Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
NXK7tvxiAh.exe

Overview

General Information

Sample name:NXK7tvxiAh.exe
renamed because original name is a hash value
Original sample name:4f121ea16b6d93625750722b82b68566.exe
Analysis ID:1528612
MD5:4f121ea16b6d93625750722b82b68566
SHA1:cf11c14525ae058bc653724281965314550b0c64
SHA256:d7ac0037bcddd94c672402c04523ecf749de0156e550e1eec5d91abf29a7ddb2
Tags:64exeMeterpretertrojan
Infos:

Detection

Metasploit
Score:96
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Metasploit Payload
AI detected suspicious sample
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Entry point lies outside standard sections
Internet Provider seen in connection with other malware
PE file contains an invalid checksum
PE file contains sections with non-standard names
Program does not show much activity (idle)
Yara signature match

Classification

  • System is w10x64
  • NXK7tvxiAh.exe (PID: 3228 cmdline: "C:\Users\user\Desktop\NXK7tvxiAh.exe" MD5: 4F121EA16B6D93625750722B82B68566)
  • cleanup
{"Type": "Metasploit Connect", "IP": "47.239.242.141", "Port": 6666}
SourceRuleDescriptionAuthorStrings
NXK7tvxiAh.exeJoeSecurity_MetasploitPayload_2Yara detected Metasploit PayloadJoe Security
    NXK7tvxiAh.exeJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
      NXK7tvxiAh.exeWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
      • 0x1881:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
      NXK7tvxiAh.exeWindows_Trojan_Metasploit_91bc5d7dunknownunknown
      • 0x18d7:$a: 49 BE 77 73 32 5F 33 32 00 00 41 56 49 89 E6 48 81 EC A0 01 00 00 49 89 E5
      SourceRuleDescriptionAuthorStrings
      00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmpJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
        00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmpWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
        • 0x81:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
        00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmpWindows_Trojan_Metasploit_91bc5d7dunknownunknown
        • 0xd7:$a: 49 BE 77 73 32 5F 33 32 00 00 41 56 49 89 E6 48 81 EC A0 01 00 00 49 89 E5
        00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmpJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
          00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmpWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
          • 0x81:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
          Click to see the 1 entries
          SourceRuleDescriptionAuthorStrings
          0.0.NXK7tvxiAh.exe.140000000.0.unpackJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
            0.0.NXK7tvxiAh.exe.140000000.0.unpackWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
            • 0x16c9:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
            0.0.NXK7tvxiAh.exe.140000000.0.unpackWindows_Trojan_Metasploit_91bc5d7dunknownunknown
            • 0x171f:$a: 49 BE 77 73 32 5F 33 32 00 00 41 56 49 89 E6 48 81 EC A0 01 00 00 49 89 E5
            0.2.NXK7tvxiAh.exe.140000000.0.unpackJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
              0.2.NXK7tvxiAh.exe.140000000.0.unpackWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
              • 0x16c9:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
              Click to see the 1 entries
              No Sigma rule has matched
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: NXK7tvxiAh.exeAvira: detected
              Source: NXK7tvxiAh.exeMalware Configuration Extractor: Metasploit {"Type": "Metasploit Connect", "IP": "47.239.242.141", "Port": 6666}
              Source: NXK7tvxiAh.exeReversingLabs: Detection: 92%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: NXK7tvxiAh.exeJoe Sandbox ML: detected
              Source: global trafficTCP traffic: 192.168.2.5:49704 -> 47.239.242.141:6666
              Source: Joe Sandbox ViewASN Name: CHARTER-20115US CHARTER-20115US
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: unknownTCP traffic detected without corresponding DNS query: 47.239.242.141
              Source: C:\Users\user\Desktop\NXK7tvxiAh.exeCode function: 0_2_00000001400040D6 LoadLibraryA,WSASocketA,connect,recv,closesocket,0_2_00000001400040D6

