Windows
Analysis Report
EYve4TeHvZ.exe
Overview
General Information
Sample name: | EYve4TeHvZ.exerenamed because original name is a hash value |
Original sample name: | d89407ff1c7e68212ea29e5d7da5fba9.exe |
Analysis ID: | 1636804 |
MD5: | d89407ff1c7e68212ea29e5d7da5fba9 |
SHA1: | 8def9ed32436c34b27fcee48b9b10e4f4b519f74 |
SHA256: | af621a0196ca315b44e889e295e0b227a1ed3afc3e2f1b266875436874138fa3 |
Tags: | exeRedLineStealeruser-abuse_ch |
Infos: | |
Detection
RedLine
Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected RedLine Stealer
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Binary is likely a compiled AutoIt script file
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to launch a program with higher privileges
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality to simulate keystroke presses
Contains functionality to simulate mouse events
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found evasive API chain (date check)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Internet Provider seen in connection with other malware
OS version to string mapping found (often used in BOTs)
Potential key logger detected (key state polling based)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match
Classification
- System is w10x64
EYve4TeHvZ.exe (PID: 7736 cmdline:
"C:\Users\ user\Deskt op\EYve4Te HvZ.exe" MD5: D89407FF1C7E68212EA29E5D7DA5FBA9) RegSvcs.exe (PID: 7752 cmdline:
"C:\Users\ user\Deskt op\EYve4Te HvZ.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) EYve4TeHvZ.exe (PID: 7760 cmdline:
"C:\Users\ user\Deskt op\EYve4Te HvZ.exe" MD5: D89407FF1C7E68212EA29E5D7DA5FBA9) RegSvcs.exe (PID: 7808 cmdline:
"C:\Users\ user\Deskt op\EYve4Te HvZ.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) EYve4TeHvZ.exe (PID: 7816 cmdline:
"C:\Users\ user\Deskt op\EYve4Te HvZ.exe" MD5: D89407FF1C7E68212EA29E5D7DA5FBA9) RegSvcs.exe (PID: 7832 cmdline:
"C:\Users\ user\Deskt op\EYve4Te HvZ.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
{"C2 url": ["45.144.212.192:1912"], "Bot Id": "GRACELOVELOG", "Authorization Header": "c74790bd166600f1f665c8ce201776eb"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_RedLine_1 | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
| |
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
| |
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Click to see the 8 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
| |
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
| |
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
infostealer_win_redline_strings | Finds Redline samples based on characteristic strings | Sekoia.io |
| |
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
Click to see the 20 entries |
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-13T06:17:18.061900+0100 | 2043234 | 1 | A Network Trojan was detected | 45.144.212.192 | 1912 | 192.168.2.4 | 49712 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-13T06:17:17.879285+0100 | 2043231 | 1 | A Network Trojan was detected | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:23.350751+0100 | 2043231 | 1 | A Network Trojan was detected | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:25.545844+0100 | 2043231 | 1 | A Network Trojan was detected | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:25.782649+0100 | 2043231 | 1 | A Network Trojan was detected | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-13T06:17:23.543075+0100 | 2046056 | 1 | A Network Trojan was detected | 45.144.212.192 | 1912 | 192.168.2.4 | 49712 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-13T06:17:17.879285+0100 | 2046045 | 1 | A Network Trojan was detected | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00B7445A | |
Source: | Code function: | 0_2_00B7C6D1 | |
Source: | Code function: | 0_2_00B7C75C | |
Source: | Code function: | 0_2_00B7EF95 | |
Source: | Code function: | 0_2_00B7F0F2 | |
Source: | Code function: | 0_2_00B7F3F3 | |
Source: | Code function: | 0_2_00B737EF | |
Source: | Code function: | 0_2_00B73B12 | |
Source: | Code function: | 0_2_00B7BCBC |
Source: | Code function: | 5_2_068D267C | |
Source: | Code function: | 5_2_068D1F68 | |
Source: | Code function: | 5_2_068ECDC8 | |
Source: | Code function: | 5_2_076FB529 | |
Source: | Code function: | 5_2_076FB530 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_00B822EE |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_00B84164 |
Source: | Code function: | 0_2_00B84164 |
Source: | Code function: | 0_2_00B83F66 |
Source: | Code function: | 0_2_00B7001C |
Source: | Code function: | 0_2_00B9CABC |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00B13B3A | |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_42192206-a | |
Source: | String found in binary or memory: | memstr_c7e9a417-f | |
Source: | String found in binary or memory: | memstr_22d844c8-4 | |
Source: | String found in binary or memory: | memstr_b6979cc1-6 | |
Source: | String found in binary or memory: | memstr_bd0cf1f2-7 | |
Source: | String found in binary or memory: | memstr_31165787-3 | |
Source: | String found in binary or memory: | memstr_c42b5786-0 | |
Source: | String found in binary or memory: | memstr_e1c0392a-a |
Source: | Code function: | 0_2_00B7A1EF |
Source: | Code function: | 0_2_00B68310 |
Source: | Code function: | 0_2_00B751BD |
Source: | Code function: | 0_2_00B3D975 | |
Source: | Code function: | 0_2_00B321C5 | |
Source: | Code function: | 0_2_00B462D2 | |
Source: | Code function: | 0_2_00B903DA | |
Source: | Code function: | 0_2_00B4242E | |
Source: | Code function: | 0_2_00B325FA | |
Source: | Code function: | 0_2_00B1E6A0 | |
Source: | Code function: | 0_2_00B266E1 | |
Source: | Code function: | 0_2_00B6E616 | |
Source: | Code function: | 0_2_00B4878F | |
Source: | Code function: | 0_2_00B78889 | |
Source: | Code function: | 0_2_00B28808 | |
Source: | Code function: | 0_2_00B90857 | |
Source: | Code function: | 0_2_00B46844 | |
Source: | Code function: | 0_2_00B3CB21 | |
Source: | Code function: | 0_2_00B46DB6 | |
Source: | Code function: | 0_2_00B26F9E | |
Source: | Code function: | 0_2_00B23030 | |
Source: | Code function: | 0_2_00B33187 | |
Source: | Code function: | 0_2_00B3F1D9 | |
Source: | Code function: | 0_2_00B11287 | |
Source: | Code function: | 0_2_00B31484 | |
Source: | Code function: | 0_2_00B25520 | |
Source: | Code function: | 0_2_00B37696 | |
Source: | Code function: | 0_2_00B25760 | |
Source: | Code function: | 0_2_00B31978 | |
Source: | Code function: | 0_2_00B1FCE0 | |
Source: | Code function: | 0_2_00B3BDA6 | |
Source: | Code function: | 0_2_00B31D90 | |
Source: | Code function: | 0_2_00B97DDB | |
Source: | Code function: | 0_2_00B23FE0 | |
Source: | Code function: | 0_2_00B1DF00 | |
Source: | Code function: | 0_2_014435B0 | |
Source: | Code function: | 2_2_010F2628 | |
Source: | Code function: | 4_2_0153FC6D | |
Source: | Code function: | 4_2_01543608 | |
Source: | Code function: | 5_2_00408C60 | |
Source: | Code function: | 5_2_0040DC11 | |
Source: | Code function: | 5_2_00407C3F | |
Source: | Code function: | 5_2_00418CCC | |
Source: | Code function: | 5_2_00406CA0 | |
Source: | Code function: | 5_2_004028B0 | |
Source: | Code function: | 5_2_0041A4BE | |
Source: | Code function: | 5_2_00418244 | |
Source: | Code function: | 5_2_00401650 | |
Source: | Code function: | 5_2_00402F20 | |
Source: | Code function: | 5_2_004193C4 | |
Source: | Code function: | 5_2_00418788 | |
Source: | Code function: | 5_2_00402F89 | |
Source: | Code function: | 5_2_00402B90 | |
Source: | Code function: | 5_2_004073A0 | |
Source: | Code function: | 5_2_02FB7740 | |
Source: | Code function: | 5_2_02FB7733 | |
Source: | Code function: | 5_2_06889C48 | |
Source: | Code function: | 5_2_0688BD90 | |
Source: | Code function: | 5_2_06887BE0 | |
Source: | Code function: | 5_2_0688B810 | |
Source: | Code function: | 5_2_0688C0C0 | |
Source: | Code function: | 5_2_06886EA8 | |
