Windows
Analysis Report
kwlYObMOSn.exe
Overview
General Information
Sample name: | kwlYObMOSn.exerenamed because original name is a hash value |
Original sample name: | 3914bb7ca015e96eb45556b7fa427a8b5fbfc497a9909b777ea5d4e5b321111e.exe |
Analysis ID: | 1561585 |
MD5: | f28a1fb54a5c3b2b4e4184e3dff4f50a |
SHA1: | 180878512f7cd7c75c87fff174203228de688d34 |
SHA256: | 3914bb7ca015e96eb45556b7fa427a8b5fbfc497a9909b777ea5d4e5b321111e |
Tags: | exeuser-Chainskilabs |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- kwlYObMOSn.exe (PID: 4080 cmdline:
"C:\Users\ user\Deskt op\kwlYObM OSn.exe" MD5: F28A1FB54A5C3B2B4E4184E3DFF4F50A) - BootstrapperV1.23.exe (PID: 2860 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Bootstrap perV1.23.e xe" MD5: 02C70D9D6696950C198DB93B7F6A835E) - conhost.exe (PID: 5856 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 2604 cmdline:
"cmd" /c i pconfig /a ll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 4296 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - ipconfig.exe (PID: 5556 cmdline:
ipconfig / all MD5: 62F170FB07FDBB79CEB7147101406EB8) - WerFault.exe (PID: 1848 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 2 860 -s 219 6 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) - XClient.exe (PID: 5428 cmdline:
"C:\Users\ user\AppDa ta\Roaming \XClient.e xe" MD5: E82A4E80B783AB902E649D21DCD0F3D5) - schtasks.exe (PID: 1896 cmdline:
"C:\Window s\System32 \schtasks. exe" /crea te /f /RL HIGHEST /s c minute / mo 1 /tn " Teams" /tr "C:\Users \user\AppD ata\Roamin g\Teams.ex e" MD5: 76CD6626DD8834BD4A42E6A565104DC2) - conhost.exe (PID: 6844 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- Teams.exe (PID: 6172 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Teams.exe MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- Teams.exe (PID: 1892 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Teams.exe " MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- Teams.exe (PID: 4196 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Teams.exe " MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- Teams.exe (PID: 6112 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Teams.exe MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- Teams.exe (PID: 5168 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Teams.exe MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- Teams.exe (PID: 5988 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Teams.exe MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- Teams.exe (PID: 3288 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Teams.exe MD5: E82A4E80B783AB902E649D21DCD0F3D5)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
{"C2 url": ["Cactus-33152.portmap.host"], "Port": 33152, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.2"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PowershellDownloadAndExecute | Yara detected Powershell download and execute | Joe Security | ||
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 2 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 5 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io': |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T21:00:09.122437+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49707 | 172.67.203.125 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T21:02:40.792427+0100 | 2853193 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50028 | 193.161.193.99 | 33152 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Operating System Destruction |
---|
Source: | Process information set: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 2_2_00007FF848F52540 | |
Source: | Code function: | 2_2_00007FF848F46DB0 | |
Source: | Code function: | 2_2_00007FF848F44928 | |
Source: | Code function: | 4_2_00007FF848F21689 | |
Source: | Code function: | 4_2_00007FF848F284D2 | |
Source: | Code function: | 4_2_00007FF848F27726 | |
Source: | Code function: | 4_2_00007FF848F20EFA | |
Source: | Code function: | 4_2_00007FF848F21FC1 | |
Source: | Code function: | 10_2_00007FF848F31689 | |
Source: | Code function: | 10_2_00007FF848F30EFA | |
Source: | Code function: | 10_2_00007FF848F31FC1 | |
Source: | Code function: | 11_2_00007FF848F01689 | |
Source: | Code function: | 11_2_00007FF848F01FC1 | |
Source: | Code function: | 11_2_00007FF848F00EFA | |
Source: | Code function: | 17_2_00007FF848F11689 | |
Source: | Code function: | 17_2_00007FF848F10EFA | |
Source: | Code function: | 17_2_00007FF848F11FC1 | |
Source: | Code function: | 19_2_00007FF848F31689 | |
Source: | Code function: | 19_2_00007FF848F30EFA | |
Source: | Code function: | 19_2_00007FF848F31FC1 | |
Source: | Code function: | 20_2_00007FF848F21689 | |
Source: | Code function: | 20_2_00007FF848F20EFA | |
Source: | Code function: | 20_2_00007FF848F21FC1 | |
Source: | Code function: | 21_2_00007FF848F21689 | |
Source: | Code function: | 21_2_00007FF848F20EFA | |
Source: | Code function: | 21_2_00007FF848F21FC1 | |
Source: | Code function: | 22_2_00007FF848F31689 | |
Source: | Code function: | 22_2_00007FF848F30EFA | |
Source: | Code function: | 22_2_00007FF848F31FC1 |
Source: | Dropped File: |
Source: | Process created: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00007FF848F200C1 | |
Source: | Code function: | 2_2_00007FF848F5D837 | |
Source: | Code function: | 2_2_00007FF848F5A282 | |
Source: | Code function: | 2_2_00007FF848F400C1 | |
Source: | Code function: | 4_2_00007FF848F2134A | |
Source: | Code function: | 4_2_00007FF848F200C1 | |
Source: | Code function: | 10_2_00007FF848F300C1 | |
Source: | Code function: | 17_2_00007FF848F100C1 | |
Source: | Code function: | 19_2_00007FF848F300C1 | |
Source: | Code function: | 20_2_00007FF848F200C1 | |
Source: | Code function: | 21_2_00007FF848F200C1 | |
Source: | Code function: | 22_2_00007FF848F300C1 |
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Persistence and Installation Behavior |
---|
Source: | Process created: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Process created: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File source: | ||
Source: | File source: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Windows Management Instrumentation | 1 Scheduled Task/Job | 11 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Query Registry | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 21 Registry Run Keys / Startup Folder | 1 Scheduled Task/Job | 1 Disable or Modify Tools | LSASS Memory | 231 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 21 Registry Run Keys / Startup Folder | 141 Virtualization/Sandbox Evasion | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 11 Process Injection | NTDS | 141 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | 13 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Obfuscated Files or Information | Cached Domain Credentials | 1 System Network Configuration Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 22 Software Packing | DCSync | 1 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | 13 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
68% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1305769 | ||
100% | Avira | HEUR/AGEN.1305769 | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
63% | ReversingLabs | Win64.Trojan.Heracles | ||
83% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT | ||
83% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
Cactus-33152.portmap.host | 193.161.193.99 | true | true | unknown | |
nodejs.org | 104.20.23.46 | true | false | high | |
getsolara.dev | 172.67.203.125 | true | false | high | |
www.nodejs.org | 104.20.22.46 | true | false | high | |
edge-term4-lhr2.roblox.com | 128.116.119.3 | true | false | high | |
clientsettings.roblox.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.67.203.125 | getsolara.dev | United States | 13335 | CLOUDFLARENETUS | false | |
193.161.193.99 | Cactus-33152.portmap.host | Russian Federation | 198134 | BITREE-ASRU | true | |
128.116.119.3 | edge-term4-lhr2.roblox.com | United States | 22697 | ROBLOX-PRODUCTIONUS | false | |
104.20.22.46 | www.nodejs.org | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1561585 |
Start date and time: | 2024-11-23 20:59:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 23 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | kwlYObMOSn.exerenamed because original name is a hash value |
Original Sample Name: | 3914bb7ca015e96eb45556b7fa427a8b5fbfc497a9909b777ea5d4e5b321111e.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@22/13@5/5 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.182.143.212
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, onedsblobprdcus15.centralus.cloudapp.azure.com, login.live.com, slscr.update.microsoft.com, otelrules.azureedge.net, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target BootstrapperV1.23.exe, PID 2860 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 1892 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 3288 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 4196 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 5168 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 5988 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 6112 because it is empty
- Execution Graph export aborted for target Teams.exe, PID 6172 because it is empty
- Execution Graph export aborted for target kwlYObMOSn.exe, PID 4080 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
- VT rate limit hit for: kwlYObMOSn.exe
Time | Type | Description |
---|---|---|
15:00:05 | API Interceptor | |
15:00:06 | API Interceptor | |
15:00:49 | API Interceptor | |
21:00:05 | Autostart | |
21:00:07 | Task Scheduler | |
21:00:13 | Autostart | |
21:00:21 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
172.67.203.125 | Get hash | malicious | XWorm | Browse | ||
Get hash | malicious | Blank Grabber | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | AsyncRAT, XWorm | Browse | |||
Get hash | malicious | Unknown | Browse | |||
193.161.193.99 | Get hash | malicious | RedLine | Browse |
| |
Get hash | malicious | AsyncRAT RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
128.116.119.3 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | DCRat | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
www.nodejs.org | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer, XWorm | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
getsolara.dev | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer, XWorm | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
nodejs.org | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer, XWorm | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITREE-ASRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | AveMaria, PrivateLoader, UACMe | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