              System Summary

              barindex
              Source: NXK7tvxiAh.exe, type: SAMPLEMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
              Source: NXK7tvxiAh.exe, type: SAMPLEMatched rule: Windows_Trojan_Metasploit_91bc5d7d Author: unknown
              Source: 0.0.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
              Source: 0.0.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Metasploit_91bc5d7d Author: unknown
              Source: 0.2.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
              Source: 0.2.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Metasploit_91bc5d7d Author: unknown
              Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
              Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_91bc5d7d Author: unknown
              Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
              Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_91bc5d7d Author: unknown
              Source: NXK7tvxiAh.exe, type: SAMPLEMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
              Source: NXK7tvxiAh.exe, type: SAMPLEMatched rule: Windows_Trojan_Metasploit_91bc5d7d reference_sample = 0dd993ff3917dc56ef02324375165f0d66506c5a9b9548eda57c58e041030987, os = windows, severity = x86, creation_date = 2021-08-02, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 8848a3de66a25dd98278761a7953f31b7995e48621dec258f3d92bd91a4a3aa3, id = 91bc5d7d-31e3-4c02-82b3-a685194981f3, last_modified = 2021-10-04
              Source: 0.0.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
              Source: 0.0.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Metasploit_91bc5d7d reference_sample = 0dd993ff3917dc56ef02324375165f0d66506c5a9b9548eda57c58e041030987, os = windows, severity = x86, creation_date = 2021-08-02, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 8848a3de66a25dd98278761a7953f31b7995e48621dec258f3d92bd91a4a3aa3, id = 91bc5d7d-31e3-4c02-82b3-a685194981f3, last_modified = 2021-10-04
              Source: 0.2.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
              Source: 0.2.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Metasploit_91bc5d7d reference_sample = 0dd993ff3917dc56ef02324375165f0d66506c5a9b9548eda57c58e041030987, os = windows, severity = x86, creation_date = 2021-08-02, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 8848a3de66a25dd98278761a7953f31b7995e48621dec258f3d92bd91a4a3aa3, id = 91bc5d7d-31e3-4c02-82b3-a685194981f3, last_modified = 2021-10-04
              Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
              Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_91bc5d7d reference_sample = 0dd993ff3917dc56ef02324375165f0d66506c5a9b9548eda57c58e041030987, os = windows, severity = x86, creation_date = 2021-08-02, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 8848a3de66a25dd98278761a7953f31b7995e48621dec258f3d92bd91a4a3aa3, id = 91bc5d7d-31e3-4c02-82b3-a685194981f3, last_modified = 2021-10-04
              Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
              Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_91bc5d7d reference_sample = 0dd993ff3917dc56ef02324375165f0d66506c5a9b9548eda57c58e041030987, os = windows, severity = x86, creation_date = 2021-08-02, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 8848a3de66a25dd98278761a7953f31b7995e48621dec258f3d92bd91a4a3aa3, id = 91bc5d7d-31e3-4c02-82b3-a685194981f3, last_modified = 2021-10-04
              Source: classification engineClassification label: mal96.troj.winEXE@1/0@0/1
              Source: C:\Users\user\Desktop\NXK7tvxiAh.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: NXK7tvxiAh.exeReversingLabs: Detection: 92%
              Source: C:\Users\user\Desktop\NXK7tvxiAh.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\NXK7tvxiAh.exeSection loaded: mswsock.dllJump to behavior
              Source: NXK7tvxiAh.exeStatic PE information: Image base 0x140000000 > 0x60000000
              Source: initial sampleStatic PE information: section where entry point is pointing to: .aycs
              Source: NXK7tvxiAh.exeStatic PE information: real checksum: 0x58ba should be: 0x5a72
              Source: NXK7tvxiAh.exeStatic PE information: section name: .aycs
              Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
              Source: NXK7tvxiAh.exe, 00000000.00000002.3257704414.00000000005F6000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
              Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: NXK7tvxiAh.exe, type: SAMPLE
              Source: Yara matchFile source: 0.0.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.NXK7tvxiAh.exe.140000000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, type: MEMORY
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
              DLL Side-Loading
              1
              DLL Side-Loading
              1
              DLL Side-Loading
              OS Credential Dumping1
              Security Software Discovery
              Remote ServicesData from Local System1
              Non-Standard Port
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
              System Information Discovery
              Remote Desktop ProtocolData from Removable Media1
              Ingress Tool Transfer
              Exfiltration Over BluetoothNetwork Denial of Service
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              NXK7tvxiAh.exe92%ReversingLabsWin64.Backdoor.Meterpreter
              NXK7tvxiAh.exe100%AviraTR/Crypt.XPACK.Gen7
              NXK7tvxiAh.exe100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              No contacted domains info
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              47.239.242.141
              unknownUnited States
              20115CHARTER-20115UStrue
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1528612
              Start date and time:2024-10-08 04:28:07 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 34s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:4
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:NXK7tvxiAh.exe
              renamed because original name is a hash value
              Original Sample Name:4f121ea16b6d93625750722b82b68566.exe
              Detection:MAL
              Classification:mal96.troj.winEXE@1/0@0/1
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 1
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • VT rate limit hit for: NXK7tvxiAh.exe
              No simulations
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              47.239.242.141vNenBbeRFZ.exeGet hashmaliciousCobaltStrike, Metasploit, ReflectiveLoaderBrowse
              • 47.239.242.141:9999/ga.js
              hRjh70pZ6Q.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
              • 47.239.242.141:9999/s9bO
              No context
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              CHARTER-20115USvNenBbeRFZ.exeGet hashmaliciousCobaltStrike, Metasploit, ReflectiveLoaderBrowse
              • 47.239.242.141
              cenSXPimaG.elfGet hashmaliciousMirai, OkiruBrowse
              • 97.94.57.120
              XvAqhy3FO6.elfGet hashmaliciousMirai, OkiruBrowse
              • 172.220.122.192
              na.elfGet hashmaliciousUnknownBrowse
              • 66.215.147.152
              O8scEm3rJN.exeGet hashmaliciousUnknownBrowse
              • 47.238.55.14
              setupa.exeGet hashmaliciousGhostRatBrowse
              • 47.239.116.158
              Jr77pnmOup.elfGet hashmaliciousMiraiBrowse
              • 71.94.21.162
              ZEjcJZcrXc.elfGet hashmaliciousMiraiBrowse
              • 24.178.88.151
              na.elfGet hashmaliciousMiraiBrowse
              • 47.26.86.21
              na.elfGet hashmaliciousMirai, OkiruBrowse
              • 66.169.57.64
              No context
              No context
              No created / dropped files found
              File type:PE32+ executable (GUI) x86-64, for MS Windows
              Entropy (8bit):1.315425145419752
              TrID:
              • Win64 Executable GUI (202006/5) 92.65%
              • Win64 Executable (generic) (12005/4) 5.51%
              • Generic Win/DOS Executable (2004/3) 0.92%
              • DOS Executable Generic (2002/1) 0.92%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:NXK7tvxiAh.exe
              File size:7'168 bytes
              MD5:4f121ea16b6d93625750722b82b68566
              SHA1:cf11c14525ae058bc653724281965314550b0c64
              SHA256:d7ac0037bcddd94c672402c04523ecf749de0156e550e1eec5d91abf29a7ddb2
              SHA512:fc532fe11356c833d22302750a0259081e9ece7e632444ce5f544eea2460cd784005198369f76cc13d162080d63efd4cc686a00617200bd8ad8da33950d8531a
              SSDEEP:24:eFGStrJ9u0/6XZnZdkBQAVxc/q9KZqAaeNDMSCvOXpmB:is0WpkBQNC9vSD9C2kB
              TLSH:F7E175133B184EB6D87C057947E3FDA766689A293F3F43758D180307387232479A5918
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9$..}E..}E..}E..Z...~E..}E~..E..t=..|E..t=..|E..Rich}E..................PE..d...}<.K..........#......0...........@.........@...
              Icon Hash:00928e8e8686b000
              Entrypoint:0x140004000
              Entrypoint Section:.aycs
              Digitally signed:false
              Imagebase:0x140000000
              Subsystem:windows gui
              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
              DLL Characteristics:TERMINAL_SERVER_AWARE
              Time Stamp:0x4BC63C7D [Wed Apr 14 22:06:53 2010 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:4
              OS Version Minor:0
              File Version Major:4
              File Version Minor:0
              Subsystem Version Major:4
              Subsystem Version Minor:0
              Import Hash:b4c6fff030479aa3b12625be67bf4914
              Instruction
              cld
              dec eax
              and esp, FFFFFFF0h
              call 00007F8F1C4ED6A1h
              inc ecx
              push ecx
              inc ecx
              push eax
              push edx
              dec eax
              xor edx, edx
              dec eax
              mov edx, dword ptr [edx+60h]
              dec eax
              mov edx, dword ptr [edx+18h]
              push ecx
              push esi
              dec eax
              mov edx, dword ptr [edx+20h]
              dec ebp
              xor ecx, ecx
              dec eax
              movzx ecx, word ptr [edx+4Ah]
              dec eax
              mov esi, dword ptr [edx+50h]
              dec eax
              xor eax, eax
              lodsb
              cmp al, 61h
              jl 00007F8F1C4ED5D4h
              sub al, 20h
              inc ecx
              ror ecx, 0Dh
              inc ecx
              add ecx, eax
              loop 00007F8F1C4ED5BFh
              push edx
              dec eax
              mov edx, dword ptr [edx+20h]
              inc ecx
              push ecx
              mov eax, dword ptr [edx+3Ch]
              dec eax
              add eax, edx
              cmp word ptr [eax+18h], 020Bh
              jne 00007F8F1C4ED648h
              mov eax, dword ptr [eax+00000088h]
              dec eax
              test eax, eax
              je 00007F8F1C4ED639h
              dec eax
              add eax, edx
              mov ecx, dword ptr [eax+18h]
              push eax
              inc esp
              mov eax, dword ptr [eax+20h]
              dec ecx
              add eax, edx
              jecxz 00007F8F1C4ED628h
              dec eax
              dec ecx
              inc ecx
              mov esi, dword ptr [eax+ecx*4]
              dec eax
              add esi, edx
              dec ebp
              xor ecx, ecx
              dec eax
              xor eax, eax
              lodsb
              inc ecx
              ror ecx, 0Dh
              inc ecx
              add ecx, eax
              cmp al, ah
              jne 00007F8F1C4ED5C3h
              dec esp
              add ecx, dword ptr [esp+08h]
              inc ebp
              cmp ecx, edx
              jne 00007F8F1C4ED5AAh
              pop eax
              inc esp
              mov eax, dword ptr [eax+24h]
              dec ecx
              add eax, edx
              inc cx
              mov ecx, dword ptr [eax+ecx*2]
              inc esp
              mov eax, dword ptr [eax+1Ch]
              dec ecx
              add eax, edx
              inc ecx
              mov eax, dword ptr [eax+ecx*4]
              inc ecx
              pop eax
              inc ecx
              pop eax
              dec eax
              add eax, edx
              pop esi
              pop ecx
              pop edx
              inc ecx
              pop eax
              inc ecx
              pop ecx
              inc ecx
              pop edx
              dec eax
              sub esp, 20h
              inc ecx
              Programming Language:
              • [IMP] VS2005 build 50727
              • [ASM] VS2008 SP1 build 30729
              • [LNK] VS2008 SP1 build 30729
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x42000x6c.aycs
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x42700x8.aycs
              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x30000x18.rdata
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x104e0x1200a4a5deae25708a9e05f50bcad7075c86False0.025390625data0.16810049402497224IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rdata0x30000x840x200253b88122c36b6951090c6288183e4aeFalse0.15625data0.9630867345987311IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .aycs0x40000x2780x400ea92a97d65e01e0fb402ff25159a45c5False0.5302734375data4.304252932787313IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              DLLImport
              KERNEL32.dllVirtualAlloc, ExitProcess
              TimestampSource PortDest PortSource IPDest IP
              Oct 8, 2024 04:28:56.356075048 CEST497046666192.168.2.547.239.242.141
              Oct 8, 2024 04:28:56.361088037 CEST66664970447.239.242.141192.168.2.5
              Oct 8, 2024 04:28:56.361190081 CEST497046666192.168.2.547.239.242.141
              Oct 8, 2024 04:28:58.433989048 CEST66664970447.239.242.141192.168.2.5
              Oct 8, 2024 04:28:58.434071064 CEST497046666192.168.2.547.239.242.141
              Oct 8, 2024 04:28:58.434437037 CEST497046666192.168.2.547.239.242.141
              Oct 8, 2024 04:28:58.435074091 CEST497056666192.168.2.547.239.242.141
              Oct 8, 2024 04:28:58.439378023 CEST66664970447.239.242.141192.168.2.5
              Oct 8, 2024 04:28:58.439924002 CEST66664970547.239.242.141192.168.2.5
              Oct 8, 2024 04:28:58.440006018 CEST497056666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:00.504858017 CEST66664970547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:00.504968882 CEST497056666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:00.505351067 CEST497056666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:00.505887032 CEST497066666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:00.510112047 CEST66664970547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:00.510657072 CEST66664970647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:00.510735035 CEST497066666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:02.581083059 CEST66664970647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:02.581222057 CEST497066666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:02.581533909 CEST497066666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:02.582176924 CEST497076666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:02.586350918 CEST66664970647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:02.587069988 CEST66664970747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:02.587146044 CEST497076666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:04.630455017 CEST66664970747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:04.630587101 CEST497076666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:04.630860090 CEST497076666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:04.631505013 CEST497086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:04.635730982 CEST66664970747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:04.636398077 CEST66664970847.239.242.141192.168.2.5
              Oct 8, 2024 04:29:04.636472940 CEST497086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:06.681799889 CEST66664970847.239.242.141192.168.2.5
              Oct 8, 2024 04:29:06.681891918 CEST497086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:06.682199955 CEST497086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:06.682832003 CEST497096666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:06.687028885 CEST66664970847.239.242.141192.168.2.5
              Oct 8, 2024 04:29:06.687762976 CEST66664970947.239.242.141192.168.2.5
              Oct 8, 2024 04:29:06.687844992 CEST497096666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:08.726419926 CEST66664970947.239.242.141192.168.2.5
              Oct 8, 2024 04:29:08.726705074 CEST497096666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:08.727113962 CEST497096666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:08.727648973 CEST497106666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:08.731853962 CEST66664970947.239.242.141192.168.2.5
              Oct 8, 2024 04:29:08.732449055 CEST66664971047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:08.732551098 CEST497106666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:10.800486088 CEST66664971047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:10.800581932 CEST497106666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:10.800975084 CEST497106666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:10.801609993 CEST497116666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:10.805777073 CEST66664971047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:10.806353092 CEST66664971147.239.242.141192.168.2.5
              Oct 8, 2024 04:29:10.806437016 CEST497116666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:12.851751089 CEST66664971147.239.242.141192.168.2.5
              Oct 8, 2024 04:29:12.851816893 CEST497116666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:12.852216959 CEST497116666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:12.853136063 CEST497156666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:12.856976032 CEST66664971147.239.242.141192.168.2.5
              Oct 8, 2024 04:29:12.857940912 CEST66664971547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:12.857999086 CEST497156666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:14.930875063 CEST66664971547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:14.930938005 CEST497156666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:14.931272030 CEST497156666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:14.932104111 CEST497206666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:14.936139107 CEST66664971547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:14.936930895 CEST66664972047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:14.937014103 CEST497206666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:17.040447950 CEST66664972047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:17.041559935 CEST497206666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:17.046022892 CEST497206666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:17.046952009 CEST497276666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:17.050923109 CEST66664972047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:17.051930904 CEST66664972747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:17.052006960 CEST497276666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:19.144570112 CEST66664972747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:19.147877932 CEST497276666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:19.148088932 CEST497276666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:19.148725033 CEST497436666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:19.152812958 CEST66664972747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:19.153481960 CEST66664974347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:19.153588057 CEST497436666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:21.246426105 CEST66664974347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:21.246494055 CEST497436666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:21.246773005 CEST497436666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:21.247325897 CEST497596666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:21.251562119 CEST66664974347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:21.252105951 CEST66664975947.239.242.141192.168.2.5
              Oct 8, 2024 04:29:21.252173901 CEST497596666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:23.286938906 CEST66664975947.239.242.141192.168.2.5
              Oct 8, 2024 04:29:23.287023067 CEST497596666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:23.287471056 CEST497596666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:23.288675070 CEST497706666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:23.292289019 CEST66664975947.239.242.141192.168.2.5
              Oct 8, 2024 04:29:23.293587923 CEST66664977047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:23.293685913 CEST497706666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:25.338098049 CEST66664977047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:25.338217974 CEST497706666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:25.338702917 CEST497706666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:25.339658976 CEST497866666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:25.343468904 CEST66664977047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:25.344506025 CEST66664978647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:25.344588041 CEST497866666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:27.383529902 CEST66664978647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:27.383622885 CEST497866666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:27.383928061 CEST497866666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:27.384646893 CEST498026666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:27.388755083 CEST66664978647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:27.389583111 CEST66664980247.239.242.141192.168.2.5
              Oct 8, 2024 04:29:27.389656067 CEST498026666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:29.445700884 CEST66664980247.239.242.141192.168.2.5
              Oct 8, 2024 04:29:29.445797920 CEST498026666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:29.446114063 CEST498026666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:29.446758032 CEST498136666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:29.450894117 CEST66664980247.239.242.141192.168.2.5
              Oct 8, 2024 04:29:29.451549053 CEST66664981347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:29.451639891 CEST498136666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:31.535274982 CEST66664981347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:31.535337925 CEST498136666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:31.535681963 CEST498136666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:31.536343098 CEST498256666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:31.540400982 CEST66664981347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:31.541111946 CEST66664982547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:31.541188955 CEST498256666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:33.603993893 CEST66664982547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:33.604094982 CEST498256666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:33.615071058 CEST498256666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:33.615806103 CEST498376666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:33.619847059 CEST66664982547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:33.620615005 CEST66664983747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:33.620686054 CEST498376666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:35.681138039 CEST66664983747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:35.681206942 CEST498376666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:35.681498051 CEST498376666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:35.682102919 CEST498536666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:35.686309099 CEST66664983747.239.242.141192.168.2.5
              Oct 8, 2024 04:29:35.686937094 CEST66664985347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:35.687002897 CEST498536666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:37.727580070 CEST66664985347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:37.727664948 CEST498536666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:37.728108883 CEST498536666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:37.729012966 CEST498646666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:37.732916117 CEST66664985347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:37.733818054 CEST66664986447.239.242.141192.168.2.5
              Oct 8, 2024 04:29:37.733896971 CEST498646666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:39.815304041 CEST66664986447.239.242.141192.168.2.5
              Oct 8, 2024 04:29:39.815469980 CEST498646666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:39.816402912 CEST498646666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:39.816525936 CEST498806666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:39.821132898 CEST66664986447.239.242.141192.168.2.5
              Oct 8, 2024 04:29:39.821392059 CEST66664988047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:39.821476936 CEST498806666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:41.884593010 CEST66664988047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:41.884674072 CEST498806666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:41.885839939 CEST498806666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:41.889339924 CEST498966666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:41.890698910 CEST66664988047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:41.894144058 CEST66664989647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:41.894203901 CEST498966666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:43.951167107 CEST66664989647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:43.951297045 CEST498966666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:43.951596975 CEST498966666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:43.952177048 CEST499086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:43.956360102 CEST66664989647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:43.956943989 CEST66664990847.239.242.141192.168.2.5
              Oct 8, 2024 04:29:43.957014084 CEST499086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:45.992993116 CEST66664990847.239.242.141192.168.2.5
              Oct 8, 2024 04:29:45.993061066 CEST499086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:45.993349075 CEST499086666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:45.993997097 CEST499236666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:45.998277903 CEST66664990847.239.242.141192.168.2.5
              Oct 8, 2024 04:29:45.998800039 CEST66664992347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:45.998878002 CEST499236666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:48.062649965 CEST66664992347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:48.062721968 CEST499236666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:48.063028097 CEST499236666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:48.063644886 CEST499356666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:48.067765951 CEST66664992347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:48.068483114 CEST66664993547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:48.068548918 CEST499356666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:50.118088961 CEST66664993547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:50.118300915 CEST499356666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:50.118488073 CEST499356666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:50.119093895 CEST499506666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:50.125288010 CEST66664993547.239.242.141192.168.2.5
              Oct 8, 2024 04:29:50.125374079 CEST66664995047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:50.125447035 CEST499506666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:52.207807064 CEST66664995047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:52.207892895 CEST499506666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:52.208163977 CEST499506666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:52.208756924 CEST499636666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:52.213762045 CEST66664995047.239.242.141192.168.2.5
              Oct 8, 2024 04:29:52.214472055 CEST66664996347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:52.214565039 CEST499636666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:54.285712004 CEST66664996347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:54.285800934 CEST499636666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:54.286189079 CEST499636666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:54.286690950 CEST499766666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:54.290919065 CEST66664996347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:54.291461945 CEST66664997647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:54.291544914 CEST499766666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:56.378954887 CEST66664997647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:56.379062891 CEST499766666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:56.379451036 CEST499766666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:56.380069971 CEST499916666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:56.384272099 CEST66664997647.239.242.141192.168.2.5
              Oct 8, 2024 04:29:56.384926081 CEST66664999147.239.242.141192.168.2.5
              Oct 8, 2024 04:29:56.385003090 CEST499916666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:58.452920914 CEST66664999147.239.242.141192.168.2.5
              Oct 8, 2024 04:29:58.454679012 CEST499916666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:58.454991102 CEST499916666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:58.455651045 CEST500036666192.168.2.547.239.242.141
              Oct 8, 2024 04:29:58.459839106 CEST66664999147.239.242.141192.168.2.5
              Oct 8, 2024 04:29:58.460510969 CEST66665000347.239.242.141192.168.2.5
              Oct 8, 2024 04:29:58.460628986 CEST500036666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:00.536055088 CEST66665000347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:00.536204100 CEST500036666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:00.536505938 CEST500036666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:00.537245989 CEST500086666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:00.541299105 CEST66665000347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:00.542115927 CEST66665000847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:00.542201042 CEST500086666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:02.685066938 CEST66665000847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:02.685179949 CEST500086666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:02.685460091 CEST500086666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:02.686028957 CEST500096666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:02.690253973 CEST66665000847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:02.690850019 CEST66665000947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:02.690922022 CEST500096666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:04.896684885 CEST66665000947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:04.896883965 CEST500096666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:04.897214890 CEST500096666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:04.897839069 CEST500106666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:04.902129889 CEST66665000947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:04.902673960 CEST66665001047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:04.902753115 CEST500106666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:07.049470901 CEST66665001047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:07.049640894 CEST500106666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:07.050070047 CEST500106666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:07.051021099 CEST500116666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:07.054908991 CEST66665001047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:07.055915117 CEST66665001147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:07.056315899 CEST500116666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:09.178224087 CEST66665001147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:09.178801060 CEST500116666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:09.178801060 CEST500116666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:09.179734945 CEST500126666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:09.183907986 CEST66665001147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:09.184823990 CEST66665001247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:09.185034037 CEST500126666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:11.274348021 CEST66665001247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:11.274425983 CEST500126666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:11.274707079 CEST500126666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:11.275320053 CEST500136666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:11.279526949 CEST66665001247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:11.280265093 CEST66665001347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:11.280345917 CEST500136666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:13.322252035 CEST66665001347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:13.322542906 CEST500136666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:13.322635889 CEST500136666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:13.323183060 CEST500146666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:13.327440977 CEST66665001347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:13.328011036 CEST66665001447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:13.328075886 CEST500146666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:15.403410912 CEST66665001447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:15.403582096 CEST500146666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:15.403980970 CEST500146666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:15.404845953 CEST500156666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:15.409653902 CEST66665001447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:15.411248922 CEST66665001547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:15.411331892 CEST500156666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:17.478486061 CEST66665001547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:17.479244947 CEST500156666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:17.479244947 CEST500156666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:17.480401993 CEST500166666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:17.484097004 CEST66665001547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:17.485248089 CEST66665001647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:17.485580921 CEST500166666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:19.525316000 CEST66665001647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:19.525398970 CEST500166666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:19.525722027 CEST500166666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:19.526432037 CEST500176666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:19.530432940 CEST66665001647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:19.531234026 CEST66665001747.239.242.141192.168.2.5
              Oct 8, 2024 04:30:19.531333923 CEST500176666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:21.589792013 CEST66665001747.239.242.141192.168.2.5
              Oct 8, 2024 04:30:21.589924097 CEST500176666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:21.590405941 CEST500176666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:21.591377974 CEST500186666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:21.595195055 CEST66665001747.239.242.141192.168.2.5
              Oct 8, 2024 04:30:21.596184969 CEST66665001847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:21.596270084 CEST500186666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:23.692441940 CEST66665001847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:23.692637920 CEST500186666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:23.692996979 CEST500186666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:23.694060087 CEST500196666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:23.698183060 CEST66665001847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:23.699369907 CEST66665001947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:23.699465036 CEST500196666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:25.786032915 CEST66665001947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:25.786237001 CEST500196666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:25.786784887 CEST500196666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:25.787435055 CEST500206666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:25.791645050 CEST66665001947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:25.792288065 CEST66665002047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:25.792355061 CEST500206666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:27.860841990 CEST66665002047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:27.861083984 CEST500206666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:27.862035990 CEST500206666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:27.864213943 CEST500216666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:27.866841078 CEST66665002047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:27.869070053 CEST66665002147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:27.869240999 CEST500216666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:29.919061899 CEST66665002147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:29.919174910 CEST500216666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:29.919629097 CEST500216666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:29.920639038 CEST500226666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:29.925020933 CEST66665002147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:29.925405979 CEST66665002247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:29.925487995 CEST500226666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:31.994503975 CEST66665002247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:31.994573116 CEST500226666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:31.994863987 CEST500226666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:31.995523930 CEST500236666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:31.999599934 CEST66665002247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:32.000332117 CEST66665002347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:32.000421047 CEST500236666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:34.118360043 CEST66665002347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:34.118489027 CEST500236666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:34.119189024 CEST500236666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:34.119680882 CEST500246666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:34.123995066 CEST66665002347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:34.124555111 CEST66665002447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:34.124677896 CEST500246666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:36.211252928 CEST66665002447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:36.211399078 CEST500246666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:36.211628914 CEST500246666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:36.212219000 CEST500256666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:36.216406107 CEST66665002447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:36.217004061 CEST66665002547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:36.217067957 CEST500256666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:38.259572029 CEST66665002547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:38.259758949 CEST500256666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:38.260400057 CEST500256666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:38.261014938 CEST500266666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:38.265191078 CEST66665002547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:38.265847921 CEST66665002647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:38.265928984 CEST500266666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:40.349695921 CEST66665002647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:40.349844933 CEST500266666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:40.353390932 CEST500266666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:40.358298063 CEST66665002647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:40.361038923 CEST500276666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:40.365957975 CEST66665002747.239.242.141192.168.2.5
              Oct 8, 2024 04:30:40.366039991 CEST500276666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:42.419358015 CEST66665002747.239.242.141192.168.2.5
              Oct 8, 2024 04:30:42.419596910 CEST500276666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:42.419836998 CEST500276666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:42.420438051 CEST500286666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:42.424604893 CEST66665002747.239.242.141192.168.2.5
              Oct 8, 2024 04:30:42.425290108 CEST66665002847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:42.425364971 CEST500286666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:44.463434935 CEST66665002847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:44.463651896 CEST500286666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:44.463829041 CEST500286666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:44.464416027 CEST500296666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:44.468661070 CEST66665002847.239.242.141192.168.2.5
              Oct 8, 2024 04:30:44.469307899 CEST66665002947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:44.469368935 CEST500296666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:46.508956909 CEST66665002947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:46.509089947 CEST500296666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:46.509644032 CEST500296666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:46.510479927 CEST500306666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:46.514514923 CEST66665002947.239.242.141192.168.2.5
              Oct 8, 2024 04:30:46.515378952 CEST66665003047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:46.515464067 CEST500306666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:48.557754993 CEST66665003047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:48.557976961 CEST500306666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:48.558176041 CEST500306666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:48.558779955 CEST500316666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:48.562953949 CEST66665003047.239.242.141192.168.2.5
              Oct 8, 2024 04:30:48.563610077 CEST66665003147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:48.563802004 CEST500316666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:50.620909929 CEST66665003147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:50.621042967 CEST500316666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:50.621331930 CEST500316666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:50.622100115 CEST500326666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:50.626274109 CEST66665003147.239.242.141192.168.2.5
              Oct 8, 2024 04:30:50.627099991 CEST66665003247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:50.627293110 CEST500326666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:52.665915966 CEST66665003247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:52.665998936 CEST500326666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:52.666316986 CEST500326666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:52.666939974 CEST500336666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:52.671374083 CEST66665003247.239.242.141192.168.2.5
              Oct 8, 2024 04:30:52.671974897 CEST66665003347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:52.672046900 CEST500336666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:54.713901043 CEST66665003347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:54.714101076 CEST500336666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:54.714930058 CEST500336666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:54.719650984 CEST66665003347.239.242.141192.168.2.5
              Oct 8, 2024 04:30:54.721426010 CEST500346666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:54.726264000 CEST66665003447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:54.726356983 CEST500346666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:56.821557045 CEST66665003447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:56.821827888 CEST500346666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:56.822124004 CEST500346666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:56.826117039 CEST500356666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:56.826935053 CEST66665003447.239.242.141192.168.2.5
              Oct 8, 2024 04:30:56.831056118 CEST66665003547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:56.831163883 CEST500356666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:58.885932922 CEST66665003547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:58.886169910 CEST500356666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:58.886452913 CEST500356666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:58.887101889 CEST500366666192.168.2.547.239.242.141
              Oct 8, 2024 04:30:58.891355038 CEST66665003547.239.242.141192.168.2.5
              Oct 8, 2024 04:30:58.892373085 CEST66665003647.239.242.141192.168.2.5
              Oct 8, 2024 04:30:58.892474890 CEST500366666192.168.2.547.239.242.141
              Oct 8, 2024 04:31:00.932276011 CEST66665003647.239.242.141192.168.2.5
              Oct 8, 2024 04:31:00.932477951 CEST500366666192.168.2.547.239.242.141
              Oct 8, 2024 04:31:00.933505058 CEST500366666192.168.2.547.239.242.141
              Oct 8, 2024 04:31:00.935398102 CEST500376666192.168.2.547.239.242.141
              Oct 8, 2024 04:31:00.938322067 CEST66665003647.239.242.141192.168.2.5
              Oct 8, 2024 04:31:00.940196037 CEST66665003747.239.242.141192.168.2.5
              Oct 8, 2024 04:31:00.940361023 CEST500376666192.168.2.547.239.242.141

              Click to jump to process

              Click to jump to process

              Click to dive into process behavior distribution

              Target ID:0
              Start time:22:28:55
              Start date:07/10/2024
              Path:C:\Users\user\Desktop\NXK7tvxiAh.exe
              Wow64 process (32bit):false
              Commandline:"C:\Users\user\Desktop\NXK7tvxiAh.exe"
              Imagebase:0x140000000
              File size:7'168 bytes
              MD5 hash:4F121EA16B6D93625750722B82B68566
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Yara matches:
              • Rule: JoeSecurity_MetasploitPayload_3, Description: Yara detected Metasploit Payload, Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Author: unknown
              • Rule: Windows_Trojan_Metasploit_91bc5d7d, Description: unknown, Source: 00000000.00000000.2017931866.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Author: unknown
              • Rule: JoeSecurity_MetasploitPayload_3, Description: Yara detected Metasploit Payload, Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Author: Joe Security
              • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Author: unknown
              • Rule: Windows_Trojan_Metasploit_91bc5d7d, Description: unknown, Source: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Author: unknown
              Reputation:low
              Has exited:false

              Reset < >

                Execution Graph

                Execution Coverage:42.8%
                Dynamic/Decrypted Code Coverage:0%
                Signature Coverage:88.9%
                Total number of Nodes:9
                Total number of Limit Nodes:2
                execution_graph 33 140004000 36 1400040d6 LoadLibraryA 33->36 37 14000411b 36->37 38 14000411f WSASocketA 37->38 39 14000413e connect 38->39 40 14000415e recv 39->40 42 140004154 39->42 41 1400041d1 closesocket 40->41 40->42 41->38 42->39 42->40 42->41 43 1400041ee 42->43 43->43

                Callgraph

                • Executed
                • Not Executed
                • Opacity -> Relevance
                • Disassembly available
                callgraph 0 Function_00000001400040D6 1 Function_0000000140004000 1->0

                Control-flow Graph

                APIs
                Strings
                Memory Dump Source
                • Source File: 00000000.00000002.3257863596.0000000140004000.00000080.00000001.01000000.00000003.sdmp, Offset: 0000000140000000, based on PE: true
                • Associated: 00000000.00000002.3257795738.0000000140000000.00000002.00000001.01000000.00000003.sdmpDownload File
                Joe Sandbox IDA Plugin
                • Snapshot File: hcaresult_0_2_140000000_NXK7tvxiAh.jbxd
                Yara matches
                Similarity
                • API ID: LibraryLoadSocketclosesocketconnectrecv
                • String ID: unMa$ws2_32
                • API String ID: 2974377591-2325342229
                • Opcode ID: 89f92c085a98e0a76f54d3c6f7480ad20a4018a5f34a8644ac3c2a25d9a8b8ea
                • Instruction ID: 142aa4cc21d4ff41224c27b3dc1efc0ac2e34cf01bdba4847470c7e655eee39f
                • Opcode Fuzzy Hash: 89f92c085a98e0a76f54d3c6f7480ad20a4018a5f34a8644ac3c2a25d9a8b8ea
                • Instruction Fuzzy Hash: 4A21E2E2B5525828FA27A2A33D17FF684456B29FE0F1880207F1E8F7D6DC68C6C2511D