Source: | Code function: | 5_2_068D5608 | |
Source: | Code function: | 5_2_068DF460 | |
Source: | Code function: | 5_2_068D0848 | |
Source: | Code function: | 5_2_068DD9E8 | |
Source: | Code function: | 5_2_068E0033 | |
Source: | Code function: | 5_2_068E0040 | |
Source: | Code function: | 5_2_068E5565 | |
Source: | Code function: | 5_2_076F8F20 | |
Source: | Code function: | 5_2_076FDFA8 | |
Source: | Code function: | 5_2_076FE428 | |
Source: | Code function: | 5_2_076FF308 | |
Source: | Code function: | 5_2_076FC3E8 | |
Source: | Code function: | 5_2_076FEBC0 | |
Source: | Code function: | 5_2_076F12E8 | |
Source: | Code function: | 5_2_076FAA90 | |
Source: | Code function: | 5_2_076FD179 | |
Source: | Code function: | 5_2_076FD953 | |
Source: | Code function: | 5_2_076F58D8 | |
Source: | Code function: | 5_2_076F942B | |
Source: | Code function: | 5_2_076FC3D8 | |
Source: | Code function: | 5_2_076FEBB1 | |
Source: | Code function: | 5_2_076FAA80 | |
Source: | Code function: | 5_2_076F5100 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Code function: | 0_2_00B7A06A |
Source: | Code function: | 0_2_00B681CB | |
Source: | Code function: | 0_2_00B687E1 |
Source: | Code function: | 0_2_00B7B3FB |
Source: | Code function: | 0_2_00B8EE0D |
Source: | Code function: | 0_2_00B883BB |
Source: | Code function: | 0_2_00B14E89 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: |
Source: | Code function: | 0_2_00B14B37 |
Source: | Code function: | 0_2_00B38958 | |
Source: | Code function: | 5_2_0041C4E2 | |
Source: | Code function: | 5_2_00423179 | |
Source: | Code function: | 5_2_0041C4E2 | |
Source: | Code function: | 5_2_00423179 | |
Source: | Code function: | 5_2_0040E230 | |
Source: | Code function: | 5_2_0041C6BF | |
Source: | Code function: | 5_2_068846EC | |
Source: | Code function: | 5_2_0688466C | |
Source: | Code function: | 5_2_068893C9 | |
Source: | Code function: | 5_2_068862E0 | |
Source: | Code function: | 5_2_0688CD10 | |
Source: | Code function: | 5_2_068D96D0 | |
Source: | Code function: | 5_2_068D2440 | |
Source: | Code function: | 5_2_068D4220 | |
Source: | Code function: | 5_2_068D9820 | |
Source: | Code function: | 5_2_068D9840 | |
Source: | Code function: | 5_2_068D9840 | |
Source: | Code function: | 5_2_076FB297 |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | Code function: | 0_2_00B148D7 | |
Source: | Code function: | 0_2_00B95376 |
Source: | Code function: | 0_2_00B33187 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Code function: | 5_2_004019F0 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_0-105786 |
Source: | API coverage: |
Source: | WMI Queries: |
Source: | Code function: | 0_2_00B7445A | |
Source: | Code function: | 0_2_00B7C6D1 | |
Source: | Code function: | 0_2_00B7C75C | |
Source: | Code function: | 0_2_00B7EF95 | |
Source: | Code function: | 0_2_00B7F0F2 | |
Source: | Code function: | 0_2_00B7F3F3 | |
Source: | Code function: | 0_2_00B737EF | |
Source: | Code function: | 0_2_00B73B12 | |
Source: | Code function: | 0_2_00B7BCBC |
Source: | Code function: | 0_2_00B149A0 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | API call chain: |
Source: | Code function: | 5_2_02FB0890 |
Source: | Code function: | 0_2_00B83F09 |
Source: | Code function: | 0_2_00B13B3A |
Source: | Code function: | 0_2_00B45A7C |
Source: | Code function: | 5_2_004019F0 |
Source: | Code function: | 0_2_00B14B37 |
Source: | Code function: | 0_2_01443440 | |
Source: | Code function: | 0_2_014434A0 | |
Source: | Code function: | 0_2_01441E00 | |
Source: | Code function: | 2_2_010F2518 | |
Source: | Code function: | 2_2_010F24B8 | |
Source: | Code function: | 2_2_010F0E78 | |
Source: | Code function: | 4_2_01541E58 | |
Source: | Code function: | 4_2_015434F8 | |
Source: | Code function: | 4_2_01543498 |
Source: | Code function: | 0_2_00B680A9 |
Source: | Code function: | 0_2_00B3A124 | |
Source: | Code function: | 0_2_00B3A155 | |
Source: | Code function: | 5_2_0040CE09 | |
Source: | Code function: | 5_2_0040E61C | |
Source: | Code function: | 5_2_00416F6A | |
Source: | Code function: | 5_2_004123F1 |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Section loaded: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 0_2_00B687B1 |
Source: | Code function: | 0_2_00B13B3A |
Source: | Code function: | 0_2_00B148D7 |
Source: | Code function: | 0_2_00B74C27 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_00B67CAF |
Source: | Code function: | 0_2_00B6874B |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00B3862B |
Source: | Code function: | 5_2_00417A20 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00B44E87 |
Source: | Code function: | 0_2_00B51E06 |
Source: | Code function: | 0_2_00B43F3A |
Source: | Code function: | 0_2_00B149A0 |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00B86283 | |
Source: | Code function: | 0_2_00B86747 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 2 Valid Accounts | 221 Windows Management Instrumentation | 1 DLL Side-Loading | 1 Exploitation for Privilege Escalation | 11 Disable or Modify Tools | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 2 Native API | 2 Valid Accounts | 1 DLL Side-Loading | 11 Deobfuscate/Decode Files or Information | 21 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 3 Data from Local System | 1 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 2 Valid Accounts | 3 Obfuscated Files or Information | Security Account Manager | 1 File and Directory Discovery | SMB/Windows Admin Shares | 21 Input Capture | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 21 Access Token Manipulation | 2 Software Packing | NTDS | 237 System Information Discovery | Distributed Component Object Model | 3 Clipboard Data | 1 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 212 Process Injection | 1 DLL Side-Loading | LSA Secrets | 371 Security Software Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 221 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Valid Accounts | DCSync | 2 Process Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 221 Virtualization/Sandbox Evasion | Proc Filesystem | 11 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 21 Access Token Manipulation | /etc/passwd and /etc/shadow | 1 System Owner/User Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 212 Process Injection | Network Sniffing | Network Service Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
54% | Virustotal | Browse | ||
71% | ReversingLabs | Win32.Trojan.AutoitInject | ||
100% | Avira | TR/AD.RedLineSteal.xsmpg |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No contacted domains info
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
45.144.212.192 | unknown | Ukraine | 47169 | HPC-MVM-ASHU | true |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1636804 |
Start date and time: | 2025-03-13 06:16:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 52s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | EYve4TeHvZ.exerenamed because original name is a hash value |
Original Sample Name: | d89407ff1c7e68212ea29e5d7da5fba9.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@11/5@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.60.203.209, 52.149.20.212
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
01:17:23 | API Interceptor |
⊘No context
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
HPC-MVM-ASHU | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Fallen Miner, Xmrig | Browse |
| ||
Get hash | malicious | Fallen Miner, Xmrig | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
|
⊘No context
⊘No context
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3094 |
Entropy (8bit): | 5.33145931749415 |
Encrypted: | false |
SSDEEP: | 96:Pq5qHwCYqh3oPtI6eqzxP0aymTqdqlq7qqjqcEZ5D:Pq5qHwCYqh3qtI6eqzxP0atTqdqlq7qV |
MD5: | 3FD5C0634443FB2EF2796B9636159CB6 |
SHA1: | 366DDE94AEFCFFFAB8E03AD8B448E05D7489EB48 |
SHA-256: | 58307E94C67E2348F5A838DE4FF668983B38B7E9A3B1D61535D3A392814A57D6 |
SHA-512: | 8535E7C0777C6B0876936D84BDE2BDC59963CF0954D4E50D65808E6E806E8B131DF5DB8FA0E030FAE2702143A7C3A70698A2B9A80519C9E2FFC286A71F0B797C |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 343860 |
Entropy (8bit): | 7.9741965699148 |
Encrypted: | false |
SSDEEP: | 6144:i6GMXMIuzcCQ1gvEjUrvsUxUgPY8tFpmyxRkaO0pjSGcoTDztdRkUXZ578zY5oF0:pGMbuzcC5qwEUxUf8zpPS90pjqoTXr9Z |
MD5: | DBA9D554429778EAB4B3D6987DF301A5 |
SHA1: | 0D31965E7FAABD1A4FD07999AC99957A4D8D80BC |
SHA-256: | 1E68D3D7C0B8A766A11A8CE596345716A90BE688C1149C9AB9C633EB7870D939 |
SHA-512: | E7D4AE0F63B897CD8F8E46299854712937839C47BDA69E77EF86F1938DEF95E9A8C4782E3969BB029736DC37B95E2F4A65C97601450797E38E63E420B85BEE64 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 343860 |
Entropy (8bit): | 7.9741965699148 |
Encrypted: | false |
SSDEEP: | 6144:i6GMXMIuzcCQ1gvEjUrvsUxUgPY8tFpmyxRkaO0pjSGcoTDztdRkUXZ578zY5oF0:pGMbuzcC5qwEUxUf8zpPS90pjqoTXr9Z |
MD5: | DBA9D554429778EAB4B3D6987DF301A5 |
SHA1: | 0D31965E7FAABD1A4FD07999AC99957A4D8D80BC |
SHA-256: | 1E68D3D7C0B8A766A11A8CE596345716A90BE688C1149C9AB9C633EB7870D939 |
SHA-512: | E7D4AE0F63B897CD8F8E46299854712937839C47BDA69E77EF86F1938DEF95E9A8C4782E3969BB029736DC37B95E2F4A65C97601450797E38E63E420B85BEE64 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 343860 |
Entropy (8bit): | 7.9741965699148 |
Encrypted: | false |
SSDEEP: | 6144:i6GMXMIuzcCQ1gvEjUrvsUxUgPY8tFpmyxRkaO0pjSGcoTDztdRkUXZ578zY5oF0:pGMbuzcC5qwEUxUf8zpPS90pjqoTXr9Z |
MD5: | DBA9D554429778EAB4B3D6987DF301A5 |
SHA1: | 0D31965E7FAABD1A4FD07999AC99957A4D8D80BC |
SHA-256: | 1E68D3D7C0B8A766A11A8CE596345716A90BE688C1149C9AB9C633EB7870D939 |
SHA-512: | E7D4AE0F63B897CD8F8E46299854712937839C47BDA69E77EF86F1938DEF95E9A8C4782E3969BB029736DC37B95E2F4A65C97601450797E38E63E420B85BEE64 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 422912 |
Entropy (8bit): | 7.439584686925007 |
Encrypted: | false |
SSDEEP: | 12288:8dwTnkh9Np4aZzdqSGRzedbFmyXU8SZ2fCcT9oW9:8Zp4aXoRzedbFmyXUxZ2IW9 |
MD5: | 75B8CBE941586F299068B1731C7965B1 |
SHA1: | D38EBB6A058C88CDEF6D9D87EDB16CF5A2DD6A01 |
SHA-256: | 70D29D248FD0FC70C43940E4D9BB78A02D35E841FEE8EDE4F6352B296CC3D828 |
SHA-512: | 4A77822EC5A44E54FDB41C9A1131FC7151DFB7E4A5F043C5F598F408BD2A48E9B8CD2E3AA01698CBBAEE8A2E8BC7EC8E25C2EE825B8DB663DCD6F6E5FF2C5AC5 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.229023307471796 |
TrID: |
|
File name: | EYve4TeHvZ.exe |
File size: | 1'247'232 bytes |
MD5: | d89407ff1c7e68212ea29e5d7da5fba9 |
SHA1: | 8def9ed32436c34b27fcee48b9b10e4f4b519f74 |
SHA256: | af621a0196ca315b44e889e295e0b227a1ed3afc3e2f1b266875436874138fa3 |
SHA512: | 8f7fe44749ce7259dc8279a0a764a9fafd4ce9beae16cc50aeaabab756243a8c1ac881e5a3a37912821c5a2cfbd15e69431aae11770d1c42309517dd212f70fb |
SSDEEP: | 24576:vu6J33O0c+JY5UZ+XC0kGso6Fa/IkNPfDkQJMJP2WY:Zu0c++OCvkGs9Fa/ZwbfY |
TLSH: | DD45CF22B3DDC360CB669173BF69B7056EBF7C214630B85B2F880D7DA950162262D763 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6...r}..r}..r}..4,".p}......s}.../..A}.../#..}.../".G}..{.@.{}..{.P.W}..r}..R.....)."}......s}.../..s}..r}T.s}......s}..Richr}. |
Icon Hash: | aaf3e3e3938382a0 |
Entrypoint: | 0x427dcd |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67CE2D0E [Mon Mar 10 00:06:38 2025 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | afcdf79be1557326c854b6e20cb900a7 |
Instruction |
---|
call 00007FA0E87D363Ah |
jmp 00007FA0E87C6404h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
push edi |
push esi |
mov esi, dword ptr [esp+10h] |
mov ecx, dword ptr [esp+14h] |
mov edi, dword ptr [esp+0Ch] |
mov eax, ecx |
mov edx, ecx |
add eax, esi |
cmp edi, esi |
jbe 00007FA0E87C658Ah |
cmp edi, eax |
jc 00007FA0E87C68EEh |
bt dword ptr [004C31FCh], 01h |
jnc 00007FA0E87C6589h |
rep movsb |
jmp 00007FA0E87C689Ch |
cmp ecx, 00000080h |
jc 00007FA0E87C6754h |
mov eax, edi |
xor eax, esi |
test eax, 0000000Fh |
jne 00007FA0E87C6590h |
bt dword ptr [004BE324h], 01h |
jc 00007FA0E87C6A60h |
bt dword ptr [004C31FCh], 00000000h |
jnc 00007FA0E87C672Dh |
test edi, 00000003h |
jne 00007FA0E87C673Eh |
test esi, 00000003h |
jne 00007FA0E87C671Dh |
bt edi, 02h |
jnc 00007FA0E87C658Fh |
mov eax, dword ptr [esi] |
sub ecx, 04h |
lea esi, dword ptr [esi+04h] |
mov dword ptr [edi], eax |
lea edi, dword ptr [edi+04h] |
bt edi, 03h |
jnc 00007FA0E87C6593h |
movq xmm1, qword ptr [esi] |
sub ecx, 08h |
lea esi, dword ptr [esi+08h] |
movq qword ptr [edi], xmm1 |
lea edi, dword ptr [edi+08h] |
test esi, 00000007h |
je 00007FA0E87C65E5h |
bt esi, 03h |
jnc 00007FA0E87C6638h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xba44c | 0x17c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc7000 | 0x67f88 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x12f000 | 0x711c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x92bc0 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0xa4870 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8f000 | 0x884 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x8dcc4 | 0x8de00 | d28a820a1d9ff26cda02d12b888ba4b4 | False | 0.5728679102422908 | data | 6.676118058520316 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8f000 | 0x2e10e | 0x2e200 | 79b14b254506b0dbc8cd0ad67fb70ad9 | False | 0.33535526761517614 | OpenPGP Public Key | 5.76010872795207 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xbe000 | 0x8f74 | 0x5200 | 9f9d6f746f1a415a63de45f8b7983d33 | False | 0.1017530487804878 | data | 1.198745897703538 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xc7000 | 0x67f88 | 0x68000 | 993e811e2e88e94b511ffb1c8906dc4e | False | 0.9370164137620193 | data | 7.913874925931253 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x12f000 | 0x711c | 0x7200 | 6fcae3cbbf6bfbabf5ec5bbe7cf612c3 | False | 0.7650767543859649 | data | 6.779031650454199 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xc75a8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.7466216216216216 |
RT_ICON | 0xc76d0 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | Great Britain | 0.3277027027027027 |
RT_ICON | 0xc77f8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.3885135135135135 |
RT_ICON | 0xc7920 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | Great Britain | 0.3333333333333333 |
RT_ICON | 0xc7c08 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | Great Britain | 0.5 |
RT_ICON | 0xc7d30 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | Great Britain | 0.2835820895522388 |
RT_ICON | 0xc8bd8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | Great Britain | 0.37906137184115524 |
RT_ICON | 0xc9480 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | Great Britain | 0.23699421965317918 |
RT_ICON | 0xc99e8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | Great Britain | 0.13858921161825727 |
RT_ICON | 0xcbf90 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | Great Britain | 0.25070356472795496 |
RT_ICON | 0xcd038 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | Great Britain | 0.3173758865248227 |
RT_MENU | 0xcd4a0 | 0x50 | data | English | Great Britain | 0.9 |
RT_STRING | 0xcd4f0 | 0x594 | data | English | Great Britain | 0.3333333333333333 |
RT_STRING | 0xcda84 | 0x68a | data | English | Great Britain | 0.2747909199522103 |
RT_STRING | 0xce110 | 0x490 | data | English | Great Britain | 0.3715753424657534 |
RT_STRING | 0xce5a0 | 0x5fc | data | English | Great Britain | 0.3087467362924282 |
RT_STRING | 0xceb9c | 0x65c | data | English | Great Britain | 0.34336609336609336 |
RT_STRING | 0xcf1f8 | 0x466 | data | English | Great Britain | 0.3605683836589698 |
RT_STRING | 0xcf660 | 0x158 | Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0 | English | Great Britain | 0.502906976744186 |
RT_RCDATA | 0xcf7b8 | 0x5f24f | data | 1.0003233165089003 | ||
RT_GROUP_ICON | 0x12ea08 | 0x76 | data | English | Great Britain | 0.6610169491525424 |
RT_GROUP_ICON | 0x12ea80 | 0x14 | data | English | Great Britain | 1.25 |
