Windows
Analysis Report
PROD_Start_DriverPack.hta
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Multi AV Scanner detection for domain / URL
Writes or reads registry keys via WMI
Queries the volume information (name, serial number etc) of a device
Searches for the Microsoft Outlook file path
Uses a known web browser user agent for HTTP communication
IP address seen in connection with other malware
Classification
- System is w10x64
mshta.exe (PID: 4764 cmdline:
mshta.exe "C:\Users\ user\Deskt op\PROD_St art_Driver Pack.hta" MD5: 7083239CE743FDB68DFC933B7308E80A)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • AV Detection
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Anti Debugging
- • Language, Device and Operating System Detection
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 1 Windows Management Instrumentation | Path Interception | Path Interception | 1 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | 1 Email Collection | Exfiltration Over Other Network Medium | 3 Non-Application Layer Protocol | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 13 Application Layer Protocol | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | 12 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 3 Ingress Tool Transfer | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | Binary Padding | NTDS | 1 Remote System Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | Protocol Impersonation | SIM Card Swap | Carrier Billing Fraud |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | Virustotal | Browse |
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse | ||
8% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
example-dwrapper.matomo.cloud | 18.157.122.248 | true | false |
| unknown |
dwrapper-prod.herokuapp.com | 46.137.15.86 | true | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
false |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false | high | |||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false | high | |||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
false |
| low | ||
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true | unknown | |||
true |
| unknown | ||
true |
| unknown | ||
true |
| unknown | ||
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.157.122.248 | example-dwrapper.matomo.cloud | United States | 16509 | AMAZON-02US | false | |
46.137.15.86 | dwrapper-prod.herokuapp.com | Ireland | 16509 | AMAZON-02US | false |
Joe Sandbox Version: | 37.1.0 Beryl |
Analysis ID: | 882168 |
Start date and time: | 2023-06-05 23:30:51 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | PROD_Start_DriverPack.hta |
Detection: | MAL |
Classification: | mal52.winHTA@1/12@2/2 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, WMIADAP.exe, conho st.exe, WmiPrvSE.exe - Execution Graph export aborted
for target mshta.exe, PID 476 4 because it is empty - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtAllocateVirtualMemor y calls found. - Report size getting too big, t
oo many NtOpenKeyEx calls foun d. - Report size getting too big, t
oo many NtProtectVirtualMemory calls found. - Report size getting too big, t
oo many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
23:31:42 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
18.157.122.248 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
46.137.15.86 | Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
dwrapper-prod.herokuapp.com | Get hash | malicious | Unknown | Browse |
| |
example-dwrapper.matomo.cloud | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | GRQ Scam | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
AMAZON-02US | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Moobot | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | GRQ Scam | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
⊘No context
⊘No context
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1304 |
Entropy (8bit): | 5.371258741762522 |
Encrypted: | false |
SSDEEP: | 24:JmXoFt/9j3riN7RaM3MxvKrRrkE+u3mcJI6c/22bv27jPQzLkKWyU:YYFneUvaF3lJIR/2YsszAKWyU |
MD5: | 4BDB642A191FD4BF5A806A7B7478633A |
SHA1: | 2A7CDBB5C072655F4B4899FCE40AA273037495B7 |
SHA-256: | 494AACB6BA9D44FED47D20ADEA0FF2C597E6E1439C4D0694BC9EECB4AF77D096 |
SHA-512: | 63C248F44E4F93E5D6E513D19E526D77C7D483FC36182951805552E87BC8E4C7DF79BF63407AE382C9804A915D4C576FE5ECDE1E464EB87FDECEFF21B34CADFE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5086 |
Entropy (8bit): | 5.422218540561902 |
Encrypted: | false |
SSDEEP: | 96:Q+LHTI2QlTMWpFuh5mS2huO4KzbNgT5cN2yd6uAcq1BLYaX2Vv5I9Ffv5+T0iNDW:QSTI28TMWXu4caWT5cZIvgILZ+AkDC5 |
MD5: | 22D3D08CBEC1245327396FAA5B60725A |
SHA1: | 71DFB22D57F73CD5390F1991B6013AB44CD7351A |
SHA-256: | 923CBFF9E47CA64E292A8932A13ED11F9E4A488DC20775181B010231F15E3E26 |
SHA-512: | D90B4C383077038D436B9E125240B62CFD928D24940E464A93FC88A0C76F1F1EE79E617CCCE0F41FBF1DF3D660C3764E323F02674E2F45BBA0CD31B957E09D92 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2538 |
Entropy (8bit): | 5.676353904867985 |
Encrypted: | false |
SSDEEP: | 48:YPpaPGzh7iHgZ03jZ4onR1AF3R8I/idgw6+9dSVlhHH7QpZXKxDU:BP+EgZ0TZRu/id66wVD1Y |
MD5: | CC9E168614A8D567352E24F970CA21E0 |
SHA1: | 623C06BB9699F5AD91C4D19199A0F3780FC76A4D |
SHA-256: | 578820B83CD0244FFC068665C531A8C7D633F890A927A682A1708B84B7A08702 |
SHA-512: | A98DACDE394030A590E9D31941F71B8FBA3544EDCA2F17188FA940B314E58A8139FD62CF664A3D49264C8812053F5E869ECB6700A2B2A7BDCABD3C731C224D2F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1157 |
Entropy (8bit): | 5.443625546433963 |
Encrypted: | false |
SSDEEP: | 24:JmrIkiNpip1BYNeupYeuHgk2x3HN5E1vIfooGUeerKeQ3No:YrMNpTnanuH/Emf+UJrKeiNo |
MD5: | B21247B2428E6D9F72405EB1A2F5F75C |
SHA1: | 11C6612989710432AE9730C2C20CE7EE9F0DF609 |
SHA-256: | 9DDF298484BD63F71CFF04DD81E00913266FA8D71793E2C26F3B7B215067812C |
SHA-512: | D3060F786D378680DA1917F7E00878A2012C6B9C497693B0C01BECF5D896F2681E851FB4F6724710A6E9C755D988A0828DF55B0966B431A38756355B9ACD0EBB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 538 |
Entropy (8bit): | 5.280112968479041 |
Encrypted: | false |
SSDEEP: | 12:JqdCBVoflqnKA1B8lsD20X9koquJYVaXBZVz1odqnA:JmCBCflGN162auVVWVGm+A |
MD5: | AEEE81BB12D7059393E42828191765C2 |
SHA1: | 733A7D859097567B2B7FEAACE0498AD68C0F429D |
SHA-256: | F9156E0C0A06207EB66A51AB364A05E37E0273242F9373F8378F6E0DEB705D0B |
SHA-512: | E0ACB5A0A51677276124BEFD4AE8AAB0558C0BC95C5E7B70F6F2212367ECCFA9BEC85827D9CE6FD8BEF09A59D48A262CC0C155B72FAAECF897154E35C9219189 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 67231 |
Entropy (8bit): | 5.549452833601988 |
Encrypted: | false |
SSDEEP: | 768:FSkBQstkitLTvcQ4p61Hh3ehnspXqDqIjvZq6mfUJTHe7tvnx8PZXJRr2z5t9rya:+sbv22VeIxcwz5jG14useIEBDGx |
MD5: | 0F8AA7C95F02FF49F1FBAE3D5817F2F9 |
SHA1: | 3FEC254401BCDEC1D2DB5F23F9E02155E096571F |
SHA-256: | 685F7D5BF2AF77F561B24F8E4B2363503A76690D70B179BB55B161317BA47676 |
SHA-512: | CA3B3AB35E5F79A734727642A2AC76EBE20BED0552ECDDB116CFDF903BA1666A6A48B5837FD1F06B1B3969C360F5F07A6ED73D8882C7C09DBFFB919D9BB1CB8C |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3549 |
Entropy (8bit): | 5.718751523287771 |
Encrypted: | false |
SSDEEP: | 96:eGTzm4iZlN7GC+Ec4iGTzVbi+nMGTViBaHxWrsJrbOPFvJ+8Xu:Bm4eX7GFr9czV2CwaHygyx4 |
MD5: | 5C4131C3255CB275FB6D7D2F2B6A1FB8 |
SHA1: | FF24D538B653C455865D6133AF5FF768FDADB32E |
SHA-256: | 75733A0CB0D087048775602B5AB85D081F5B26330189FD187529CDA95CB9A518 |
SHA-512: | 4051ED5B1A4819E6EAFB0BF0E2DD4ED214EF9DC8DCCB1490D4AD59731B7B250DBC31E0B162C44B9E67A2DE071985B122C2C93117D8D1F4667FE3983B54A0ADA0 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8133 |
Entropy (8bit): | 5.512060404041763 |
Encrypted: | false |
SSDEEP: | 192:rLVRyhuoevivVLbVxe9zTTQsy/VGL5u5hKj631NFlJ6WNbjSb1pxCE8qbJ:GhyUCTTQ8kizh |
MD5: | B2343F840D0138C1D34648AF653617AF |
SHA1: | ABC1F107DFBAA67F7FADC6B03F2A69C561C51247 |
SHA-256: | 8ECA86E628A4BF5C7CB78DB8654CE749E5BB4A3DAA5FE79ED61045CBF3A97E73 |
SHA-512: | 8616D5865BF1C511F6E4C3E3CC5CBB1B2C4C71ECB255B3CB6EEF900EE3C9961E828A264F03436CAE7A7E430567BB397087550BADCCB83811C188CB90759F5B7C |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32 |
Entropy (8bit): | 4.366729296672174 |
Encrypted: | false |
SSDEEP: | 3:qYwmHMwMgRzn:qY3HMwMgRzn |
MD5: | B097BC01F54B411CCD715DF31A02165A |
SHA1: | 42AEF60341257F6915AD99236674F0834CC6219A |
SHA-256: | A8C62167EDF230A9096B4ADEE7EB1FC6F5E320A75278955E80F393C2B3AE4CB4 |
SHA-512: | 558D274427F96D3E0FA49F43BADD674C2125356371B0119E4D78032793E023E360E4CF76357A2E54BCA6DF940203159956446A3FCD32F1ECC297775020FC5EA7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1807 |
Entropy (8bit): | 4.663040957738839 |
Encrypted: | false |
SSDEEP: | 24:cuM2VgeG3RWZQericn0EG1WGDROQP/YZqpMT6BM393pfb0+4p3wdJOIC5ypfLLcD:cDcgnwfiOGWK77iiM5FI5C2ylGf |
MD5: | 5BB70933199563BD95A85E9D58D0920B |
SHA1: | 1E0322DD237C61A911D58D11F3A2879D78A36444 |
SHA-256: | 915A03DDD5D887CE43185A21FD9927FFCFC6E8F373D80D6FB0BFE96E65C029CD |
SHA-512: | 7F727D6F0ABB14746B24D10E7D2A532B20BA44B0E177C4B1D778BDF8EA3AC4D8B4D644EBEC169DAA4777DFFD22B376D1DAFB0EF790815558A665922598DA24EB |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3369 |
Entropy (8bit): | 5.647548365349031 |
Encrypted: | false |
SSDEEP: | 48:uMD2epuqggNwVngUF2EJDi+33Ld9oFWLCd6MVCON5p49TpNHkN/NyNdNfNjNsC8q:l73ZNengUdY8C6K5ul7E1OvVp+OIgp |
MD5: | D9C4EDD8648B146931B486C8FC4853F1 |
SHA1: | 4B5C47AD23061C8E225E7F6BBC3F116100DA296F |
SHA-256: | C36CFE0BBA2E4B111968E9899B82A5FD6829949D8BA4BF31D0448C86904D7AA0 |
SHA-512: | 1541027AD8D858F4A584E18CAE73BE9BD4E9EA3ECC670D76AAF24A833D11B8A199CDAA4735A27E70A870426C98E25DAFD642E6530D712A3D1A82CAE8A61C5346 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\mshta.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2981 |
Entropy (8bit): | 5.119918146134988 |
Encrypted: | false |
SSDEEP: | 48:fsCKWBr6pIl8r3yCyTprhGMCkMaJ7re6VOrnAM/TESJFBIr9U5JReskpUVh5buU2:fnxGp48hyTHbCFWS6VOz/TESJ7IK5JRi |
MD5: | 817F995CDDC5BB427032EB7286FCDA39 |
SHA1: | C676C64C0D0C902C66E8448680846FF45D388E8B |
SHA-256: | F3BDB1D94F79EFD344620028E69EB6BC4AADCA69081E9A9E91D5389E6BFD6DFB |
SHA-512: | 4ECA49C7041A35125031188716F341E1E7081FD7A4C7E505606E4FD38143164C36E461D42308D9633CCD89F113BBF4E77DE6C01DB60B0E4C29F447A7FB0CA4F6 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 5.121271796929296 |
TrID: |
|
File name: | PROD_Start_DriverPack.hta |
File size: | 1672 |
MD5: | dda846a4704efc2a03e1f8392e6f1ffc |
SHA1: | 387171a06eee5a76aaedc3664385bb89703cf6df |
SHA256: | e9dc9648d8fb7d943431459f49a7d9926197c2d60b3c2b6a58294fd75b672b25 |
SHA512: | 5cc5ad3fbdf083a87a65be76869bca844faa2d9be25657b45ad070531892f20d9337739590dd8995bca03ce23e9cb611129fe2f8457879b6263825d6df49da7a |
SSDEEP: | 48:uzK1vpKljUYpuqgs1pxXzOSRByHCpmF50bxxdW6kI:qiIT3BjNOSOGmF50tKA |
TLSH: | 34310E660D56902090372A6247FE620AEB73A5631289E752B8CC914F3F70B439E43BE8 |
File Content Preview: | ...<!DOCTYPE html>..<html>....<head>.. <title>Starting...</title>.. ->.. <meta http-equiv="X-UA-Compatible" content="IE=7">.. -->.... { IF [NOSCRIPT] } -->.. .. <noscript>.. <meta http-equiv="refresh" c |
Download Network PCAP: filtered – full
- Total Packets: 121
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 5, 2023 23:31:41.364528894 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.409316063 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.409446001 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.409811974 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.453984022 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.455796957 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.455882072 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.455894947 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.455941916 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.455950975 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.455993891 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.456044912 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.456065893 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.469209909 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.471534967 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.513608932 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.515221119 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.515336037 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.515465975 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.515535116 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.515551090 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.515580893 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.515595913 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.515666962 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.516076088 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.518364906 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.559454918 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.561242104 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.561340094 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.561358929 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.561408997 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.562438011 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.563178062 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.563694000 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.563817024 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.566026926 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.606405973 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.608189106 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.608237028 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.608303070 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.608529091 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.610080004 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.610392094 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.611664057 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.611713886 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.611759901 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.611776114 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.611776114 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.611805916 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.611819029 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.611845970 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.611861944 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.611901045 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.613610983 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.653543949 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.659137964 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.659203053 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.659256935 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.659256935 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.659303904 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.659353971 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.659966946 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.660104990 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.660109997 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.660162926 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.672878981 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.683690071 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.716243982 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.717969894 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.718157053 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.730541945 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.730623007 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.730690002 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.730727911 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.730742931 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.730783939 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.730784893 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.730808973 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.760950089 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.762079000 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806013107 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806086063 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806137085 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806168079 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806224108 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806292057 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806307077 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806348085 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806385040 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806437016 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806464911 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806528091 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.806546926 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.806587934 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807476044 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807547092 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807579041 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807611942 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807627916 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807673931 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807674885 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807733059 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807790995 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807810068 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807810068 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807842016 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807846069 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807902098 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807904005 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.807961941 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.807962894 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.808018923 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.808022022 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.808082104 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852169037 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852302074 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852340937 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852382898 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852385998 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852456093 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852458954 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852528095 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852528095 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852606058 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852607012 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852690935 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852691889 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852758884 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852819920 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852827072 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852876902 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852896929 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852931023 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.852965117 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.852988005 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853034019 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853039026 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853101969 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853106022 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853168964 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853176117 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853238106 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853244066 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853305101 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853343010 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853373051 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853384972 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853441000 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853451967 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853507042 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853518009 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853579044 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.853585005 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.853657007 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897675991 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897706985 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897732973 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897758961 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897785902 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897810936 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897834063 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897860050 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897862911 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897862911 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897862911 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897887945 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897914886 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897924900 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897926092 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897942066 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897948027 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897972107 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.897979021 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.897998095 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898000002 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898025036 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898030996 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898049116 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898051023 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898075104 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898078918 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898101091 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898102045 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898128986 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898144960 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898158073 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898164988 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898188114 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898189068 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898219109 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898238897 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898247004 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898273945 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898293018 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898300886 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:41.898317099 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898317099 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898339033 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:41.898379087 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:43.087299109 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:31:43.107964039 CEST | 80 | 49701 | 18.157.122.248 | 192.168.2.3 |
Jun 5, 2023 23:31:43.108094931 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:31:43.121170998 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:31:43.140350103 CEST | 80 | 49701 | 18.157.122.248 | 192.168.2.3 |
Jun 5, 2023 23:31:43.150623083 CEST | 80 | 49701 | 18.157.122.248 | 192.168.2.3 |
Jun 5, 2023 23:31:43.150777102 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:31:43.490397930 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:31:43.521100998 CEST | 80 | 49701 | 18.157.122.248 | 192.168.2.3 |
Jun 5, 2023 23:31:43.521383047 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:31:56.853729010 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:56.853934050 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:31:56.951406002 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:31:56.951562881 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:32:11.905899048 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:32:11.906006098 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:32:12.183543921 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:32:12.183689117 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:32:27.009798050 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:32:27.010900974 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:32:27.287658930 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:32:27.287858963 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:32:41.806559086 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:32:41.807533026 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:32:41.809568882 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:32:41.809763908 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:33:31.292181015 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:33:31.292517900 CEST | 49699 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:33:31.292887926 CEST | 49700 | 80 | 192.168.2.3 | 46.137.15.86 |
Jun 5, 2023 23:33:31.312350988 CEST | 80 | 49701 | 18.157.122.248 | 192.168.2.3 |
Jun 5, 2023 23:33:31.312634945 CEST | 49701 | 80 | 192.168.2.3 | 18.157.122.248 |
Jun 5, 2023 23:33:31.336008072 CEST | 80 | 49700 | 46.137.15.86 | 192.168.2.3 |
Jun 5, 2023 23:33:31.336505890 CEST | 80 | 49699 | 46.137.15.86 | 192.168.2.3 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 5, 2023 23:31:41.325001955 CEST | 52387 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 5, 2023 23:31:41.352510929 CEST | 53 | 52387 | 8.8.8.8 | 192.168.2.3 |
Jun 5, 2023 23:31:42.996372938 CEST | 56924 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 5, 2023 23:31:43.074219942 CEST | 53 | 56924 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jun 5, 2023 23:31:41.325001955 CEST | 192.168.2.3 | 8.8.8.8 | 0x2dc5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 5, 2023 23:31:42.996372938 CEST | 192.168.2.3 | 8.8.8.8 | 0x2c48 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jun 5, 2023 23:31:41.352510929 CEST | 8.8.8.8 | 192.168.2.3 | 0x2dc5 | No error (0) | 46.137.15.86 | A (IP address) | IN (0x0001) | false | ||
Jun 5, 2023 23:31:41.352510929 CEST | 8.8.8.8 | 192.168.2.3 | 0x2dc5 | No error (0) | 54.220.192.176 | A (IP address) | IN (0x0001) | false | ||
Jun 5, 2023 23:31:41.352510929 CEST | 8.8.8.8 | 192.168.2.3 | 0x2dc5 | No error (0) | 54.73.53.134 | A (IP address) | IN (0x0001) | false | ||
Jun 5, 2023 23:31:43.074219942 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c48 | No error (0) | 18.157.122.248 | A (IP address) | IN (0x0001) | false | ||
Jun 5, 2023 23:31:43.074219942 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c48 | No error (0) | 18.195.235.189 | A (IP address) | IN (0x0001) | false | ||
Jun 5, 2023 23:31:43.074219942 CEST | 8.8.8.8 | 192.168.2.3 | 0x2c48 | No error (0) | 3.126.133.169 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49699 | 46.137.15.86 | 80 | C:\Windows\SysWOW64\mshta.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 5, 2023 23:31:41.409811974 CEST | 92 | OUT | |
Jun 5, 2023 23:31:41.455796957 CEST | 92 | IN | |
Jun 5, 2023 23:31:41.455882072 CEST | 94 | IN | |
Jun 5, 2023 23:31:41.455941916 CEST | 94 | IN | |
Jun 5, 2023 23:31:41.455993891 CEST | 94 | IN | |
Jun 5, 2023 23:31:41.469209909 CEST | 95 | OUT | |
Jun 5, 2023 23:31:41.515221119 CEST | 96 | IN |