ROBLOX-PRODUCTIONUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blank Grabber, Umbral Stealer, XWorm | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Amadey, Credential Flusher, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Blank Grabber | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Amadey, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_BootstrapperV1.2_b3bef142175e2c9feedfe8f06a73673fcbfff2_9c4008b6_55181495-87bb-4c66-9a44-3854d34aea5d\Report.wer
Download File
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 1.2671348489429193 |
Encrypted: | false |
SSDEEP: | 192:H1wgcswr0bU9+dQVaWxejol2/fsLzuiFvZ24lO8F:OgcsPbG+dQVaml23sLzuiFvY4lO8F |
MD5: | 98CDE6EACCCBD6E095E2E545F945BFE7 |
SHA1: | E8774E2ED387E7FB226A4781F0DD4E452068B76A |
SHA-256: | D9C4EAE29A26D430BDA2C776CC5B7B1C9F32677D0F48E98B612478DF33E62E22 |
SHA-512: | C52AE114C82720A3A1C23D596B73C05B1E90F3CF35DEF8DAF82CB7749E9901812864B5FDEE3BDBD2487ECFBC3B268567744FD9BAA118FC8B7285CF940D790B6F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 603646 |
Entropy (8bit): | 3.307347295263333 |
Encrypted: | false |
SSDEEP: | 6144:yfyDzrySV6kN8OvtKdqyuyq3IpA2OiK0nAc3QK/P:y8rySV46yq3IpA2OizQ |
MD5: | 1CF39890037C7C4017E35D7566788C2E |
SHA1: | FA9BBB18E2BFDD4FB629BF0C2FB85AF5B8C794CB |
SHA-256: | 639053F7FDAC259CA802D40975E941A3A603C36BD20D6531E15FC6233AA126B2 |
SHA-512: | 9A81D37C7CCE43EDCF46A06319DEBE7AC2B76E222F7FAAE08E4E78F13607D2F16948A8B86CEC7B28A1108AB7E548567206367DB9BFA16CACC3B0EA8578E910A8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6824 |
Entropy (8bit): | 3.7187814624713535 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJQVZio5gbYZK8Ypru89baCUfsem:R6lXJyZiUgbYAJapfc |
MD5: | 342E319241D85DE8AF523DED652C0C72 |
SHA1: | 77396E79DC66DC75DDAC61265E3FDCE7612C91D6 |
SHA-256: | FE07ADB460C4859283FA9A2054B7689EB9BB771103D574C20B485AF2E6CBE8BC |
SHA-512: | 82DF750482004E3EDDF12A1D01B6FEAEFDBBE0DC06DA822F22E9F9BCC15493FED41DFF476BF57A80F90258BAFE2CFE44215D8BBA6063A2569162C10FC45F963A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4834 |
Entropy (8bit): | 4.464854798453406 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zs0Jg771I9pOWpW8VY3Ym8M4JQKy/FMNlyq8vay4Dx5b5Ud:uIjfyI7mv7VbJzWGf1Ud |
MD5: | C2B14730949DC8304808266C5785100F |
SHA1: | E2D3CA390F32DE893A461301F6CF3DEB383D91B4 |
SHA-256: | 4F5DB76274A7E33C7C2AEBBA28F5B2B7725C89847A55A6BB2E3809DE85866ADA |
SHA-512: | CD43810FC93035201FC1850E951C2CCD788460702A303299E830CE797F97FC4846B63FD777EB3FECACB3898A68B9339E1F5FFA0A4204C8B9CB8E455890179B5A |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\Teams.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 654 |
Entropy (8bit): | 5.380476433908377 |
Encrypted: | false |
SSDEEP: | 12:Q3La/KDLI4MWuPXcp1OKbbDLI4MWuPOKfSSI6Khap+92n4MNQp3/VXM5gXu9tv:ML9E4KQwKDE4KGKZI6Kh6+84xp3/VclT |
MD5: | 30E4BDFC34907D0E4D11152CAEBE27FA |
SHA1: | 825402D6B151041BA01C5117387228EC9B7168BF |
SHA-256: | A7B8F7FFB4822570DB1423D61ED74D7F4B538CE73521CC8745BC6B131C18BE63 |
SHA-512: | 89FBCBCDB0BE5AD7A95685CF9AA4330D5B0250440E67DC40C6642260E024F52A402E9381F534A9824D2541B98B02094178A15BF2320148432EDB0D09B5F972BA |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\kwlYObMOSn.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 654 |
Entropy (8bit): | 5.380476433908377 |
Encrypted: | false |
SSDEEP: | 12:Q3La/KDLI4MWuPXcp1OKbbDLI4MWuPOKfSSI6Khap+92n4MNQp3/VXM5gXu9tv:ML9E4KQwKDE4KGKZI6Kh6+84xp3/VclT |
MD5: | 30E4BDFC34907D0E4D11152CAEBE27FA |
SHA1: | 825402D6B151041BA01C5117387228EC9B7168BF |
SHA-256: | A7B8F7FFB4822570DB1423D61ED74D7F4B538CE73521CC8745BC6B131C18BE63 |
SHA-512: | 89FBCBCDB0BE5AD7A95685CF9AA4330D5B0250440E67DC40C6642260E024F52A402E9381F534A9824D2541B98B02094178A15BF2320148432EDB0D09B5F972BA |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\kwlYObMOSn.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 819200 |
Entropy (8bit): | 5.598261375667174 |
Encrypted: | false |
SSDEEP: | 12288:qhd8cjaLXVh84wEFkW1mocaBj6WtiRPpptHxQ0z:2ycjar84w5W4ocaBj6y2tHDz |
MD5: | 02C70D9D6696950C198DB93B7F6A835E |
SHA1: | 30231A467A49CC37768EEA0F55F4BEA1CBFB48E2 |
SHA-256: | 8F2E28588F2303BD8D7A9B0C3FF6A9CB16FA93F8DDC9C5E0666A8C12D6880EE3 |
SHA-512: | 431D9B9918553BFF4F4A5BC2A5E7B7015F8AD0E2D390BB4D5264D08983372424156524EF5587B24B67D1226856FC630AACA08EDC8113097E0094501B4F08EFEB |
Malicious: | true |
Antivirus: |
|
Joe Sandbox View: | |
Preview: |
Process: | C:\Users\user\AppData\Roaming\XClient.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 753 |
Entropy (8bit): | 5.00342396501985 |
Encrypted: | false |
SSDEEP: | 12:8b04f+88CQTlsY//49ESLAItXZClWUjAMHENlWtmxMxfmV:8RfF8lZwmsAqslWAA7NlWtSEfm |
MD5: | 9A1C13C1DFEAC2E49524050A020BD8EE |
SHA1: | 98B322C0AAC3D3878086E5E99A19E2B453B3E581 |
SHA-256: | 827618C840CB935EFFEEF5250C80F520D80F988EB133CE9198D2149C146C3B03 |
SHA-512: | 43021A195DEF58249A7750DD35BE88F5FB66BC8C633A004E016B042E4EF37069311FF5667A9CDBAC627BC7B43A5EA8BE73CB00BD6B8217513AFA3E72CA1B496C |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\XClient.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 68096 |
Entropy (8bit): | 6.020738658795511 |
Encrypted: | false |
SSDEEP: | 1536:0QPbpWkVHai1Ub2rFRIdxRmKVMKokb4R9rAooBsh6bgOP+l:0QDpWk6Jb6+xVMKokb4RndOP+l |
MD5: | E82A4E80B783AB902E649D21DCD0F3D5 |
SHA1: | DD32A84C4BFF58262FECB1511FBDBECDAC2B8045 |
SHA-256: | 63988792736CC57B3B93735662A660A4229D76E487D3D59ABC0AE17BC05050A5 |
SHA-512: | 51E5CA643E3E7576F073207EE854B10CF9DC61434670D20AFE771AAAFBBD883FF5A09CC471C5B5E2334BE5FF4C8E83B32722E7A8F29F5C61379B225191E98F98 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\kwlYObMOSn.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 68096 |
Entropy (8bit): | 6.020738658795511 |
Encrypted: | false |
SSDEEP: | 1536:0QPbpWkVHai1Ub2rFRIdxRmKVMKokb4R9rAooBsh6bgOP+l:0QDpWk6Jb6+xVMKokb4RndOP+l |
MD5: | E82A4E80B783AB902E649D21DCD0F3D5 |
SHA1: | DD32A84C4BFF58262FECB1511FBDBECDAC2B8045 |
SHA-256: | 63988792736CC57B3B93735662A660A4229D76E487D3D59ABC0AE17BC05050A5 |
SHA-512: | 51E5CA643E3E7576F073207EE854B10CF9DC61434670D20AFE771AAAFBBD883FF5A09CC471C5B5E2334BE5FF4C8E83B32722E7A8F29F5C61379B225191E98F98 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 103 |
Entropy (8bit): | 4.081427527984575 |
Encrypted: | false |
SSDEEP: | 3:XSWHlkHFWKBgdvHvIhN9GIxFf9oQg652UTF/HLMl1m:XSWHlW0aivQLkWFfx/52uyPm |
MD5: | B016DAFCA051F817C6BA098C096CB450 |
SHA1: | 4CC74827C4B2ED534613C7764E6121CEB041B459 |
SHA-256: | B03C8C2D2429E9DBC7920113DEDF6FC09095AB39421EE0CC8819AD412E5D67B9 |
SHA-512: | D69663E1E81EC33654B87F2DFADDD5383681C8EBF029A559B201D65EB12FA2989FA66C25FA98D58066EAB7B897F0EEF6B7A68FA1A9558482A17DFED7B6076ACA |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.421796526248881 |
Encrypted: | false |
SSDEEP: | 6144:8Svfpi6ceLP/9skLmb0OT5WSPHaJG8nAgeMZMMhA2fX4WABlEnNE0uhiTw:nvloT5W+EZMM6DFyK03w |
MD5: | 81A1AA30793DD8171DDB48E3695E336C |
SHA1: | CE3A89F8B7ED7728A8411D7FFFE11667F622DB07 |
SHA-256: | 4D5D6EB65BD43D5F68F21A4A450AB3ECACBCA3E037E0537A739B9C70DD6D79BA |
SHA-512: | 070F4EE46A5D7F8FCC2A682F60EBFCE44E63A4450CBD2D25D2C066924D488912A229EF517EBA8EC0216C50B1807969C681E0CB0CAD920B148E3CCE3AE424378A |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 571 |
Entropy (8bit): | 4.9398118662542965 |
Encrypted: | false |
SSDEEP: | 12:t+3p+t/hQAOfVaOQsXCzLQ8X+UwkY1v3igBe:Yot/h+ltcQy+UwkY1vdBe |
MD5: | 5294778E41EE83E1F1E78B56466AD690 |
SHA1: | 348B8B4687216D57B8DF59BBCEC481DC9D1E61A6 |
SHA-256: | 3AC122288181813B83236E1A2BCB449C51B50A3CA4925677A38C08B2FC6DF69C |
SHA-512: | 381FB6F3AA34E41C17DB3DD8E68B85508F51A94B3E77C479E40AD074767D1CEAE89B6E04FB7DD3D02A74D1AC3431B30920860A198C73387A865051538AE140F1 |
Malicious: | true |
Yara Hits: |
|
Preview: |
File type: | |
Entropy (8bit): | 7.996910042858342 |
TrID: |
|
File name: | kwlYObMOSn.exe |
File size: | 897'536 bytes |
MD5: | f28a1fb54a5c3b2b4e4184e3dff4f50a |
SHA1: | 180878512f7cd7c75c87fff174203228de688d34 |
SHA256: | 3914bb7ca015e96eb45556b7fa427a8b5fbfc497a9909b777ea5d4e5b321111e |
SHA512: | b15a376ed2370dd0c338a6736c450cfb6ae7b670a69e3b54eb2105a19cf6e4b7cecbbed1c96bc91db1653a3106d873f889e5788a83eff874c1341cfd7adc39c4 |
SSDEEP: | 24576:dAt5/Yxh3QlHPSZtbd1aRu8w2BdgXKhzm1OtH6nNnKAAAG/AA14eF0oayiw:m5ucEbr8PgXKhqItH6nNnKAAAG/AA14f |
TLSH: | 10152359F5F13222EB65EBBF0FF8A9014CF057226203194FF328351D94B55E646BA24E |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...q.6g................................. ........@.. ....................... ............@................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x4dc6ce |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67369F71 [Fri Nov 15 01:10:09 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xdc678 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xde000 | 0x4d0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe0000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xda6d4 | 0xda800 | 63a2167270a33cbff4f34a97e2c9500d | False | 0.9395816200657895 | data | 7.998505878740895 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xde000 | 0x4d0 | 0x600 | 184937c6229aad767aedda4cfa4a4f16 | False | 0.375 | data | 3.7002969536945476 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe0000 | 0xc | 0x200 | 0cf50d5b905ebadd8448137df7b814a8 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xde0a0 | 0x23c | data | 0.4772727272727273 | ||
RT_MANIFEST | 0xde2e0 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T21:00:09.122437+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49707 | 172.67.203.125 | 443 | TCP |
2024-11-23T21:01:12.622457+0100 | 2855924 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.5 | 49850 | 193.161.193.99 | 33152 | TCP |
2024-11-23T21:02:40.792427+0100 | 2853193 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.5 | 50028 | 193.161.193.99 | 33152 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 23, 2024 21:00:03.299864054 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:03.299899101 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:03.299959898 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:03.445008039 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:03.445030928 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:04.765207052 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:04.765346050 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:04.771785975 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:04.771801949 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:04.772037983 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:04.812753916 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:04.828233957 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:04.871335983 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:05.262703896 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:05.262813091 CET | 443 | 49704 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:05.262887001 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:05.279489040 CET | 49704 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:07.261588097 CET | 49706 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:07.348407030 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:07.348470926 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:07.348553896 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:07.349716902 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:07.349747896 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:07.386845112 CET | 33152 | 49706 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:07.386962891 CET | 49706 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:07.514628887 CET | 49706 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:07.636244059 CET | 33152 | 49706 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:08.615365028 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:08.615477085 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:08.617176056 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:08.617225885 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:08.617475986 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:08.672152042 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:08.701483965 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:08.747332096 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:09.122443914 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:09.122570992 CET | 443 | 49707 | 172.67.203.125 | 192.168.2.5 |
Nov 23, 2024 21:00:09.122631073 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:09.123128891 CET | 49707 | 443 | 192.168.2.5 | 172.67.203.125 |
Nov 23, 2024 21:00:09.606074095 CET | 33152 | 49706 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:09.606162071 CET | 49706 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:09.704185963 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:09.704221010 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:09.704307079 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:09.704593897 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:09.704610109 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.225498915 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.225619078 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:11.228952885 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:11.228965998 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.229217052 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.270900965 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:11.315331936 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.859807968 CET | 49706 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:11.862204075 CET | 49709 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:11.971838951 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.971924067 CET | 443 | 49708 | 128.116.119.3 | 192.168.2.5 |
Nov 23, 2024 21:00:11.971987009 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:11.972378016 CET | 49708 | 443 | 192.168.2.5 | 128.116.119.3 |
Nov 23, 2024 21:00:11.981117010 CET | 33152 | 49706 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:11.982709885 CET | 33152 | 49709 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:11.982791901 CET | 49709 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:11.998296022 CET | 49709 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:12.122009039 CET | 33152 | 49709 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:13.660742044 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:13.660794020 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:13.660954952 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:13.661197901 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:13.661216974 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:14.240144014 CET | 33152 | 49709 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:14.240221024 CET | 49709 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:14.939510107 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:14.939584970 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:14.941447973 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:14.941458941 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:14.941822052 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:14.943999052 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:14.991355896 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:15.516002893 CET | 49709 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:15.517836094 CET | 49711 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:15.642441988 CET | 33152 | 49709 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:15.644200087 CET | 33152 | 49711 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:15.644282103 CET | 49711 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:15.658325911 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:15.658463955 CET | 443 | 49710 | 104.20.22.46 | 192.168.2.5 |
Nov 23, 2024 21:00:15.658519983 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:15.658898115 CET | 49710 | 443 | 192.168.2.5 | 104.20.22.46 |
Nov 23, 2024 21:00:15.703146935 CET | 49711 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:15.822837114 CET | 33152 | 49711 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:17.871303082 CET | 33152 | 49711 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:17.873156071 CET | 49711 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:19.186677933 CET | 49711 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:19.191452980 CET | 49715 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:19.306468964 CET | 33152 | 49711 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:19.311083078 CET | 33152 | 49715 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:19.311211109 CET | 49715 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:19.630975008 CET | 49715 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:19.752804995 CET | 33152 | 49715 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:21.521542072 CET | 33152 | 49715 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:21.521755934 CET | 49715 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:23.392069101 CET | 49715 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:23.394730091 CET | 49727 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:23.511732101 CET | 33152 | 49715 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:23.514270067 CET | 33152 | 49727 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:23.514410019 CET | 49727 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:23.534077883 CET | 49727 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:23.654139042 CET | 33152 | 49727 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:25.771286964 CET | 33152 | 49727 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:25.771368980 CET | 49727 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:26.734819889 CET | 49727 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:26.736030102 CET | 49734 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:26.968583107 CET | 33152 | 49727 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:26.968615055 CET | 33152 | 49734 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:26.968794107 CET | 49734 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:27.000791073 CET | 49734 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:27.120539904 CET | 33152 | 49734 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:29.187747002 CET | 33152 | 49734 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:29.188133001 CET | 49734 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:31.891154051 CET | 49734 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:31.893466949 CET | 49745 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:32.017563105 CET | 33152 | 49734 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:32.020026922 CET | 33152 | 49745 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:32.020153999 CET | 49745 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:32.055676937 CET | 49745 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:32.175298929 CET | 33152 | 49745 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:34.322139025 CET | 33152 | 49745 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:34.323489904 CET | 49745 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:36.203557014 CET | 49745 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:36.205538034 CET | 49757 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:36.324210882 CET | 33152 | 49745 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:36.326049089 CET | 33152 | 49757 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:36.326167107 CET | 49757 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:36.342494011 CET | 49757 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:36.462790012 CET | 33152 | 49757 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:38.575720072 CET | 33152 | 49757 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:38.575850010 CET | 49757 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:40.719305038 CET | 49757 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:40.720619917 CET | 49770 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:40.845870018 CET | 33152 | 49757 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:40.847115993 CET | 33152 | 49770 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:40.847230911 CET | 49770 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:40.865673065 CET | 49770 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:40.987579107 CET | 33152 | 49770 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:43.147207022 CET | 33152 | 49770 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:43.147402048 CET | 49770 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:45.172965050 CET | 49770 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:45.174609900 CET | 49783 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:45.298563957 CET | 33152 | 49770 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:45.300383091 CET | 33152 | 49783 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:45.300467968 CET | 49783 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:45.319127083 CET | 49783 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:45.445641994 CET | 33152 | 49783 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:47.506131887 CET | 33152 | 49783 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:47.506221056 CET | 49783 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:48.552093983 CET | 49783 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:48.567024946 CET | 49790 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:48.674752951 CET | 33152 | 49783 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:48.689627886 CET | 33152 | 49790 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:48.689727068 CET | 49790 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:48.765028954 CET | 49790 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:48.891381979 CET | 33152 | 49790 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:51.044101954 CET | 33152 | 49790 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:51.044169903 CET | 49790 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:52.266100883 CET | 49790 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:52.267388105 CET | 49803 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:52.388396978 CET | 33152 | 49790 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:52.389782906 CET | 33152 | 49803 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:52.389852047 CET | 49803 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:52.405474901 CET | 49803 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:52.529812098 CET | 33152 | 49803 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:54.559479952 CET | 33152 | 49803 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:54.559575081 CET | 49803 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:55.219149113 CET | 49803 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:55.220257044 CET | 49809 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:55.340595007 CET | 33152 | 49803 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:55.341862917 CET | 33152 | 49809 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:55.344110012 CET | 49809 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:55.358158112 CET | 49809 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:55.651221037 CET | 33152 | 49809 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:57.772011042 CET | 33152 | 49809 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:57.773206949 CET | 49809 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:57.878268957 CET | 49809 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:57.879410028 CET | 49815 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:57.997936964 CET | 33152 | 49809 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:57.998982906 CET | 33152 | 49815 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:00:57.999082088 CET | 49815 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:58.014273882 CET | 49815 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:00:58.140716076 CET | 33152 | 49815 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:00.262073040 CET | 33152 | 49815 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:00.262259960 CET | 49815 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:01.469096899 CET | 49815 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:01.470441103 CET | 49827 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:01.589571953 CET | 33152 | 49815 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:01.590214014 CET | 33152 | 49827 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:01.590316057 CET | 49827 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:01.604844093 CET | 49827 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:01.724407911 CET | 33152 | 49827 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:03.818872929 CET | 33152 | 49827 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:03.818943024 CET | 49827 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:03.844400883 CET | 49827 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:03.846652985 CET | 49833 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:03.989620924 CET | 33152 | 49827 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:03.989640951 CET | 33152 | 49833 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:03.989732027 CET | 49833 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:04.007136106 CET | 49833 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:04.126966953 CET | 33152 | 49833 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:06.200140953 CET | 33152 | 49833 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:06.200223923 CET | 49833 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:06.859869003 CET | 49833 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:06.860991955 CET | 49839 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:06.980654001 CET | 33152 | 49833 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:06.981775999 CET | 33152 | 49839 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:06.981854916 CET | 49839 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:06.996658087 CET | 49839 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:07.121910095 CET | 33152 | 49839 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:09.356677055 CET | 33152 | 49839 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:09.356787920 CET | 49839 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:09.609901905 CET | 49839 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:09.610963106 CET | 49845 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:09.734100103 CET | 33152 | 49839 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:09.735075951 CET | 33152 | 49845 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:09.735163927 CET | 49845 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:09.751357079 CET | 49845 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:09.870971918 CET | 33152 | 49845 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:11.975301027 CET | 33152 | 49845 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:11.975450993 CET | 49845 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:11.984908104 CET | 49845 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:11.988428116 CET | 49850 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:12.104592085 CET | 33152 | 49845 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:12.108231068 CET | 33152 | 49850 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:12.108923912 CET | 49850 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:12.136013031 CET | 49850 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:12.255645037 CET | 33152 | 49850 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:12.622457027 CET | 49850 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:12.774574995 CET | 33152 | 49850 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:14.319156885 CET | 33152 | 49850 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:14.319384098 CET | 49850 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:17.922445059 CET | 49850 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:17.926841974 CET | 49863 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:18.042232037 CET | 33152 | 49850 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:18.046396971 CET | 33152 | 49863 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:18.047405005 CET | 49863 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:18.243248940 CET | 49863 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:18.363203049 CET | 33152 | 49863 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:20.216532946 CET | 33152 | 49863 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:20.223373890 CET | 49863 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:23.422841072 CET | 49863 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:23.425652981 CET | 49878 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:23.545886040 CET | 33152 | 49863 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:23.548445940 CET | 33152 | 49878 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:23.548543930 CET | 49878 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:23.577423096 CET | 49878 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:23.716734886 CET | 33152 | 49878 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:25.781775951 CET | 33152 | 49878 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:25.781963110 CET | 49878 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:28.938066959 CET | 49878 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:28.940043926 CET | 49891 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:29.058788061 CET | 33152 | 49878 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:29.060421944 CET | 33152 | 49891 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:29.060520887 CET | 49891 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:29.095881939 CET | 49891 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:29.218436956 CET | 33152 | 49891 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:29.218511105 CET | 49891 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:29.338110924 CET | 33152 | 49891 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:31.335202932 CET | 33152 | 49891 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:31.335278034 CET | 49891 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:34.220731974 CET | 49891 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:34.220973969 CET | 49902 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:34.340869904 CET | 33152 | 49891 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:34.341259956 CET | 33152 | 49902 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:34.344465017 CET | 49902 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:34.529293060 CET | 49902 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:34.648889065 CET | 33152 | 49902 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:36.577519894 CET | 33152 | 49902 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:36.577629089 CET | 49902 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:39.598490000 CET | 49902 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:39.647177935 CET | 49916 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:39.724705935 CET | 33152 | 49902 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:39.772231102 CET | 33152 | 49916 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:39.772381067 CET | 49916 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:39.960097075 CET | 49916 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:40.079791069 CET | 33152 | 49916 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:41.982325077 CET | 33152 | 49916 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:41.985441923 CET | 49916 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:45.047614098 CET | 49916 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:45.048935890 CET | 49929 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:45.169524908 CET | 33152 | 49916 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:45.170958996 CET | 33152 | 49929 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:45.171041965 CET | 49929 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:45.208410025 CET | 49929 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:45.329502106 CET | 33152 | 49929 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:47.413651943 CET | 33152 | 49929 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:47.413877010 CET | 49929 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:50.456245899 CET | 49929 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:50.470392942 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:50.577608109 CET | 33152 | 49929 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:50.589993000 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:50.593511105 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:50.852737904 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:50.972702980 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:50.972774982 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:51.092622995 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:51.092693090 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:51.217437029 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:51.217515945 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:51.344166040 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:52.786143064 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:52.786243916 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:56.206248999 CET | 49953 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:56.206259966 CET | 49940 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:56.332783937 CET | 33152 | 49953 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:56.332824945 CET | 33152 | 49940 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:56.333478928 CET | 49953 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:56.385385990 CET | 49953 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:01:56.607283115 CET | 33152 | 49953 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:58.773209095 CET | 33152 | 49953 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:01:58.773411036 CET | 49953 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:01.500602007 CET | 49953 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:01.504160881 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:01.644845009 CET | 33152 | 49953 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:01.644889116 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:01.645215034 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:01.773494005 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:01.927239895 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:02.767220974 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:02.887109995 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:02.887157917 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:03.008790970 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:03.008857012 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:03.128547907 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:03.128609896 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:03.248270988 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:03.248328924 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:03.368107080 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:03.610661983 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:03.731745958 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:04.086576939 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:04.086720943 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:08.156769991 CET | 49966 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:08.159075022 CET | 49981 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:08.283191919 CET | 33152 | 49966 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:08.459579945 CET | 33152 | 49981 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:08.459676981 CET | 49981 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:08.527379990 CET | 49981 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:08.647099972 CET | 33152 | 49981 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:10.807389975 CET | 33152 | 49981 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:10.807471991 CET | 49981 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:13.625562906 CET | 49981 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:13.628334045 CET | 49993 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:13.796082973 CET | 33152 | 49981 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:13.796106100 CET | 33152 | 49993 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:13.799978018 CET | 49993 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:13.926516056 CET | 49993 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:14.046093941 CET | 33152 | 49993 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:16.123604059 CET | 33152 | 49993 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:16.123902082 CET | 49993 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:18.985049009 CET | 49993 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:18.987931013 CET | 50004 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:19.104815006 CET | 33152 | 49993 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:19.107449055 CET | 33152 | 50004 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:19.107522011 CET | 50004 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:19.147490025 CET | 50004 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:19.269813061 CET | 33152 | 50004 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:19.269881010 CET | 50004 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:19.391911983 CET | 33152 | 50004 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:21.352081060 CET | 33152 | 50004 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:21.352161884 CET | 50004 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:24.235146999 CET | 50004 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:24.237607002 CET | 50015 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:24.354706049 CET | 33152 | 50004 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:24.357326984 CET | 33152 | 50015 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:24.357467890 CET | 50015 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:24.465492964 CET | 50015 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:24.643404961 CET | 33152 | 50015 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:26.601911068 CET | 33152 | 50015 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:26.602031946 CET | 50015 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:29.688163996 CET | 50015 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:29.689789057 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:29.818505049 CET | 33152 | 50015 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:29.818536043 CET | 33152 | 50026 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:29.818629026 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:29.932665110 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:30.052321911 CET | 33152 | 50026 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:30.078922987 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:30.201303959 CET | 33152 | 50026 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:30.204071045 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:30.323843002 CET | 33152 | 50026 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:32.030174017 CET | 33152 | 50026 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:32.033607006 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:34.953902960 CET | 50026 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:34.956784010 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:35.074821949 CET | 33152 | 50026 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:35.077553034 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:35.077656984 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:35.119874954 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:35.246279001 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:35.246352911 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:35.372697115 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:35.372764111 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:35.497040987 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:35.497102976 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:35.616898060 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:37.290007114 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:37.290160894 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:40.438198090 CET | 50027 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:40.445549965 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:40.564450979 CET | 33152 | 50027 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:40.572083950 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:40.573617935 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:40.672575951 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:40.792367935 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:40.792427063 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:40.913609982 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:40.913670063 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:41.033386946 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:41.033443928 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:41.153031111 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:42.868109941 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:42.868191957 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:46.065466881 CET | 50028 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:46.068265915 CET | 50029 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:46.185097933 CET | 33152 | 50028 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:46.187803984 CET | 33152 | 50029 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:46.188467979 CET | 50029 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:46.246493101 CET | 50029 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:46.368263960 CET | 33152 | 50029 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:48.390034914 CET | 33152 | 50029 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:48.390237093 CET | 50029 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:51.328849077 CET | 50029 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:51.331342936 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:51.473354101 CET | 33152 | 50029 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:51.473391056 CET | 33152 | 50030 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:51.473465919 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:51.509715080 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:51.661333084 CET | 33152 | 50030 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:51.661432028 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:51.782529116 CET | 33152 | 50030 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:52.563518047 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:52.683114052 CET | 33152 | 50030 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:53.686988115 CET | 33152 | 50030 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:53.687838078 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:56.643618107 CET | 50030 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:56.648034096 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:56.765019894 CET | 33152 | 50030 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:56.769457102 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:56.773605108 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:56.968343973 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:57.088000059 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:57.088061094 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:57.208074093 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:57.208316088 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:57.328118086 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:57.375945091 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:57.502000093 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:57.502059937 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:57.624116898 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:57.624178886 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:02:57.743736029 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:58.999507904 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:02:58.999571085 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:02.578875065 CET | 50031 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:02.585643053 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:02.702831984 CET | 33152 | 50031 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:02.708714008 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:02.708848000 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:02.829986095 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:02.952294111 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:02.952367067 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:03.078382969 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:03.078450918 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:03.316735983 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:03.316804886 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:03.436429977 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:04.962121010 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:04.962192059 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:08.047751904 CET | 50032 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:08.053644896 CET | 50033 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:08.167387009 CET | 33152 | 50032 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:08.173242092 CET | 33152 | 50033 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:08.173381090 CET | 50033 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:08.337641001 CET | 50033 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:08.464145899 CET | 33152 | 50033 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:09.516854048 CET | 50033 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:09.636778116 CET | 33152 | 50033 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:10.415786028 CET | 33152 | 50033 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:10.421657085 CET | 50033 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:13.355668068 CET | 50033 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:13.359085083 CET | 50034 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:13.482037067 CET | 33152 | 50033 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:13.485352039 CET | 33152 | 50034 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:13.485431910 CET | 50034 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:13.527534008 CET | 50034 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:13.650546074 CET | 33152 | 50034 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:13.650652885 CET | 50034 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:13.770186901 CET | 33152 | 50034 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:15.712477922 CET | 33152 | 50034 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:15.712702036 CET | 50034 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:18.641690969 CET | 50034 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:18.669342995 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:18.761812925 CET | 33152 | 50034 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:18.788932085 CET | 33152 | 50035 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:18.793678045 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:18.872490883 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:18.993046045 CET | 33152 | 50035 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:18.993094921 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:19.114975929 CET | 33152 | 50035 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:20.063421011 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:20.185802937 CET | 33152 | 50035 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:21.000004053 CET | 33152 | 50035 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:21.000072002 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:23.953895092 CET | 50035 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:23.957716942 CET | 50036 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:24.080616951 CET | 33152 | 50035 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:24.084177017 CET | 33152 | 50036 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:24.084263086 CET | 50036 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:24.199932098 CET | 50036 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:24.395725965 CET | 33152 | 50036 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:24.594705105 CET | 50036 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:24.716893911 CET | 33152 | 50036 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:26.524924040 CET | 33152 | 50036 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:26.525821924 CET | 50036 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.204215050 CET | 50036 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.207675934 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.345948935 CET | 33152 | 50036 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:29.345962048 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:29.346040964 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.384287119 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.509097099 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:29.509166002 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.631556034 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:29.631618977 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.751687050 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:29.751749992 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:29.874330997 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:31.560635090 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:31.560705900 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:34.688357115 CET | 50037 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:34.691911936 CET | 50038 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:34.811491966 CET | 33152 | 50037 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:34.816422939 CET | 33152 | 50038 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:34.822870970 CET | 50038 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:34.890341997 CET | 50038 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:35.009902000 CET | 33152 | 50038 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:35.009964943 CET | 50038 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:35.129529953 CET | 33152 | 50038 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:37.031842947 CET | 33152 | 50038 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:37.031949997 CET | 50038 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:39.969739914 CET | 50038 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:39.973766088 CET | 50039 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:40.089329004 CET | 33152 | 50038 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:40.093496084 CET | 33152 | 50039 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:40.093880892 CET | 50039 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:40.201632023 CET | 50039 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:40.370523930 CET | 33152 | 50039 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:42.366164923 CET | 33152 | 50039 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:42.366952896 CET | 50039 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.328998089 CET | 50039 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.331741095 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.452915907 CET | 33152 | 50039 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:45.455849886 CET | 33152 | 50040 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:45.455925941 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.495436907 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.615591049 CET | 33152 | 50040 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:45.615643978 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.737986088 CET | 33152 | 50040 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:45.738168001 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:45.864496946 CET | 33152 | 50040 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:47.697666883 CET | 33152 | 50040 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:47.697745085 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:50.596823931 CET | 50041 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:50.596837044 CET | 50040 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:50.716510057 CET | 33152 | 50041 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:50.716532946 CET | 33152 | 50040 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:50.716669083 CET | 50041 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:50.800827980 CET | 50041 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:50.921355963 CET | 33152 | 50041 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:52.953984022 CET | 33152 | 50041 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:52.954051971 CET | 50041 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:55.891460896 CET | 50041 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:55.895685911 CET | 50042 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:56.011454105 CET | 33152 | 50041 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:56.015459061 CET | 33152 | 50042 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:56.020874023 CET | 50042 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:56.076829910 CET | 50042 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:03:56.196764946 CET | 33152 | 50042 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:58.259979010 CET | 33152 | 50042 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:03:58.261905909 CET | 50042 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:01.110373020 CET | 50042 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:01.113688946 CET | 50043 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:01.230602026 CET | 33152 | 50042 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:01.234611988 CET | 33152 | 50043 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:01.234694004 CET | 50043 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:01.279756069 CET | 50043 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:01.405982971 CET | 33152 | 50043 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:01.406039000 CET | 50043 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:01.530016899 CET | 33152 | 50043 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:03.448226929 CET | 33152 | 50043 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:03.448297024 CET | 50043 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:06.328991890 CET | 50043 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:06.330944061 CET | 50044 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:06.452939987 CET | 33152 | 50043 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:06.455004930 CET | 33152 | 50044 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:06.455163002 CET | 50044 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:06.558173895 CET | 50044 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:06.678330898 CET | 33152 | 50044 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:07.891820908 CET | 50044 | 33152 | 192.168.2.5 | 193.161.193.99 |
Nov 23, 2024 21:04:08.011630058 CET | 33152 | 50044 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:08.690259933 CET | 33152 | 50044 | 193.161.193.99 | 192.168.2.5 |
Nov 23, 2024 21:04:08.697870970 CET | 50044 | 33152 | 192.168.2.5 | 193.161.193.99 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 23, 2024 21:00:03.150702000 CET | 53021 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 23, 2024 21:00:03.289911985 CET | 53 | 53021 | 1.1.1.1 | 192.168.2.5 |
Nov 23, 2024 21:00:06.989326000 CET | 49453 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 23, 2024 21:00:07.254636049 CET | 53 | 49453 | 1.1.1.1 | 192.168.2.5 |
Nov 23, 2024 21:00:09.556058884 CET | 53774 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 23, 2024 21:00:09.702918053 CET | 53 | 53774 | 1.1.1.1 | 192.168.2.5 |
Nov 23, 2024 21:00:13.519443035 CET | 61403 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 23, 2024 21:00:13.660063028 CET | 53 | 61403 | 1.1.1.1 | 192.168.2.5 |
Nov 23, 2024 21:00:15.660528898 CET | 56819 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 23, 2024 21:00:15.801084042 CET | 53 | 56819 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 23, 2024 21:00:03.150702000 CET | 192.168.2.5 | 1.1.1.1 | 0x3c14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 23, 2024 21:00:06.989326000 CET | 192.168.2.5 | 1.1.1.1 | 0xb8b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 23, 2024 21:00:09.556058884 CET | 192.168.2.5 | 1.1.1.1 | 0xdba1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 23, 2024 21:00:13.519443035 CET | 192.168.2.5 | 1.1.1.1 | 0x902c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 23, 2024 21:00:15.660528898 CET | 192.168.2.5 | 1.1.1.1 | 0x3955 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 23, 2024 21:00:03.289911985 CET | 1.1.1.1 | 192.168.2.5 | 0x3c14 | No error (0) | 172.67.203.125 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:03.289911985 CET | 1.1.1.1 | 192.168.2.5 | 0x3c14 | No error (0) | 104.21.93.27 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:07.254636049 CET | 1.1.1.1 | 192.168.2.5 | 0xb8b1 | No error (0) | 193.161.193.99 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:09.702918053 CET | 1.1.1.1 | 192.168.2.5 | 0xdba1 | No error (0) | titanium.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:09.702918053 CET | 1.1.1.1 | 192.168.2.5 | 0xdba1 | No error (0) | edge-term4.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:09.702918053 CET | 1.1.1.1 | 192.168.2.5 | 0xdba1 | No error (0) | edge-term4-lhr2.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:09.702918053 CET | 1.1.1.1 | 192.168.2.5 | 0xdba1 | No error (0) | 128.116.119.3 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:13.660063028 CET | 1.1.1.1 | 192.168.2.5 | 0x902c | No error (0) | 104.20.22.46 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:13.660063028 CET | 1.1.1.1 | 192.168.2.5 | 0x902c | No error (0) | 104.20.23.46 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:15.801084042 CET | 1.1.1.1 | 192.168.2.5 | 0x3955 | No error (0) | 104.20.23.46 | A (IP address) | IN (0x0001) | false | ||
Nov 23, 2024 21:00:15.801084042 CET | 1.1.1.1 | 192.168.2.5 | 0x3955 | No error (0) | 104.20.22.46 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49704 | 172.67.203.125 | 443 | 2860 | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-23 20:00:04 UTC | 81 | OUT | |
2024-11-23 20:00:05 UTC | 1021 | IN | |
2024-11-23 20:00:05 UTC | 109 | IN | |
2024-11-23 20:00:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49707 | 172.67.203.125 | 443 | 2860 | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-23 20:00:08 UTC | 56 | OUT | |
2024-11-23 20:00:09 UTC | 1019 | IN | |
2024-11-23 20:00:09 UTC | 350 | IN | |
2024-11-23 20:00:09 UTC | 197 | IN | |
2024-11-23 20:00:09 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49708 | 128.116.119.3 | 443 | 2860 | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-23 20:00:11 UTC | 119 | OUT | |
2024-11-23 20:00:11 UTC | 576 | IN | |
2024-11-23 20:00:11 UTC | 119 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49710 | 104.20.22.46 | 443 | 2860 | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-23 20:00:14 UTC | 99 | OUT | |
2024-11-23 20:00:15 UTC | 497 | IN | |
2024-11-23 20:00:15 UTC | 20 | IN | |
2024-11-23 20:00:15 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 15:00:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\Desktop\kwlYObMOSn.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xd00000 |
File size: | 897'536 bytes |
MD5 hash: | F28A1FB54A5C3B2B4E4184E3DFF4F50A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:00:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\BootstrapperV1.23.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x1e6ebaa0000 |
File size: | 819'200 bytes |
MD5 hash: | 02C70D9D6696950C198DB93B7F6A835E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 15:00:01 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:00:01 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xf20000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 15:00:01 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff792b20000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 15:00:01 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 15:00:01 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\ipconfig.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4650000 |
File size: | 35'840 bytes |
MD5 hash: | 62F170FB07FDBB79CEB7147101406EB8 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 8 |
Start time: | 15:00:05 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70fbd0000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 15:00:05 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 15:00:07 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x850000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 15:00:13 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xb90000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 14 |
Start time: | 15:00:14 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\WerFault.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff721450000 |
File size: | 570'736 bytes |
MD5 hash: | FD27D9F6D02763BDE32511B5DF7FF7A0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 17 |
Start time: | 15:00:21 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x830000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 19 |
Start time: | 15:01:01 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xd10000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 20 |
Start time: | 15:02:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xa70000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 21 |
Start time: | 15:03:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x5f0000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 22 |
Start time: | 15:04:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Teams.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x50000 |
File size: | 68'096 bytes |
MD5 hash: | E82A4E80B783AB902E649D21DCD0F3D5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Function 00007FF848F210ED Relevance: .4, Instructions: 431COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F209F7 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20D80 Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20498 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20E71 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F204A8 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F204B0 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20F3F Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F46D10 Relevance: .4, Instructions: 364COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F46DB8 Relevance: .4, Instructions: 357COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4C4F3 Relevance: .3, Instructions: 341COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4C4CD Relevance: .3, Instructions: 325COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F527FA Relevance: .3, Instructions: 313COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4B4C4 Relevance: .3, Instructions: 308COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5B784 Relevance: .3, Instructions: 303COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4C5F3 Relevance: .3, Instructions: 293COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5BAC5 Relevance: .3, Instructions: 283COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F41289 Relevance: .3, Instructions: 282COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F49430 Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5B28C Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F48F25 Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F447C8 Relevance: .2, Instructions: 221COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F49440 Relevance: .2, Instructions: 213COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F528E8 Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F51D91 Relevance: .2, Instructions: 196COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F46738 Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5AFFA Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F40862 Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4F021 Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F490CA Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F46DFB Relevance: .2, Instructions: 154COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F54CDA Relevance: .1, Instructions: 149COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4DC60 Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4D228 Relevance: .1, Instructions: 144COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F55B40 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F48270 Relevance: .1, Instructions: 139COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F57728 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5F271 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F544A1 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F45955 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F414E1 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F54C50 Relevance: .1, Instructions: 125COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5FBEB Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F448ED Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F43F1B Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5F3B5 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F43F69 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F497E0 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F449F2 Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5CA31 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F47DFB Relevance: .1, Instructions: 105COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4C7D3 Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F56377 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F564B2 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F59B6B Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4BE1D Relevance: .1, Instructions: 88COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4DEE1 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5F4A3 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5EF99 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4DF00 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4BF7D Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5EFD1 Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F40480 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F46FC9 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F44ED0 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F44D51 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F502D1 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4EC79 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F49D2B Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4D79D Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F45D33 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5ABB1 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F45A80 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F44B4D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F44CF5 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F47D50 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F45BE9 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F458F2 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F56413 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5BE9B Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4DF92 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F48AE8 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4B902 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F451FE Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F404C0 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F492C5 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F458FA Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F41614 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F404C8 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F55381 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5FD40 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F445A0 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F44260 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5F189 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F48150 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F45950 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F459D0 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F4EE20 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5BCD8 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F459E0 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F404D8 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F5B81B Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F43B59 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 22% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31689 Relevance: .7, Instructions: 653COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31125 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31150 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31120 Relevance: .2, Instructions: 234COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F32171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F01689 Relevance: .7, Instructions: 656COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F01FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F01125 Relevance: .6, Instructions: 589COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F01150 Relevance: .6, Instructions: 565COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F01120 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F00BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F00528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F00A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F00949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F02171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F11689 Relevance: .7, Instructions: 656COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F11FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F11125 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F11150 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F11120 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F10BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F10528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F10A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F10949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F12171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31689 Relevance: .7, Instructions: 653COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31125 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31150 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31120 Relevance: .2, Instructions: 234COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F32171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21689 Relevance: .7, Instructions: 656COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21125 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21150 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21120 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F22171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21689 Relevance: .7, Instructions: 656COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21125 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21150 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F21120 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F20949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F22171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31689 Relevance: .7, Instructions: 653COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31FC1 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31125 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31150 Relevance: .6, Instructions: 611COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F31120 Relevance: .2, Instructions: 234COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30BFE Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30528 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30A91 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F30949 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF848F32171 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|