RT_GROUP_ICON | 0x12ea94 | 0x14 | data | English | Great Britain | 1.15 |
RT_GROUP_ICON | 0x12eaa8 | 0x14 | data | English | Great Britain | 1.25 |
RT_VERSION | 0x12eabc | 0xdc | data | English | Great Britain | 0.6181818181818182 |
RT_MANIFEST | 0x12eb98 | 0x3ef | ASCII text, with CRLF line terminators | English | Great Britain | 0.5074478649453823 |
DLL | Import |
---|---|
WSOCK32.dll | WSACleanup, socket, inet_ntoa, setsockopt, ntohs, recvfrom, ioctlsocket, htons, WSAStartup, __WSAFDIsSet, select, accept, listen, bind, closesocket, WSAGetLastError, recv, sendto, send, inet_addr, gethostbyname, gethostname, connect |
VERSION.dll | GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW |
WINMM.dll | timeGetTime, waveOutSetVolume, mciSendStringW |
COMCTL32.dll | ImageList_ReplaceIcon, ImageList_Destroy, ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, InitCommonControlsEx, ImageList_Create |
MPR.dll | WNetUseConnectionW, WNetCancelConnection2W, WNetGetConnectionW, WNetAddConnection2W |
WININET.dll | InternetQueryDataAvailable, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetQueryOptionW, HttpOpenRequestW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetReadFile, InternetConnectW |
PSAPI.DLL | GetProcessMemoryInfo |
IPHLPAPI.DLL | IcmpCreateFile, IcmpCloseHandle, IcmpSendEcho |
USERENV.dll | DestroyEnvironmentBlock, UnloadUserProfile, CreateEnvironmentBlock, LoadUserProfileW |
UxTheme.dll | IsThemeActive |
KERNEL32.dll | DuplicateHandle, CreateThread, WaitForSingleObject, HeapAlloc, GetProcessHeap, HeapFree, Sleep, GetCurrentThreadId, MultiByteToWideChar, MulDiv, GetVersionExW, IsWow64Process, GetSystemInfo, FreeLibrary, LoadLibraryA, GetProcAddress, SetErrorMode, GetModuleFileNameW, WideCharToMultiByte, lstrcpyW, lstrlenW, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, SetEndOfFile, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, SetCurrentDirectoryW, GetLongPathNameW, GetShortPathNameW, DeleteFileW, FindNextFileW, CopyFileExW, MoveFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, FindResourceW, LoadResource, LockResource, SizeofResource, EnumResourceNamesW, OutputDebugStringW, GetTempPathW, GetTempFileNameW, DeviceIoControl, GetLocalTime, CompareStringW, GetCurrentProcess, EnterCriticalSection, LeaveCriticalSection, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, LoadLibraryExW, FindResourceExW, CopyFileW, VirtualFree, FormatMessageW, GetExitCodeProcess, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, SetFileAttributesW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetSystemDirectoryW, HeapReAlloc, HeapSize, GetComputerNameW, GetWindowsDirectoryW, GetCurrentProcessId, GetProcessIoCounters, CreateProcessW, GetProcessId, SetPriorityClass, LoadLibraryW, VirtualAlloc, IsDebuggerPresent, GetCurrentDirectoryW, lstrcmpiW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, GetCurrentThread, CloseHandle, GetFullPathNameW, EncodePointer, ExitProcess, GetModuleHandleExW, ExitThread, GetSystemTimeAsFileTime, ResumeThread, GetCommandLineW, IsProcessorFeaturePresent, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, SetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetStartupInfoW, GetStringTypeW, SetStdHandle, GetFileType, GetConsoleCP, GetConsoleMode, RtlUnwind, ReadConsoleW, GetTimeZoneInformation, GetDateFormatW, GetTimeFormatW, LCMapStringW, GetEnvironmentStringsW, FreeEnvironmentStringsW, WriteConsoleW, FindClose, SetEnvironmentVariableA |
USER32.dll | AdjustWindowRectEx, CopyImage, SetWindowPos, GetCursorInfo, RegisterHotKey, ClientToScreen, GetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, MonitorFromPoint, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, CallWindowProcW, ReleaseCapture, SetCapture, CreateIconFromResourceEx, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, TrackPopupMenuEx, GetCursorPos, DeleteMenu, SetRect, GetMenuItemID, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, MonitorFromRect, keybd_event, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowLongW, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, ScreenToClient, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, GetUserObjectSecurity, MessageBoxW, DefWindowProcW, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, GetMessageW, LockWindowUpdate, DispatchMessageW, TranslateMessage, PeekMessageW, UnregisterHotKey, CheckMenuRadioItem, CharLowerBuffW, MoveWindow, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, SystemParametersInfoW, LoadImageW, GetClassNameW |
GDI32.dll | StrokePath, DeleteObject, GetTextExtentPoint32W, ExtCreatePen, GetDeviceCaps, EndPath, SetPixel, CloseFigure, CreateCompatibleBitmap, CreateCompatibleDC, SelectObject, StretchBlt, GetDIBits, LineTo, AngleArc, MoveToEx, Ellipse, DeleteDC, GetPixel, CreateDCW, GetStockObject, GetTextFaceW, CreateFontW, SetTextColor, PolyDraw, BeginPath, Rectangle, SetViewportOrgEx, GetObjectW, SetBkMode, RoundRect, SetBkColor, CreatePen, CreateSolidBrush, StrokeAndFillPath |
COMDLG32.dll | GetOpenFileNameW, GetSaveFileNameW |
ADVAPI32.dll | GetAce, RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegConnectRegistryW, InitializeSecurityDescriptor, InitializeAcl, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, GetLengthSid, CopySid, LogonUserW, AllocateAndInitializeSid, CheckTokenMembership, RegCreateKeyExW, FreeSid, GetTokenInformation, GetSecurityDescriptorDacl, GetAclInformation, AddAce, SetSecurityDescriptorDacl, GetUserNameW, InitiateSystemShutdownExW |
SHELL32.dll | DragQueryPoint, ShellExecuteExW, DragQueryFileW, SHEmptyRecycleBinW, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateShellItem, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetFolderPathW, SHFileOperationW, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW, DragFinish |
ole32.dll | CoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, ProgIDFromCLSID, CLSIDFromProgID, OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoCreateInstance, IIDFromString, StringFromGUID2, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, CoUninitialize, GetRunningObjectTable, CoGetInstanceFromFile, CoGetObject, CoSetProxyBlanket, CoCreateInstanceEx, CoInitializeSecurity |
OLEAUT32.dll | LoadTypeLibEx, VariantCopyInd, SysReAllocString, SysFreeString, SafeArrayDestroyDescriptor, SafeArrayDestroyData, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayAllocData, SafeArrayAllocDescriptorEx, SafeArrayCreateVector, RegisterTypeLib, CreateStdDispatch, DispCallFunc, VariantChangeType, SysStringLen, VariantTimeToSystemTime, VarR8FromDec, SafeArrayGetVartype, VariantCopy, VariantClear, OleLoadPicture, QueryPathOfRegTypeLib, RegisterTypeLibForUser, UnRegisterTypeLibForUser, UnRegisterTypeLib, CreateDispTypeInfo, SysAllocString, VariantInit |
Description | Data |
---|---|
Translation | 0x0809 0x04b0 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | Great Britain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-13T06:17:17.879285+0100 | 2043231 | ET MALWARE Redline Stealer TCP CnC Activity | 1 | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:17.879285+0100 | 2046045 | ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization) | 1 | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:18.061900+0100 | 2043234 | ET MALWARE Redline Stealer TCP CnC - Id1Response | 1 | 45.144.212.192 | 1912 | 192.168.2.4 | 49712 | TCP |
2025-03-13T06:17:23.350751+0100 | 2043231 | ET MALWARE Redline Stealer TCP CnC Activity | 1 | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:23.543075+0100 | 2046056 | ET MALWARE Redline Stealer/MetaStealer Family Activity (Response) | 1 | 45.144.212.192 | 1912 | 192.168.2.4 | 49712 | TCP |
2025-03-13T06:17:25.545844+0100 | 2043231 | ET MALWARE Redline Stealer TCP CnC Activity | 1 | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
2025-03-13T06:17:25.782649+0100 | 2043231 | ET MALWARE Redline Stealer TCP CnC Activity | 1 | 192.168.2.4 | 49712 | 45.144.212.192 | 1912 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 13, 2025 06:17:17.184657097 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:17.189533949 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:17.189606905 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:17.200844049 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:17.205553055 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:17.811148882 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:17.877578974 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:17.879285097 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:17.883920908 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:18.061899900 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:18.112071991 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:23.350750923 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:23.355398893 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:23.542956114 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:23.542968988 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:23.542979002 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:23.543039083 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:23.543075085 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:23.543087006 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:23.543114901 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:23.596415997 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.539463043 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.544234991 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544246912 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544276953 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544286966 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544320107 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544329882 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544336081 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.544341087 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544349909 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544362068 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.544367075 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544419050 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.544482946 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.544552088 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.549133062 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549149036 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549190044 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.549221039 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.549257994 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549266100 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549274921 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549284935 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549293995 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549312115 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549320936 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549326897 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.549340963 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549370050 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549412012 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.549422979 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.549427986 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.549474955 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.553935051 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554064035 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554073095 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554084063 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554115057 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554126024 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554172039 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554192066 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554290056 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554299116 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554356098 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554363966 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554462910 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554476023 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554502964 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554519892 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554544926 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554548025 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554578066 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554595947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554604053 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554634094 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554694891 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554703951 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554713011 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554716110 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554721117 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554738998 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554749966 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554770947 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554799080 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554800034 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554809093 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554817915 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554826021 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554848909 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554852009 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554860115 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554863930 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554867983 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.554903030 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.554929018 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.558789968 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558799028 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558832884 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558841944 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558851957 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558861017 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558875084 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.558887959 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.558895111 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558903933 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558919907 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558927059 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.558928967 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558950901 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558959007 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.558959007 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.558988094 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.559005976 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559012890 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.559015036 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559019089 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559026957 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559047937 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559056997 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559087038 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559093952 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559134007 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559143066 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559149981 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559159040 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559174061 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559181929 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559196949 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559205055 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559221029 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559274912 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559283018 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559287071 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559308052 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559315920 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559330940 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559339046 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559421062 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559429884 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559432983 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559464931 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559473038 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559484959 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559494019 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559509039 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559519053 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559556961 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559643030 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559652090 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.559653044 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559719086 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.559751987 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559761047 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559768915 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559777975 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559787035 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559794903 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559899092 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559909105 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559916019 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559926033 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559932947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559942007 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559951067 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559961081 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559968948 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559992075 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.559998989 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.560003996 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.560012102 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.560020924 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.560029030 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563592911 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563620090 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563631058 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563667059 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563714027 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563723087 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563766003 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563787937 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563798904 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563848972 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563858986 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563868046 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563904047 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563919067 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563958883 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563963890 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563971043 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.563987970 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564007044 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564016104 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564090014 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564099073 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564107895 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564116955 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564313889 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.564369917 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.564378977 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564467907 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564476013 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564533949 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564543009 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564546108 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564553976 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564564943 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564574003 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564609051 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564618111 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564640999 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564649105 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564718962 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564727068 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564740896 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564755917 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564764977 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564774036 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564825058 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564834118 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564841032 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564851046 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564863920 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564872026 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564888000 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564897060 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564949036 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564958096 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564965963 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564975023 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564990997 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.564999104 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565013885 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565022945 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565058947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565068007 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565095901 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565104008 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565124989 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565134048 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565220118 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565227032 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565244913 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565253973 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565260887 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565269947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565294981 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565304995 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565320015 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565327883 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565339088 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.565345049 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569127083 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569135904 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569139004 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569147110 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569154978 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569161892 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569200039 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569209099 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569217920 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569226027 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569278955 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569287062 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569289923 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569298983 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569350004 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.569394112 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569401979 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.569403887 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569411993 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569421053 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569428921 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569437027 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569446087 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569454908 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569475889 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569484949 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569494009 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569503069 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569524050 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569533110 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569536924 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569540024 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569621086 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569629908 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569634914 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569643974 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569659948 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569669008 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569684029 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569752932 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569761038 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569768906 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569792032 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569801092 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569946051 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569955111 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569962025 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569971085 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569978952 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569991112 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.569998980 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.570008039 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.570024014 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.570030928 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.570039988 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574474096 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574481964 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574520111 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574528933 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574532986 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574549913 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574634075 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574642897 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574697971 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574707985 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574708939 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.574716091 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574732065 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574748039 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574757099 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574769974 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.574794054 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574801922 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574809074 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574819088 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574835062 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574842930 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574851990 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574862003 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574942112 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574950933 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574959993 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574969053 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.574978113 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575025082 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575033903 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575120926 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575130939 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575138092 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575146914 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575161934 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575198889 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575208902 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575221062 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575337887 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575346947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575350046 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575354099 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575361967 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575371027 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575403929 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575412035 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575416088 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575423956 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575439930 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575448036 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575458050 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575500011 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575509071 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.575544119 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579675913 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579684973 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579693079 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579701900 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579720020 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579729080 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579737902 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579747915 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579822063 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579830885 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579838037 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579847097 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579855919 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579865932 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579902887 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579911947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579916954 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579925060 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.579930067 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.579994917 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.580018044 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580028057 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580111980 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580121994 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580125093 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580127954 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580146074 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580154896 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580178022 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580187082 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580208063 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580215931 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580241919 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580250978 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580272913 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580281973 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580365896 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580374002 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580380917 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580390930 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580501080 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580508947 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580518007 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580527067 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580534935 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580544949 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580560923 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580569983 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580585003 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580593109 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580600023 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580610037 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580626965 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580636978 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.580643892 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585125923 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585134983 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585180044 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585187912 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585197926 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585208893 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585223913 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585232973 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585268021 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585277081 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585290909 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585315943 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585324049 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585331917 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585340977 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585534096 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585541964 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.585542917 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585558891 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585570097 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585602999 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.585613012 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585622072 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585629940 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585638046 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585695028 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585752010 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585761070 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585782051 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585789919 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585901976 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585910082 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585912943 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585922003 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585930109 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.585937977 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.612071037 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.616784096 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.616995096 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.617063999 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.617063999 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.617108107 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.621721983 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.621748924 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.621822119 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.621836901 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.621942997 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.621959925 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622052908 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622061014 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622144938 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622153997 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622205973 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622255087 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622342110 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622350931 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.622376919 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:24.643301964 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:24.647981882 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:25.545008898 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:25.545844078 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Mar 13, 2025 06:17:25.550518990 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:25.754959106 CET | 1912 | 49712 | 45.144.212.192 | 192.168.2.4 |
Mar 13, 2025 06:17:25.782649040 CET | 49712 | 1912 | 192.168.2.4 | 45.144.212.192 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 01:17:08 |
Start date: | 13/03/2025 |
Path: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb10000 |
File size: | 1'247'232 bytes |
MD5 hash: | D89407FF1C7E68212EA29E5D7DA5FBA9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 01:17:09 |
Start date: | 13/03/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x380000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 01:17:09 |
Start date: | 13/03/2025 |
Path: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb10000 |
File size: | 1'247'232 bytes |
MD5 hash: | D89407FF1C7E68212EA29E5D7DA5FBA9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 01:17:11 |
Start date: | 13/03/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x50000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 01:17:11 |
Start date: | 13/03/2025 |
Path: | C:\Users\user\Desktop\EYve4TeHvZ.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb10000 |
File size: | 1'247'232 bytes |
MD5 hash: | D89407FF1C7E68212EA29E5D7DA5FBA9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 01:17:12 |
Start date: | 13/03/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe80000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |