Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
file.exe (PID: 2556 cmdline:
C:\Users\u ser\Deskto p\file.exe MD5: 734FCB6992CC87731801713D81F0D557) WMIC.exe (PID: 5136 cmdline:
wmic os ge t Caption MD5: EC80E603E0090B3AC3C1234C2BA43A0F) conhost.exe (PID: 5124 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) cmd.exe (PID: 5208 cmdline:
cmd /C "wm ic path wi n32_VideoC ontroller get name" MD5: 4E2ACF4F8A396486AB4268C94A6A245F) conhost.exe (PID: 5176 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) WMIC.exe (PID: 5248 cmdline:
wmic path win32_Vide oControlle r get name MD5: EC80E603E0090B3AC3C1234C2BA43A0F) cmd.exe (PID: 1392 cmdline:
cmd /C "wm ic cpu get name" MD5: 4E2ACF4F8A396486AB4268C94A6A245F) conhost.exe (PID: 1372 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496) WMIC.exe (PID: 4504 cmdline:
wmic cpu g et name MD5: EC80E603E0090B3AC3C1234C2BA43A0F)
- cleanup
- • AV Detection
- • Compliance
- • Spreading
- • Networking
- • Key, Mouse, Clipboard, Microphone and Screen Capturing
- • System Summary
- • Data Obfuscation
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Anti Debugging
- • HIPS / PFW / Operating System Protection Evasion
- • Language, Device and Operating System Detection
- • Stealing of Sensitive Information
Click to jump to signature section
AV Detection |
---|
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | WMI Queries: |
Source: | Classification label: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | System information queried: | Jump to behavior |
Source: | WMI Queries: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 11 Windows Management Instrumentation | Path Interception | 11 Process Injection | 1 Virtualization/Sandbox Evasion | 1 OS Credential Dumping | 1 System Time Discovery | Remote Services | 11 Input Capture | Exfiltration Over Other Network Medium | 1 Non-Standard Port | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 11 Process Injection | 11 Input Capture | 11 Security Software Discovery | Remote Desktop Protocol | 2 Data from Local System | Exfiltration Over Bluetooth | Junk Data | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | 1 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Steganography | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 13 System Information Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
176.124.220.67 | unknown | Russian Federation | 59652 | GULFSTREAMUA | false |
Joe Sandbox Version: | 36.0.0 Rainbow Opal |
Analysis ID: | 729270 |
Start date and time: | 2022-10-24 16:26:05 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | file.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal52.spyw.winEXE@14/0@0/1 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S grmBroker.exe, conhost.exe, sv chost.exe - Excluded domains from analysis
(whitelisted): fs.microsoft.c om - Execution Graph export aborted
for target file.exe, PID 2556 because there are no executed function - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtCreateFile calls fou nd. - Report size getting too big, t
oo many NtOpenFile calls found . - Report size getting too big, t
oo many NtProtectVirtualMemory calls found.
Time | Type | Description |
---|---|---|
16:27:07 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
GULFSTREAMUA | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
File type: | |
Entropy (8bit): | 6.247898286881813 |
TrID: |
|
File name: | file.exe |
File size: | 4847238 |
MD5: | 734fcb6992cc87731801713d81f0d557 |
SHA1: | bf9a42ff5ec69d7945ddee72dd0ffc0315e2ff39 |
SHA256: | 398df90a42c7b3cc43ea5095630ef3d8cf059beeda54e6a5888c839f5d6f5055 |
SHA512: | 3b5883f8fd9e3030726b0d8f7884d270b74ea1e99b0c07ecf6fc17164ef2c339c3e38a793ae9e384936eed65363f1b64f6d14f4a1a5c0bfee7f3e2359cdf48b2 |
SSDEEP: | 98304:ezAv5Q+EAG8l6EW3gWVup6aaIb7b7YEKtayr4dZ1YnvkMK83LhJokenV6Iq2K7z4:eE0u1 |
TLSH: | 12262847F89980F5C1AED1308A268253BA723C991B3063D73B51F7B86B73BD46A79314 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.........F......."......."..........^........@..............................pP......PJ...`... ............................ |
Icon Hash: | 0030303038181800 |
Entrypoint: | 0x465e80 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, DEBUG_STRIPPED |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x0 [Thu Jan 1 00:00:00 1970 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 1 |
File Version Major: | 6 |
File Version Minor: | 1 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 1 |
Import Hash: | 9cbefe68f395e67356e2a5d8d1b285c0 |
Instruction |
---|
jmp 00007F5270BB25E0h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
pushfd |
cld |
dec eax |
sub esp, 000000E0h |
dec eax |
mov dword ptr [esp], edi |
dec eax |
mov dword ptr [esp+08h], esi |
dec eax |
mov dword ptr [esp+10h], ebp |
dec eax |
mov dword ptr [esp+18h], ebx |
dec esp |
mov dword ptr [esp+20h], esp |
dec esp |
mov dword ptr [esp+28h], ebp |
dec esp |
mov dword ptr [esp+30h], esi |
dec esp |
mov dword ptr [esp+38h], edi |
movups dqword ptr [esp+40h], xmm6 |
movups dqword ptr [esp+50h], xmm7 |
inc esp |
movups dqword ptr [esp+60h], xmm0 |
inc esp |
movups dqword ptr [esp+70h], xmm1 |
inc esp |
movups dqword ptr [esp+00000080h], xmm2 |
inc esp |
movups dqword ptr [esp+00000090h], xmm3 |
inc esp |
movups dqword ptr [esp+000000A0h], xmm4 |
inc esp |
movups dqword ptr [esp+000000B0h], xmm5 |
inc esp |
movups dqword ptr [esp+000000C0h], xmm6 |
inc esp |
movups dqword ptr [esp+000000D0h], xmm7 |
dec eax |
sub esp, 30h |
dec ecx |
mov edi, eax |
dec eax |
mov edx, dword ptr [00000028h] |
dec eax |
cmp edx, 00000000h |
jne 00007F5270BB610Eh |
dec eax |
mov eax, 00000000h |
jmp 00007F5270BB6185h |
dec eax |
mov edx, dword ptr [edx+00000000h] |
dec eax |
cmp edx, 00000000h |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x4bb000 | 0x47c | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4c7000 | 0x3f0b8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x4bc000 | 0x99c0 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x41b240 | 0x140 | .data |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x22a815 | 0x22aa00 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x22c000 | 0x1ee6a0 | 0x1ee800 | False | 0.39460728166076847 | data | 5.582119832029706 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x41b000 | 0x9fdc0 | 0x3ca00 | False | 0.41630557345360825 | data | 5.300196718182688 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0x4bb000 | 0x47c | 0x600 | False | 0.33203125 | data | 3.567258212132925 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x4bc000 | 0x99c0 | 0x9a00 | False | 0.276760349025974 | data | 5.43709646464519 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.symtab | 0x4c6000 | 0x4 | 0x200 | False | 0.02734375 | data | 0.020393135236084953 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4c7000 | 0x3f0b8 | 0x3f200 | False | 0.03193842821782178 | data | 5.600157130601035 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x4c70ac | 0x3eff8 | Device independent bitmap graphic, 250 x 500 x 32, image size 250000, resolution 3779 x 3779 px/m | ||
RT_GROUP_ICON | 0x5060a4 | 0x14 | data |
DLL | Import |
---|---|
kernel32.dll | WriteFile, WriteConsoleW, WaitForMultipleObjects, WaitForSingleObject, VirtualQuery, VirtualFree, VirtualAlloc, SwitchToThread, SuspendThread, SetWaitableTimer, SetUnhandledExceptionFilter, SetProcessPriorityBoost, SetEvent, SetErrorMode, SetConsoleCtrlHandler, ResumeThread, PostQueuedCompletionStatus, LoadLibraryA, LoadLibraryW, SetThreadContext, GetThreadContext, GetSystemInfo, GetSystemDirectoryA, GetStdHandle, GetQueuedCompletionStatusEx, GetProcessAffinityMask, GetProcAddress, GetEnvironmentStringsW, GetConsoleMode, FreeEnvironmentStringsW, ExitProcess, DuplicateHandle, CreateWaitableTimerExW, CreateThread, CreateIoCompletionPort, CreateFileA, CreateEventA, CloseHandle, AddVectoredExceptionHandler |
Download Network PCAP: filtered – full
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 24, 2022 16:27:08.139823914 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:08.201853037 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:08.204988956 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.520391941 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.582638979 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.582674026 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.582916021 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.644821882 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.644844055 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.644879103 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.644893885 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.644984961 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.645031929 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.645081997 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.645129919 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.707688093 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.707715034 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.707730055 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.707871914 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.707886934 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.707890034 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.707904100 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.707968950 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.708012104 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.708030939 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.708045959 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.708055019 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.708055019 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.708096027 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.708096981 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.708132982 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.770565987 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770607948 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770627975 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770646095 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770663977 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770678997 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770709038 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770775080 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.770775080 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.770821095 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770901918 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.770910025 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.770962954 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.770962954 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771012068 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771012068 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771379948 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771452904 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771502972 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771552086 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771574020 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771630049 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771656036 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771732092 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771761894 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771776915 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771820068 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771852970 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.771862030 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771886110 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771907091 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.771960974 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772000074 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772000074 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772053957 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772104025 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772130013 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772155046 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772172928 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772233009 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772241116 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772254944 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772321939 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772351027 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772381067 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772402048 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772420883 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.772623062 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.772670031 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.812421083 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.812582970 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.832720995 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.832748890 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.832767963 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.832779884 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.832796097 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.832832098 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.832923889 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.832950115 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833019972 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833046913 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833072901 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833097935 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833116055 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833161116 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833187103 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833199024 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833220959 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833264112 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833297014 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833300114 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833357096 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833378077 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833440065 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833452940 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833512068 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833575010 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833655119 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833709955 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833769083 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833899021 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833950043 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.833987951 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.833997011 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834024906 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834076881 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834084034 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834095955 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834146976 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834193945 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834198952 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834198952 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834213018 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834250927 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834250927 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834280014 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834321022 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834338903 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834383011 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834387064 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834407091 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834415913 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834450960 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834455967 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834481955 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834543943 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834618092 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834682941 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834693909 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834764957 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834827900 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834846020 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834894896 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834912062 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.834925890 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.834988117 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835050106 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835069895 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835117102 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835119963 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835120916 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835135937 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835175037 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835185051 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835206032 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835235119 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835254908 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835266113 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835304022 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835304976 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835333109 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835381031 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835390091 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835428953 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835455894 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835483074 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835506916 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835525036 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835566044 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835592031 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835628033 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835681915 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835793018 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835810900 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835860014 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835879087 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835912943 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835932970 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.835936069 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835936069 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835977077 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.835999012 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:15.836049080 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836153030 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836199045 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836308956 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836327076 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836374998 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836452961 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836555958 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836661100 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.836678982 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.874608994 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.894874096 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895131111 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895148039 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895160913 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895173073 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895185947 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895255089 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895418882 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895432949 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895576954 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895590067 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895733118 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895903111 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.895921946 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896068096 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896083117 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896096945 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896229982 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896245003 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896260977 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896378994 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896394014 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896542072 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.896692991 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897066116 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897082090 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897095919 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897108078 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897120953 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897133112 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897229910 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897284031 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897414923 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897511959 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897597075 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.897670031 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.898546934 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.898569107 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.900530100 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.900743961 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901052952 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901073933 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901118994 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901154995 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901204109 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901222944 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901592016 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901618004 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901635885 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901654005 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901673079 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901691914 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901710033 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901727915 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.901746988 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902223110 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902252913 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902271986 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902319908 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902522087 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902543068 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902564049 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902651072 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902673006 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902760983 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902939081 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902961969 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902981043 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.902998924 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.903055906 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.903104067 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.915740967 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:15.959901094 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:18.746762991 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:18.746912003 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:18.808749914 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808778048 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808789968 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808805943 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808849096 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808862925 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808876038 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808952093 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.808964968 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809009075 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809149981 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809221029 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809253931 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809359074 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809393883 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.809540033 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.816302061 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.847671032 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:18.909586906 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909609079 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909622908 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909636021 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909692049 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909771919 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909852028 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909877062 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.909971952 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.915534019 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:18.959512949 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:19.101619005 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:19.101800919 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:19.101895094 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:19.163708925 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.163753033 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.163769960 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.163822889 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.163932085 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164058924 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164223909 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164381027 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164484024 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164619923 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164741039 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.164858103 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.165021896 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.165271997 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.165637970 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.165811062 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.165868998 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.166021109 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.166183949 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.172410965 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:19.223817110 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:25.806915045 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:25.870055914 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:25.870776892 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Oct 24, 2022 16:27:25.870841980 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:25.870841980 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:26.199008942 CEST | 49705 | 8081 | 192.168.2.6 | 176.124.220.67 |
Oct 24, 2022 16:27:26.260819912 CEST | 8081 | 49705 | 176.124.220.67 | 192.168.2.6 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 16:27:05 |
Start date: | 24/10/2022 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x1030000 |
File size: | 4847238 bytes |
MD5 hash: | 734FCB6992CC87731801713D81F0D557 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 1 |
Start time: | 16:27:07 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\wbem\WMIC.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77e4d0000 |
File size: | 521728 bytes |
MD5 hash: | EC80E603E0090B3AC3C1234C2BA43A0F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 2 |
Start time: | 16:27:07 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6da640000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 3 |
Start time: | 16:27:09 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7cb270000 |
File size: | 273920 bytes |
MD5 hash: | 4E2ACF4F8A396486AB4268C94A6A245F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 4 |
Start time: | 16:27:09 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6da640000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 5 |
Start time: | 16:27:09 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\wbem\WMIC.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77e4d0000 |
File size: | 521728 bytes |
MD5 hash: | EC80E603E0090B3AC3C1234C2BA43A0F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 6 |
Start time: | 16:27:10 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7cb270000 |
File size: | 273920 bytes |
MD5 hash: | 4E2ACF4F8A396486AB4268C94A6A245F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 7 |
Start time: | 16:27:10 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6da640000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Target ID: | 8 |
Start time: | 16:27:10 |
Start date: | 24/10/2022 |
Path: | C:\Windows\System32\wbem\WMIC.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77e4d0000 |
File size: | 521728 bytes |
MD5 hash: | EC80E603E0090B3AC3C1234C2BA43A0F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |