Source: regsvr32.exe.4688.1.memstr |
Malware Configuration Extractor: Ursnif {"server": "12", "whoami": "user@494126hh", "dns": "494126", "version": "251173", "uptime": "170", "crc": "2", "id": "4355", "user": "253fc4ee08f8d2d8cdc8873a98c9d714", "soft": "3"} |
Source: 6007d134e83fctar.dll |
Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, DLL |
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll |
Jump to behavior |
Source: unknown |
HTTPS traffic detected: 151.101.1.44:443 -> 192.168.2.3:49742 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 151.101.1.44:443 -> 192.168.2.3:49743 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 151.101.1.44:443 -> 192.168.2.3:49744 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 151.101.1.44:443 -> 192.168.2.3:49746 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 151.101.1.44:443 -> 192.168.2.3:49745 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 151.101.1.44:443 -> 192.168.2.3:49741 version: TLS 1.2 |
Source: 6007d134e83fctar.dll |
Static PE information: DYNAMIC_BASE, NX_COMPAT |
Source: |
Binary string: partial method>An expression tree may not contain an unsafe pointer operationAAn expression tree may not contain an anonymous method expressionHAn anonymous method expression cannot be converted to an expression tree@Range variable '%1!ls!' cannot be assigned to -- it is read onlyPThe range variable '%1!ls!' cannot have the same name as a method type parameterKThe contextual keyword 'var' cannot be used in a range variable declarationaThe best overloaded Add method '%1!ls!' for the collection initializer has some invalid argumentsAAn expression tree lambda may not contain an out or ref parameterJAn expression tree lambda may not contain a method with variable argumentsSSpecify debug information file name (default: output file name with .pdb extension)$Specify a Win32 manifest file (.xml))Do not include the default Win32 manifestNSpecify an application configuration file containing assembly binding settings8Output line and column of the end location of each errorFBuild a Windows Runtime intermediate file that is consumed by WinMDExp Build an Appcontainer executable+Specify the preferred output language name.3Could not write to output file '%2!ls!' -- '%1!ls!' source: csc.exe, 00000022.00000002.411809654.000001F23FCA0000.00000002.00000001.sdmp, csc.exe, 00000026.00000002.422411494.000001D454620000.00000002.00000001.sdmp |
Source: |
Binary string: ntdll.pdb source: regsvr32.exe, 00000001.00000003.431440202.0000000005950000.00000004.00000001.sdmp |
Source: |
Binary string: 7C:\Users\user\AppData\Local\Temp\pzrffmak\pzrffmak.pdb source: powershell.exe, 00000020.00000002.450828267.000001AE45BD8000.00000004.00000001.sdmp |
Source: |
Binary string: ntdll.pdbUGP source: regsvr32.exe, 00000001.00000003.431440202.0000000005950000.00000004.00000001.sdmp |
Source: |
Binary string: 7C:\Users\user\AppData\Local\Temp\crd40oh3\crd40oh3.pdb source: powershell.exe, 00000020.00000002.450828267.000001AE45BD8000.00000004.00000001.sdmp |
Source: |
Binary string: c:\Movenear\AgoSection\placeRace\Liquid.pdb source: 6007d134e83fctar.dll |
Source: |
Binary string: 7C:\Users\user\AppData\Local\Temp\pzrffmak\pzrffmak.pdbXP source: powershell.exe, 00000020.00000002.450999766.000001AE45C50000.00000004.00000001.sdmp |
Source: |
Binary string: 7C:\Users\user\AppData\Local\Temp\crd40oh3\crd40oh3.pdbXP source: powershell.exe, 00000020.00000002.450828267.000001AE45BD8000.00000004.00000001.sdmp |
Source: C:\Windows\SysWOW64\regsvr32.exe |
Code function: 1_2_043A056C RtlAllocateHeap,RtlAllocateHeap,RtlAllocateHeap,memset,CreateFileA,GetFileTime,CloseHandle,StrRChrA,lstrcat,FindFirstFileA,FindFirstFileA,CompareFileTime,CompareFileTime,FindClose,FindNextFileA,FindClose,FindFirstFileA,CompareFileTime,StrChrA,memcpy,FindNextFileA,FindClose,FindFirstFileA,CompareFileTime,FindClose,HeapFree,HeapFree, |
1_2_043A056C |
Source: C:\Windows\SysWOW64\regsvr32.exe |
Code function: 1_2_0438BF1E FindFirstFileW,lstrlenW,lstrlenW,lstrcpyW,lstrlenW,lstrcpyW,lstrcpyW,FindNextFileW,FindClose,FreeLibrary, |
1_2_0438BF1E |
Source: C:\Windows\SysWOW64\regsvr32.exe |
Code function: 1_2_0439AF0E lstrlenW,wcscpy,lstrlenW,lstrlenW,memset,FindFirstFileW,lstrlenW,lstrlenW,memset,wcscpy,PathFindFileNameW,RtlEnterCriticalSection,RtlLeaveCriticalSection,lstrlenW,FindNextFileW,WaitForSingleObject,FindClose,FindFirstFileW,lstrlenW,FindNextFileW,WaitForSingleObject,FindClose, |
1_2_0439AF0E |
Source: C:\Windows\SysWOW64\regsvr32.exe |
Code function: 1_2_04399363 lstrlenW,FindFirstFileW,lstrlenW,RemoveDirectoryW,DeleteFileW,FindNextFileW,GetLastError, |
1_2_04399363 |
Source: C:\Windows\SysWOW64\regsvr32.exe |
Code function: 1_2_04395ECD wcscpy,wcscpy,GetLogicalDriveStringsW,GetLogicalDriveStringsW,RtlAllocateHeap,memset,GetLogicalDriveStringsW,WaitForSingleObject,GetDriveTypeW,lstrlenW,wcscpy,lstrlenW,HeapFree, |
1_2_04395ECD |
Source: Joe Sandbox View |
IP Address: 151.101.1.44 151.101.1.44 |
Source: Joe Sandbox View |
JA3 fingerprint: 9e10692f1b7f78228b2d4e424db3a98c |
Source: global traffic |
HTTP traffic detected: GET /manifest/9dBougJwDtiqZ/QQHMIVU_/2BhS1knkkKX_2FVufwZ0oyN/EbGuCLEAI8/LnviyVmU_2BJ7xAua/uY77q6VVLGV8/agEg6nrSlO8/ECdHQy5W4nMbRU/wngAS3IMky7ngjR5nSGPQ/K9l7rtKzY6Pm4I7S/PgkTHSMkne_2BL6/avNSLX3b9xZHhQcrwM/KqzdjJJ_2/BoGyL5Rb/hdm5SZ8.cnx HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: lopppooole.xyzConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: GET /favicon.ico HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: lopppooole.xyzConnection: Keep-AliveCookie: PHPSESSID=cklnirt54us2267ioh1bdjd451; lang=en |
Source: global traffic |
HTTP traffic detected: GET /manifest/vduANE3J_2Bc1JVCe/mGf1TVDsPl7d/IwOe5xT417F/r0djERcwNagbl3/secUFuGZN4k2hLpDAmqZ_/2B14CbUSwUpX_2Fi/39R3WtzGANArbeD/to_2F84kphfq2hxfRa/eViH_2Bcq/DU4QxfFdXEk1hh6ELb0S/LXfZS2VQbBBYXjDtBzf/6HdWO2UjIqCLslcJOFOPGY/_2FVMnTrB/_2B.cnx HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: lopppooole.xyzConnection: Keep-AliveCookie: lang=en; PHPSESSID=cklnirt54us2267ioh1bdjd451 |
Source: global traffic |
HTTP traffic detected: GET /manifest/vZLK0d4lARH3Q_2BrO_/2FsO_2F2nRs6X2oi1Zey6b/w_2BPzCyb9qWu/aUJj6fj9/AoW2RxwV5jVAuuIZ6tg8Vss/9LOe5w8WWk/h4UkM31kYpKt809d8/y04pjwYJwpB4/tTLboWwUU5K/KwHKzEhmg_2FCK/0RXjauzqdq7mdbzD87Bzs/Wj_2BxZ5qHCgyoUo/tDRuRFtxq/6W5SEq8I/P.cnx HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: lopppooole.xyzConnection: Keep-AliveCookie: lang=en; PHPSESSID=cklnirt54us2267ioh1bdjd451 |
Source: de-ch[1].htm.4.dr |
String found in binary or memory: <a href="https://www.facebook.com/" target="_blank" data-piitxt="facebooklite" piiurl="https://www.facebook.com/"> equals www.facebook.com (Facebook) |
Source: msapplication.xml0.3.dr |
String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x8a7b0678,0x01d6ef43</date><accdate>0x8a7b0678,0x01d6ef43</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook) |
Source: msapplication.xml0.3.dr |
String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x8a7b0678,0x01d6ef43</date><accdate>0x8a7b0678,0x01d6ef43</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook) |
Source: msapplication.xml5.3.dr |
String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x8a822dab,0x01d6ef43</date><accdate>0x8a822dab,0x01d6ef43</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter) |
Source: msapplication.xml5.3.dr |
String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x8a822dab,0x01d6ef43</date><accdate>0x8a848ff9,0x01d6ef43</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter) |
Source: msapplication.xml7.3.dr |
String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x8a848ff9,0x01d6ef43</date><accdate>0x8a848ff9,0x01d6ef43</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube) |
Source: msapplication.xml7.3.dr |
String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x8a848ff9,0x01d6ef43</date><accdate>0x8a848ff9,0x01d6ef43</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube) |
Source: de-ch[1].htm.4.dr |
String found in binary or memory: <link rel="preconnect" href="img-s-msn-com.akamaized.net" /><link rel="preconnect" href="c.msn.com" /><link rel="preconnect" href="c.msn.cn" /><link rel="preconnect" href="https://www.bing.com" /><link rel="preconnect" href="//web.vortex.data.msn.com" /><link rel="dns-prefetch" href="img-s-msn-com.akamaized.net" /><link rel="dns-prefetch" href="c.msn.com" /><link rel="dns-prefetch" href="c.msn.cn" /><link rel="dns-prefetch" href="https://www.bing.com" /><link rel="dns-prefetch" href="//web.vortex.data.msn.com" /><link rel="canonical" href="https://www.msn.com/de-ch/" /><meta name="msapplication-TileColor" content="#224f7b"/><meta name="msapplication-TileImage" content="//static-global-s-msn-com.akamaized.net/hp-neu/sc/1f/08ced4.png"/><meta name="msapplication-config" content="none"/> <title>MSN Schweiz | Sign in Hotmail, Outlook Login, Windows Live, Office 365</title> equals www.hotmail.com (Hotmail) |
Source: 85-0f8009-68ddb2ab[1].js.4.dr |
String found in binary or memory: glich.",errorFooterText:"Zu Twitter wechseln",taskLinks:"Benachrichtigungen|https://twitter.com/i/notifications;Ich|#;Abmelden|#"}],xbox:[{header:"Spotlight",content:"",footerText:"Alle anzeigen",footerUrl:"",taskLinks:"me_groove_taskLinks_store|https://www.microsoft.com/store/media/redirect/music?view=hub;me_groove_taskLinks_play|https://aka.ms/Ixhi8e;me_groove_taskLinks_try|https://aka.ms/msvmj1"},{header:"Meine tolle Wiedergabeliste",headerUrl:"https://aka.ms/qeqf5y",content:"",errorMessage:"",taskLinks:"me_groove_taskLinks_store|https://www.microsoft.com/store/media/redirect/music?view=hub;me_groove_taskLinks_play|https://aka.ms/Ixhi8e;me_groove_taskLinks_try|https://aka.ms/msvmj1"}],bingrewards:[{header:"Pr equals www.twitter.com (Twitter) |
Source: de-ch[1].htm.4.dr |
String found in binary or memory: hren, die sich auf Ihren Internetdatenverkehr auswirken.<br/><br/><a href=\""+e.html(f)+'" onclick="window.location.reload(true)">Klicken Sie hier<\/a> um diese Seite erneut zu laden, oder besuchen Sie: <a href="'+i+'">'+i+"<\/a><\/p><\/div><div id='errorref'><span>Ref 1: "+e.html(o(t.clientSettings.aid))+" Ref 2: "+e.html(t.clientSettings.sid||"000000")+" Ref 3: "+e.html((new r.Date).toUTCString())+"<\/span><\/div><\/div>"});ot({errId:1512,errMsg:n})}function ot(n){require(["track"],function(t){var i={errId:n.errId,errMsg:n.errMsg,reportingType:0};t.trackAppErrorEvent(i)})}function tt(){var n=v(arguments);a(l(n,b),n,!0)}function st(){var n=v(arguments);a(l(n,h),n)}function ht(){var n=v(arguments);a(l(n,y),n)}function ct(n){(r.console||{}).timeStamp?console.timeStamp(n):(r.performance||{}).mark&&r.performance.mark(n)}var w=0,it=-1,b=0,h=1,y=2,s=[],p,k,rt,o,d=!1,c=Math.random()*100<=-1;return ut(r,function(n,t,i,r){return w++,n=nt(n,t,i,r," [ENDMESSAGE]"),n&&tt("[SCRIPTERROR] "+n),!0}),c&&require(["jquery","c.deferred"],function(n){k=!0;rt=n;s.length&&g()}),{error:tt,fatalError:et,unhandledErrorCount:function(){return w},perfMark:ct,warning:st,information:ht}});require(["viewAwareInit"],function(n){n({size2row:"(min-height: 48.75em)",size1row:"(max-height: 48.74em)",size4column:"(min-width: 72em)",size3column:"(min-width: 52.313em) and (max-width: 71.99em)",size2column:"(min-width: 43.75em) and (max-width: 52.303em)",size2rowsize4column:"(min-width: 72em) and (min-height: 48.75em)",size2rowsize3column:"(min-width: 52.313em) and (max-width: 71.99em) and (min-height: 48.75em)",size2rowsize2column:"(max-width: 52.303em) and (min-height: 48.75em)",size1rowsize4column:"(min-width: 72em) and (max-height: 48.74em)",size1rowsize3column:"(min-width: 52.313em) and (max-width: 71.99em) and (max-height: 48.74em)",size1rowsize2column:"(max-width: 52.303em) and (max-height: 48.74em)"})});require(["deviceInit"],function(n){n({AllowTransform3d:"false",AllowTransform2d:"true",RtlScrollLeftAdjustment:"none",ShowMoveTouchGestures:"true",SupportFixedPosition:"true",UseCustomMatchMedia:null,Viewport_Behavior:"Default",Viewport_Landscape:null,Viewport:"width=device-width,initial-scale=1.0",IsMobileDevice:"false"})})</script><meta property="sharing_url" content="https://www.msn.com/de-ch"/><meta property="og:url" content="https://www.msn.com/de-ch/"/><meta property="og:title" content="MSN Schweiz | Sign in |