4f 06 51 06 52 06 53 06 55 06 56 06 58 06 5a 06 5b 06 5d 06 5f 06 61 06 63 06 65 06 67 06 68 06 6a 06 6c 06 6e 06 70 06 72 06 74 06 76 06 78 06 7a 06 7c 06 7d 06 7f 06 81 06 83 06 85 06 87 06 89 06 8b 06 8d 06 8f 06 91 06 93 06 95 06 97 06 99 06 9b 06 9d 06 9f 06 a1 06 a3 06 a5 06 a6 06 a8 06 aa 06 ac 06 ae 06 b0 06 b2 06 b4 06 b6 06 b7 06 |
Stream Path: \x18496\x16191\x17783\x17516\x15210\x17892\x18468, File Type: ASCII text, with very long lines, Stream Size: 78898 |
---|
General | |
---|---|
Stream Path: | \x18496\x16191\x17783\x17516\x15210\x17892\x18468 |
File Type: | ASCII text, with very long lines |
Stream Size: | 78898 |
Entropy: | 4.87770021891 |
Base64 Encoded: | True |
Data ASCII: | A t t r i b u t e s P a t c h S i z e F i l e _ P a t c h T y p e A c t i o n C o n d i t i o n S e q u e n c e C o s t F i n a l i z e C o s t I n i t i a l i z e T a b l e N a m e I n s t a l l F i n a l i z e I n s t a l l I n i t i a l i z e I n s t a l l V a l i d a t e A d v t E x e c u t e S e q u e n c e C r e a t e S h o r t c u t s M s i P u b l i s h A s s e m b l i e s P u b l i s h C o m p o n e n t s P u b l i s h F e a t u r e s P u b l i s h P r o d u c t R e g i s t e r C l a s s I n f o R |
Data Raw: | 41 74 74 72 69 62 75 74 65 73 50 61 74 63 68 53 69 7a 65 46 69 6c 65 5f 50 61 74 63 68 54 79 70 65 41 63 74 69 6f 6e 43 6f 6e 64 69 74 69 6f 6e 53 65 71 75 65 6e 63 65 43 6f 73 74 46 69 6e 61 6c 69 7a 65 43 6f 73 74 49 6e 69 74 69 61 6c 69 7a 65 54 61 62 6c 65 4e 61 6d 65 49 6e 73 74 61 6c 6c 46 69 6e 61 6c 69 7a 65 49 6e 73 74 61 6c 6c 49 6e 69 74 69 61 6c 69 7a 65 49 6e 73 74 61 |
Stream Path: \x18496\x16191\x17783\x17516\x15978\x17586\x18479, File Type: data, Stream Size: 7240 |
---|
General | |
---|---|
Stream Path: | \x18496\x16191\x17783\x17516\x15978\x17586\x18479 |
File Type: | data |
Stream Size: | 7240 |
Entropy: | 3.45772735702 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 . . . . . . . . . . . K . . . . . * . . . . . . . . . a . . . 6 . ' . . . . . . . . . . . ` . . . . . . . . . . . $ . . . 6 . . . . . . . |
Data Raw: | e4 04 00 00 0a 00 0e 00 09 00 02 00 05 00 02 00 05 00 0d 00 04 00 04 00 06 00 12 00 09 00 28 00 08 00 10 00 0c 00 06 00 0e 00 06 00 00 00 00 00 05 00 02 00 04 00 02 00 0f 00 03 00 11 00 03 00 0f 00 04 00 13 00 07 00 0f 00 03 00 14 00 03 00 11 00 03 00 0f 00 01 00 0e 00 01 00 11 00 03 00 15 00 03 00 10 00 03 00 12 00 03 00 0c 00 05 00 07 00 02 00 06 00 02 00 06 00 02 00 0a 00 02 00 |
Stream Path: \x18496\x16255\x16740\x16943\x18486, File Type: data, Stream Size: 72 |
---|
General | |
---|---|
Stream Path: | \x18496\x16255\x16740\x16943\x18486 |
File Type: | data |
Stream Size: | 72 |
Entropy: | 3.58496250072 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . % . / . 4 . 8 . ; . @ . B . E . G . K . P . Q . S . T . V . W . Z . \\ . ^ . ` . b . f . m . p . w . x . y . . . . . . . . . |
Data Raw: | 04 00 07 00 11 00 1b 00 20 00 25 00 2f 00 34 00 38 00 3b 00 40 00 42 00 45 00 47 00 4b 00 50 00 51 00 53 00 54 00 56 00 57 00 5a 00 5c 00 5e 00 60 00 62 00 66 00 6d 00 70 00 77 00 78 00 79 00 80 00 b5 00 d3 00 d7 00 |
Stream Path: \x18496\x16383\x17380\x16876\x17892\x17580\x18481, File Type: data, Stream Size: 3936 |
---|
General | |
---|---|
Stream Path: | \x18496\x16383\x17380\x16876\x17892\x17580\x18481 |
File Type: | data |
Stream Size: | 3936 |
Entropy: | 2.54122078101 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % . % . % . % . % . % . % . % . % . % . / . / . 4 . 4 . 8 . 8 . 8 . 8 . 8 . 8 . 8 . ; . ; . @ . @ . @ . B . B . B . E . E . E . G . G . G . G . G . G . G . G . G . K . K . K . K . K . P . P . P . Q . Q . Q . Q . S . S . S . T . T . V . V . V . V . V . W . W . W . W . W . W . Z . Z . Z . Z . Z . Z . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ` . ` . ` . ` . ` . b . b . b . b . f . f . f . m . m . m . |
Data Raw: | 04 00 04 00 04 00 04 00 04 00 04 00 07 00 07 00 07 00 11 00 11 00 11 00 1b 00 1b 00 20 00 20 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 2f 00 2f 00 34 00 34 00 38 00 38 00 38 00 38 00 38 00 38 00 38 00 3b 00 3b 00 40 00 40 00 40 00 42 00 42 00 42 00 45 00 45 00 45 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 4b 00 4b 00 4b 00 4b 00 4b 00 50 00 50 00 |
Stream Path: \x18496\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481, File Type: data, Stream Size: 16 |
---|
General | |
---|---|
Stream Path: | \x18496\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481 |
File Type: | data |
Stream Size: | 16 |
Entropy: | 2.5 |
Base64 Encoded: | False |
Data ASCII: | $ . 6 . 8 . : . < . 7 . 9 . ; . |
Data Raw: | 24 06 36 06 38 06 3a 06 3c 06 37 06 39 06 3b 06 |
Stream Path: \x18496\x16667\x17191\x15090\x17912\x17591\x18481, File Type: data, Stream Size: 36 |
---|
General | |
---|---|
Stream Path: | \x18496\x16667\x17191\x15090\x17912\x17591\x18481 |
File Type: | data |
Stream Size: | 36 |
Entropy: | 3.49590659848 |
Base64 Encoded: | False |
Data ASCII: | > . > . . . . . ? . > . . . . . . . . . @ . @ . . . . . = . ? . . . . . |
Data Raw: | 3e 01 3e 01 01 80 02 80 3f 01 3e 06 05 80 05 80 05 80 19 80 40 81 40 81 14 80 0f 80 3d 06 3f 06 00 00 00 00 |
Stream Path: \x18496\x16778\x17207\x17522\x16925\x17915, File Type: data, Stream Size: 420 |
---|
General | |
---|---|
Stream Path: | \x18496\x16778\x17207\x17522\x16925\x17915 |
File Type: | data |
Stream Size: | 420 |
Entropy: | 5.04335394717 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . & . ( . / . 2 . 5 . 7 . : . < . ? . A . C . E . H . J . L . N . P . R . T . V . X . Z . \\ . ^ . . . . . . . . . . . . . . . . . . . . . + . - . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . $ . ' . ) . 0 . 3 . 6 . 8 . ; . = . @ . B . D . F . |
Data Raw: | 09 00 0a 00 10 00 12 00 13 00 14 00 15 00 16 00 17 00 18 00 19 00 1a 00 1d 01 20 01 c6 01 c8 01 cd 01 d2 01 d4 01 d9 01 db 01 e0 01 e2 01 e5 01 e6 01 e8 01 ec 01 ef 01 f2 01 f3 01 f6 01 f8 01 fb 01 fd 01 ff 01 02 02 05 02 07 02 0c 02 0f 02 11 02 13 02 17 02 1b 02 20 02 23 02 26 02 28 02 2f 02 32 02 35 02 37 02 3a 02 3c 02 3f 02 41 02 43 02 45 02 48 02 4a 02 4c 02 4e 02 50 02 52 02 |
Stream Path: \x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 48 |
---|
General | |
---|---|
Stream Path: | \x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934 |
File Type: | data |
Stream Size: | 48 |
Entropy: | 3.38186998233 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . < . . . |
Data Raw: | 09 00 0a 00 0e 00 0f 00 10 00 f2 01 f8 01 fd 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 83 20 83 c8 99 dc 85 78 85 84 83 3c 8f a0 8f |
Stream Path: \x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 66 |
---|
General | |
---|---|
Stream Path: | \x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472 |
File Type: | data |
Stream Size: | 66 |
Entropy: | 3.79732461185 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . _ . ` . a . b . c . d . e . f . . . . . . . . . . . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 09 00 0a 00 f2 01 5f 02 60 02 61 02 62 02 63 02 64 02 65 02 66 02 00 00 00 00 00 00 00 00 00 00 33 01 00 00 00 00 00 00 00 00 00 00 e8 83 20 83 84 83 00 85 ce 84 01 80 14 85 ff 7f fd 7f 8c 80 fe 7f |
Stream Path: \x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 72 |
---|
General | |
---|---|
Stream Path: | \x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472 |
File Type: | data |
Stream Size: | 72 |
Entropy: | 3.44607361183 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . j . 8 . . . \\ . $ . . . |
Data Raw: | 09 00 0a 00 0e 00 0f 00 10 00 12 00 13 00 14 00 17 00 18 00 19 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 83 20 83 c8 99 dc 85 78 85 94 91 6a 98 38 98 f8 91 5c 92 24 93 c0 92 |
Stream Path: \x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486, File Type: data, Stream Size: 4 |
---|
General | |
---|---|
Stream Path: | \x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486 |
File Type: | data |
Stream Size: | 4 |
Entropy: | 1.5 |
Base64 Encoded: | False |
Data ASCII: | # . $ . |
Data Raw: | 23 00 24 00 |
Stream Path: \x18496\x16911\x17892\x17784\x18472, File Type: data, Stream Size: 16 |
---|
General | |
---|---|
Stream Path: | \x18496\x16911\x17892\x17784\x18472 |
File Type: | data |
Stream Size: | 16 |
Entropy: | 2.22460175271 |
Base64 Encoded: | False |
Data ASCII: | # . . . # . . . . . . . $ . . . |
Data Raw: | 23 00 00 00 23 00 2e 00 01 80 01 80 24 00 00 80 |
Stream Path: \x18496\x16925\x17915\x17884\x17404\x18472, File Type: data, Stream Size: 48 |
---|
General | |
---|---|
Stream Path: | \x18496\x16925\x17915\x17884\x17404\x18472 |
File Type: | data |
Stream Size: | 48 |
Entropy: | 3.09028891162 |
Base64 Encoded: | False |
Data ASCII: | . . @ . C . D . B . A . B . B . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | a1 01 40 06 43 06 44 06 42 06 41 06 42 06 42 06 08 80 0d 80 08 80 08 80 00 00 00 80 00 00 00 80 00 00 00 80 ff ff ff 80 00 80 01 80 01 80 00 80 |
Stream Path: \x18496\x17100\x16808\x15086\x18162, File Type: data, Stream Size: 12 |
---|
General | |
---|---|
Stream Path: | \x18496\x17100\x16808\x15086\x18162 |
File Type: | data |
Stream Size: | 12 |
Entropy: | 2.35538854221 |
Base64 Encoded: | False |
Data ASCII: | . . j . k . 3 . 3 . 3 . |
Data Raw: | ba 01 6a 02 6b 02 33 01 33 01 33 01 |
Stream Path: \x18496\x17163\x16689\x18229, File Type: data, Stream Size: 60 |
---|
General | |
---|---|
Stream Path: | \x18496\x17163\x16689\x18229 |
File Type: | data |
Stream Size: | 60 |
Entropy: | 2.7112204457 |
Base64 Encoded: | False |
Data ASCII: | 5 . x . . . . . . . . . . . . . . . . . . . . . g . h . i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 35 01 78 01 9f 01 a5 01 a7 01 a9 01 ab 01 ad 01 af 01 b1 01 b5 01 be 01 67 02 68 02 69 02 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 |
Stream Path: \x18496\x17165\x16949\x17894\x17778\x18492, File Type: data, Stream Size: 12 |
---|
General | |
---|---|
Stream Path: | \x18496\x17165\x16949\x17894\x17778\x18492 |
File Type: | data |
Stream Size: | 12 |
Entropy: | 2.68872187554 |
Base64 Encoded: | False |
Data ASCII: | $ . . . . . . . . . . . |
Data Raw: | 24 00 a4 02 a4 02 00 00 96 03 95 03 |
Stream Path: \x18496\x17165\x17380\x17074, File Type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.163, Stream Size: 616 |
---|
General | |
---|---|
Stream Path: | \x18496\x17165\x17380\x17074 |
File Type: | MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.163 |
Stream Size: | 616 |
Entropy: | 4.17798348327 |
Base64 Encoded: | False |
Data ASCII: | c . _ . ` . c . d . e . f . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . " . ' . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . . . r . r . r . r . r . r . r . r . r . ( . r . r . r . . . r . r . r . r . r . r . r . r . r . r . r . r . . . i . . . . . . . . . . . . . . . . . . . G . . . . . . . U . . . |
Data Raw: | 63 01 5f 02 60 02 63 02 64 02 65 02 66 02 6c 02 83 02 9b 02 9f 02 a3 02 b3 02 b8 02 ba 02 c3 02 d8 02 fb 02 05 03 09 03 0d 03 10 03 18 03 1a 03 1e 03 21 03 22 03 27 03 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 |
Stream Path: \x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 432 |
---|
General | |
---|---|
Stream Path: | \x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934 |
File Type: | data |
Stream Size: | 432 |
Entropy: | 5.74288381672 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . & . ( . / . 2 . 7 . : . < . ? . A . C . E . H . J . L . N . P . R . T . V . X . Z . \\ . ^ . i . t . x . { . } . ~ . . . . . . . . . . . % . ' . 0 . . . . . . . . . . . . . . . . . . . * . . . . . . . # . . . $ . # . . . 6 . . . $ . . . . . . . 6 . . . ) . . . & . . . . . 6 . / . . . . . 6 . . . . . . . . . & . + . . . . . , . . . 6 . 6 . $ . $ . 6 . . . 6 . 6 . 6 . 6 . |
Data Raw: | 09 00 0a 00 0e 00 0f 00 10 00 12 00 13 00 14 00 17 00 18 00 19 00 1a 00 1d 01 20 01 c6 01 c8 01 d4 01 e0 01 e2 01 e8 01 ec 01 ef 01 f2 01 f3 01 fb 01 fd 01 ff 01 02 02 05 02 0c 02 0f 02 11 02 13 02 20 02 23 02 26 02 28 02 2f 02 32 02 37 02 3a 02 3c 02 3f 02 41 02 43 02 45 02 48 02 4a 02 4c 02 4e 02 50 02 52 02 54 02 56 02 58 02 5a 02 5c 02 5e 02 69 02 74 03 78 03 7b 03 7d 03 7e 03 |
Stream Path: \x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 180 |
---|
General | |
---|---|
Stream Path: | \x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472 |
File Type: | data |
Stream Size: | 180 |
Entropy: | 5.09930005046 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . _ . b . c . d . e . f . . . . . . . " . t . v . x . } . ~ . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . 3 . . . . . 4 . = . A . B . < . 5 . . . . . . . . . . . B . 2 . # . 1 . ) . - . . . . d . . . . . . . L . . . . . . . . . K . . . . . . . . . . . . . 4 . 3 . 5 . . . . . . . . . . . . . . . . . . . |
Data Raw: | 09 00 0a 00 1d 01 20 01 f2 01 f3 01 0c 02 5f 02 62 02 63 02 64 02 65 02 66 02 9b 02 10 03 18 03 22 03 74 03 76 03 78 03 7d 03 7e 03 84 03 86 03 8a 03 8d 03 8e 03 8f 03 90 03 91 03 00 00 00 00 00 00 23 06 00 00 00 00 00 00 00 00 00 00 33 06 00 00 00 00 34 06 3d 03 41 03 42 03 3c 03 35 06 00 00 00 00 00 00 20 06 20 06 2e 06 42 03 32 06 23 06 31 06 29 06 2d 06 e8 83 20 83 64 80 90 81 |
Stream Path: \x18496\x17547\x17906\x17910\x16693\x17651\x17768\x15518\x16924\x17972\x17512\x16934, File Type: SVr4 curses screen image, little-endian, Stream Size: 54 |
---|
General | |
---|---|
Stream Path: | \x18496\x17547\x17906\x17910\x16693\x17651\x17768\x15518\x16924\x17972\x17512\x16934 |
File Type: | SVr4 curses screen image, little-endian |
Stream Size: | 54 |
Entropy: | 3.87852986267 |
Base64 Encoded: | False |
Data ASCII: | . . . . . ! . # . $ . & . ' . ( . . . . . . . " . " . % . % . " . ) . . . , . ^ . . . . . X . . . . . . |
Data Raw: | 1d 01 1f 01 20 01 21 01 23 01 24 01 26 01 27 01 28 01 1e 01 1e 01 1e 01 22 01 22 01 25 01 25 01 22 01 29 01 fa 80 2c 81 5e 81 90 81 c2 81 58 82 8a 82 bc 82 20 83 |
Stream Path: \x18496\x17548\x17648\x17522\x17512\x18487, File Type: data, Stream Size: 12 |
---|
General | |
---|---|
Stream Path: | \x18496\x17548\x17648\x17522\x17512\x18487 |
File Type: | data |
Stream Size: | 12 |
Entropy: | 1.04085208297 |
Base64 Encoded: | False |
Data ASCII: | $ . . . $ . . . . . . . |
Data Raw: | 24 00 00 00 24 00 00 80 00 00 00 00 |
Stream Path: \x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522, File Type: data, Stream Size: 72 |
---|
General | |
---|---|
Stream Path: | \x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522 |
File Type: | data |
Stream Size: | 72 |
Entropy: | 3.42994500824 |
Base64 Encoded: | False |
Data ASCII: | c . c . c . c . d . d . . . . . . . . . . . . . . . . . . . t . . . . . 5 . 5 . 5 . 5 . 9 . 9 . 5 . 5 . 5 . 8 . 8 . 7 . 7 . : . : . 6 . 6 . 6 . |
Data Raw: | 63 02 63 02 63 02 63 02 64 02 64 02 c3 02 c3 02 c3 02 eb 02 ed 02 ef 02 f1 02 f7 02 f8 02 74 02 cb 02 cd 02 35 03 35 03 35 03 35 03 39 03 39 03 35 03 35 03 35 03 38 03 38 03 37 03 37 03 3a 03 3a 03 36 03 36 03 36 03 |
Stream Path: \x18496\x17548\x17905\x17589\x15279\x16953\x17905, File Type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.99, Stream Size: 1536 |
---|
General | |
---|---|
Stream Path: | \x18496\x17548\x17905\x17589\x15279\x16953\x17905 |
File Type: | MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.99 |
Stream Size: | 1536 |
Entropy: | 4.98673799888 |
Base64 Encoded: | False |
Data ASCII: | c . c . c . c . c . c . c . _ . ` . ` . ` . c . c . c . c . d . d . d . e . f . f . l . l . l . l . l . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . ! . ! . ! . ! . ! . ! . ! . ! . ! . ! . ! . " . " . ' . |
Data Raw: | 63 01 63 01 63 01 63 01 63 01 63 01 63 01 5f 02 60 02 60 02 60 02 63 02 63 02 63 02 63 02 64 02 64 02 64 02 65 02 66 02 66 02 6c 02 6c 02 6c 02 6c 02 6c 02 6c 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 9b 02 9b 02 9b 02 9f 02 a3 02 a3 02 a3 02 a3 02 a3 02 a3 02 b3 02 b3 02 b3 02 b3 02 b3 02 b8 02 b8 02 |
Stream Path: \x18496\x17548\x17905\x17589\x18479, File Type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.95, Stream Size: 7280 |
---|
General | |
---|---|
Stream Path: | \x18496\x17548\x17905\x17589\x18479 |
File Type: | MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.95 |
Stream Size: | 7280 |
Entropy: | 4.53364756052 |
Base64 Encoded: | False |
Data ASCII: | c . c . c . c . c . c . c . c . c . _ . _ . _ . _ . _ . _ . _ . _ . _ . _ . _ . _ . ` . ` . ` . ` . ` . ` . ` . c . c . c . c . c . c . c . c . c . c . c . d . d . d . d . d . d . d . d . d . d . e . e . e . e . e . e . e . e . e . f . f . f . f . f . f . f . f . l . l . l . l . l . l . l . l . l . l . l . l . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 63 01 63 01 63 01 63 01 63 01 63 01 63 01 63 01 63 01 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 60 02 60 02 60 02 60 02 60 02 60 02 60 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 65 02 65 02 65 02 65 02 65 02 65 02 65 02 65 02 65 02 66 02 66 02 66 02 66 02 66 02 66 02 |
Stream Path: \x18496\x17630\x17770\x16868\x18472, File Type: x86 executable, Stream Size: 32 |
---|
General | |
---|---|
Stream Path: | \x18496\x17630\x17770\x16868\x18472 |
File Type: | x86 executable |
Stream Size: | 32 |
Entropy: | 2.76201589562 |
Base64 Encoded: | False |
Data ASCII: | H . H . ; . . . . . ; . . . . . . . . . . . . . . . . . 5 . . . |
Data Raw: | 48 01 48 01 3b 01 10 07 00 00 3b 01 00 00 00 00 02 00 00 80 01 01 00 80 00 00 00 00 35 06 11 07 |
Stream Path: \x18496\x17740\x16680\x16951\x17551\x16879\x17768, File Type: data, Stream Size: 4 |
---|
General | |
---|---|
Stream Path: | \x18496\x17740\x16680\x16951\x17551\x16879\x17768 |
File Type: | data |
Stream Size: | 4 |
Entropy: | 1.0 |
Base64 Encoded: | False |
Data ASCII: | $ . $ . |
Data Raw: | 24 00 24 00 |
Stream Path: \x18496\x17742\x17589\x18485, File Type: data, Stream Size: 2572 |
---|
General | |
---|---|
Stream Path: | \x18496\x17742\x17589\x18485 |
File Type: | data |
Stream Size: | 2572 |
Entropy: | 6.54317952801 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . . M . . . . . . . . . . . . . . . . . . . . . . . . ! . " . # . $ . % . & . ' . ( . ) . * . + . , . - . . . / . 0 . 1 . 2 . 3 . 4 . 5 . 6 . 7 . 8 . y . z . { . | . } . ~ . . . . . . . . . . . . . . . . . A . B . C . D . E . F . G . H . I . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . m . n . o . p . |
Data Raw: | 00 80 01 80 02 80 03 80 04 80 05 80 06 80 07 80 08 80 09 80 0a 80 0b 80 0c 80 0d 80 0e 80 0f 80 10 80 11 80 12 80 13 80 14 80 15 80 16 80 17 80 20 80 21 80 e9 83 4d 84 15 85 16 85 17 85 18 85 19 85 1a 85 1b 85 1c 85 1d 85 1e 85 1f 85 20 85 21 85 22 85 23 85 24 85 25 85 26 85 27 85 28 85 29 85 2a 85 2b 85 2c 85 2d 85 2e 85 2f 85 30 85 31 85 32 85 33 85 34 85 35 85 36 85 37 85 38 85 |
Stream Path: \x18496\x17753\x17650\x17768\x18231, File Type: data, Stream Size: 340 |
---|
General | |
---|---|
Stream Path: | \x18496\x17753\x17650\x17768\x18231 |
File Type: | data |
Stream Size: | 340 |
Entropy: | 4.62234252689 |
Base64 Encoded: | False |
Data ASCII: | . . . . * . , . . . 0 . 2 . 4 . 6 . 8 . : . < . > . @ . A . C . E . G . I . K . L . O . Q . R . T . V . W . X . Y . [ . ] . _ . ` . b . d . f . h . j . k . m . o . q . s . u . w . z . | . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . H . N . + . - . / . 1 . 3 . 5 . 7 . 9 . ; . = . ? . 3 . B . D . F . D . J . F . M . P . P . S . U . U . X . y . Z . \\ . ^ . \\ . a . c . e . g . i . 3 . l . n . p . r . t . |
Data Raw: | b1 00 01 01 2a 01 2c 01 2e 01 30 01 32 01 34 01 36 01 38 01 3a 01 3c 01 3e 01 40 01 41 01 43 01 45 01 47 01 49 01 4b 01 4c 01 4f 01 51 01 52 01 54 01 56 01 57 01 58 01 59 01 5b 01 5d 01 5f 01 60 01 62 01 64 01 66 01 68 01 6a 01 6b 01 6d 01 6f 01 71 01 73 01 75 01 77 01 7a 01 7c 01 7e 01 80 01 82 01 84 01 86 01 88 01 8a 01 8c 01 8e 01 90 01 92 01 93 01 95 01 97 01 98 01 9a 01 9c 01 |
Stream Path: \x18496\x17932\x17910\x17458\x16778\x17207\x17522, File Type: data, Stream Size: 240 |
---|
General | |
---|---|
Stream Path: | \x18496\x17932\x17910\x17458\x16778\x17207\x17522 |
File Type: | data |
Stream Size: | 240 |
Entropy: | 3.68898065651 |
Base64 Encoded: | False |
Data ASCII: | a . i . Y . e . t . v . x . { . } . ~ . . . . . . . . . . . . . . . . . . . . . 3 . . . . . A . . . . . A . A . . . A . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . . . . . i . g . g . . . g . g . g . g . g . . . $ . . . . . < . B . < . = . A . g . 3 . . . z . . . u . w . y . | . } . . . . . . . . . . . . . 3 . 3 . 3 . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 61 02 69 02 59 03 65 03 74 03 76 03 78 03 7b 03 7d 03 7e 03 81 03 84 03 86 03 88 03 8a 03 8d 03 8e 03 8f 03 90 03 91 03 33 80 01 80 01 80 41 80 13 80 01 80 41 81 41 80 01 80 41 80 33 80 33 81 33 81 33 80 33 80 33 80 33 80 33 80 33 80 01 80 8c 03 69 02 67 02 67 02 00 00 67 02 67 02 67 02 67 02 67 02 82 03 24 00 87 03 a4 02 3c 03 42 03 3c 03 3d 03 41 03 67 02 33 01 89 03 7a 03 80 03 |
Stream Path: \x18496\x17998\x17512\x15799\x17636\x17203\x17073, File Type: data, Stream Size: 128 |
---|
General | |
---|---|
Stream Path: | \x18496\x17998\x17512\x15799\x17636\x17203\x17073 |
File Type: | data |
Stream Size: | 128 |
Entropy: | 4.11408297472 |
Base64 Encoded: | False |
Data ASCII: | _ . _ . e . e . . . . . . . . . . . . . . . . . . . . . . . . . B . . . B . . . B . . . . . . . . . . . . . . . . . . . . . . . B . . . B . . . B . . . . . . . . . . . . . . . . . . . . . . . < . . . < . < . < . . . . . . . . . . . . . . . < . . . < . < . |
Data Raw: | 5f 02 5f 02 65 02 65 02 9f 02 9f 02 a3 02 b8 02 c3 02 c3 02 c3 02 c3 02 c3 02 c3 02 c3 02 c3 02 42 00 a0 02 42 00 14 03 42 00 a0 02 a8 02 a8 02 81 01 c7 02 c9 02 cb 02 cd 02 cd 02 d2 02 d4 02 42 00 15 06 42 00 14 03 42 00 15 06 17 06 17 06 18 06 18 06 18 06 1d 06 1c 06 1d 06 1b 06 1a 06 3c 00 16 06 3c 00 3c 00 3c 00 16 06 17 06 17 06 19 06 19 06 19 06 1e 06 3c 00 1e 06 3c 00 3c 00 |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 30, 2021 14:23:55.681875944 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:55.704962969 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.705121040 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:55.713620901 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:55.737919092 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.737951994 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.738030910 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.738046885 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.738142014 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:55.746073961 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:55.769239902 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.772831917 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:55.828044891 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:56.309103966 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:56.332580090 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.518338919 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.518378019 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.580656052 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:56.600362062 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.600469112 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:56.600496054 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:56.623593092 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.888870001 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.888901949 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:23:56.889061928 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:23:56.932391882 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:56.955691099 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:56.955810070 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:56.956268072 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:56.979582071 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:56.992074966 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:56.992113113 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:56.992136002 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:56.992280006 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:56.998800039 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.023611069 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.024528980 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.027854919 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.051068068 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.781831980 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.781867027 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.781878948 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.781894922 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.781912088 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.781928062 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.782042027 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.783576012 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.783597946 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.783673048 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.786345005 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.786369085 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.786438942 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.787452936 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.787475109 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.787533045 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.789114952 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.789139986 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.789221048 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:23:57.805515051 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:23:57.859430075 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:25:17.890589952 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:25:17.890620947 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:25:17.890743017 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:25:17.891783953 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:25:17.891822100 CEST | 49736 | 443 | 192.168.2.4 | 162.125.65.18 |
Aug 30, 2021 14:25:17.914962053 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:25:17.914980888 CEST | 443 | 49736 | 162.125.65.18 | 192.168.2.4 |
Aug 30, 2021 14:25:18.783674002 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:25:18.783709049 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:25:18.783919096 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:25:18.784115076 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:25:18.784182072 CEST | 49737 | 443 | 192.168.2.4 | 162.125.65.15 |
Aug 30, 2021 14:25:18.807580948 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
Aug 30, 2021 14:25:18.807629108 CEST | 443 | 49737 | 162.125.65.15 | 192.168.2.4 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 30, 2021 14:23:32.458566904 CEST | 53 | 58028 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:23:32.692558050 CEST | 53097 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:23:32.733536005 CEST | 53 | 53097 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:23:35.128690004 CEST | 49257 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:23:35.166141033 CEST | 53 | 49257 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:23:55.636085033 CEST | 62389 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:23:55.671299934 CEST | 53 | 62389 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:23:56.893455029 CEST | 49910 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:23:56.931031942 CEST | 53 | 49910 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:06.379709959 CEST | 55854 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:06.423870087 CEST | 53 | 55854 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:24.293128014 CEST | 64549 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:24.403808117 CEST | 53 | 64549 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:25.234452009 CEST | 63153 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:25.337203979 CEST | 53 | 63153 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:25.823318958 CEST | 52991 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:25.864193916 CEST | 53 | 52991 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:26.150804996 CEST | 53700 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:26.183402061 CEST | 53 | 53700 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:27.026832104 CEST | 51726 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:27.053077936 CEST | 56794 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:27.063266993 CEST | 53 | 51726 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:27.081921101 CEST | 53 | 56794 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:27.899326086 CEST | 56534 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:27.932271004 CEST | 53 | 56534 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:28.681787014 CEST | 56627 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:28.717428923 CEST | 53 | 56627 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:29.903620005 CEST | 56621 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:29.928581953 CEST | 53 | 56621 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:31.215326071 CEST | 63116 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:31.251028061 CEST | 53 | 63116 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:32.494565964 CEST | 64078 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:32.530257940 CEST | 53 | 64078 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:34.281099081 CEST | 64801 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:34.316649914 CEST | 53 | 64801 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:41.484410048 CEST | 61721 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:41.486259937 CEST | 51255 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:41.531339884 CEST | 53 | 61721 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:41.536827087 CEST | 53 | 51255 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:24:44.597460985 CEST | 61522 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:24:44.640105009 CEST | 53 | 61522 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:25:16.144350052 CEST | 52337 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:25:16.187133074 CEST | 53 | 52337 | 8.8.8.8 | 192.168.2.4 |
Aug 30, 2021 14:25:17.372715950 CEST | 55046 | 53 | 192.168.2.4 | 8.8.8.8 |
Aug 30, 2021 14:25:17.416802883 CEST | 53 | 55046 | 8.8.8.8 | 192.168.2.4 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Aug 30, 2021 14:23:55.636085033 CEST | 192.168.2.4 | 8.8.8.8 | 0x67b8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Aug 30, 2021 14:23:56.893455029 CEST | 192.168.2.4 | 8.8.8.8 | 0x27f6 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Aug 30, 2021 14:23:55.671299934 CEST | 8.8.8.8 | 192.168.2.4 | 0x67b8 | No error (0) | www-env.dropbox-dns.com | CNAME (Canonical name) | IN (0x0001) | ||
Aug 30, 2021 14:23:55.671299934 CEST | 8.8.8.8 | 192.168.2.4 | 0x67b8 | No error (0) | 162.125.65.18 | A (IP address) | IN (0x0001) | ||
Aug 30, 2021 14:23:56.931031942 CEST | 8.8.8.8 | 192.168.2.4 | 0x27f6 | No error (0) | edge-block-www-env.dropbox-dns.com | CNAME (Canonical name) | IN (0x0001) | ||
Aug 30, 2021 14:23:56.931031942 CEST | 8.8.8.8 | 192.168.2.4 | 0x27f6 | No error (0) | 162.125.65.15 | A (IP address) | IN (0x0001) |
HTTPS Packets |
---|
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Aug 30, 2021 14:23:55.738046885 CEST | 162.125.65.18 | 443 | 192.168.2.4 | 49736 | CN=*.dropbox.com, O="Dropbox, Inc", L=San Francisco, ST=California, C=US CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Tue Oct 27 01:00:00 CET 2020 Tue Oct 22 14:00:00 CEST 2013 | Mon Nov 22 00:59:59 CET 2021 Sun Oct 22 14:00:00 CEST 2028 | 771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0 | ce5f3254611a8c095a3d821d44539877 |
CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Tue Oct 22 14:00:00 CEST 2013 | Sun Oct 22 14:00:00 CEST 2028 | |||||||
Aug 30, 2021 14:23:56.992136002 CEST | 162.125.65.15 | 443 | 192.168.2.4 | 49737 | CN=*.dl.dropboxusercontent.com, O="Dropbox, Inc", L=San Francisco, ST=California, C=US CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US | CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Tue Jan 19 01:00:00 CET 2021 Thu Sep 24 02:00:00 CEST 2020 | Tue Feb 15 00:59:59 CET 2022 Tue Sep 24 01:59:59 CEST 2030 | 771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0 | ce5f3254611a8c095a3d821d44539877 |
CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US | CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Thu Sep 24 02:00:00 CEST 2020 | Tue Sep 24 01:59:59 CEST 2030 |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 14:23:40 |
Start date: | 30/08/2021 |
Path: | C:\Windows\System32\msiexec.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff777c90000 |
File size: | 66048 bytes |
MD5 hash: | 4767B71A318E201188A0D0A420C8B608 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 14:23:41 |
Start date: | 30/08/2021 |
Path: | C:\Windows\SysWOW64\msiexec.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe70000 |
File size: | 59904 bytes |
MD5 hash: | 12C17B5A5C2A7B97342C362CA467E9A2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 14:23:46 |
Start date: | 30/08/2021 |
Path: | C:\Windows\SysWOW64\wbem\WMIC.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xeb0000 |
File size: | 391680 bytes |
MD5 hash: | 79A01FCD1C8166C5642F37D1E0FB7BA8 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 14:23:46 |
Start date: | 30/08/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff724c50000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Disassembly |
---|
Code Analysis |
---|