Loading ...

Play interactive tourEdit tour

Windows Analysis Report Peixoto - QUOTATION LIST.exe

Overview

General Information

Sample Name:Peixoto - QUOTATION LIST.exe
Analysis ID:499570
MD5:0f129aa97048f7ec0557b211349a2ce0
SHA1:b597185c94fac60cd7e25db83bfb39ed07409289
SHA256:fcf3b27fdc54c53a1f7510abf8bdf748bd3199813d0294738feba29c7c1054d1
Tags:exeNanoCore
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Sigma detected: NanoCore
Detected Nanocore Rat
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Yara detected Nanocore RAT
Initial sample is a PE file and has a suspicious name
Writes to foreign memory regions
Machine Learning detection for sample
Allocates memory in foreign processes
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
Creates an undocumented autostart registry key
Machine Learning detection for dropped file
C2 URLs / IPs found in malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Internet Provider seen in connection with other malware
Detected potential crypto function
Stores files to the Windows start menu directory
Contains long sleeps (>= 3 min)
Enables debug privileges
Creates a DirectInput object (often for capturing keystrokes)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Installs a raw input device (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
PE file contains strange resources
Drops PE files
Detected TCP or UDP traffic on non-standard ports
Binary contains a suspicious time stamp
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)

Classification

Process Tree

  • System is w10x64
  • Peixoto - QUOTATION LIST.exe (PID: 5460 cmdline: 'C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe' MD5: 0F129AA97048F7EC0557B211349A2CE0)
    • Peixoto - QUOTATION LIST.exe (PID: 6572 cmdline: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe MD5: 0F129AA97048F7EC0557B211349A2CE0)
    • Peixoto - QUOTATION LIST.exe (PID: 6584 cmdline: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe MD5: 0F129AA97048F7EC0557B211349A2CE0)
  • cleanup

Malware Configuration

Threatname: NanoCore

{"Version": "1.2.2.0", "Mutex": "28a7a9fa-8b88-4ff1-be22-9ecea4e9", "Group": "T-C", "Domain1": "185.222.57.149", "Domain2": "127.0.0.1", "Port": 4557, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x59eb:$x1: NanoCore.ClientPluginHost
  • 0x5b48:$x2: IClientNetworkHost
00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x59eb:$x2: NanoCore.ClientPluginHost
  • 0x6941:$s3: PipeExists
  • 0x5be1:$s4: PipeCreated
  • 0x5a05:$s5: IClientLoggingHost
00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x37de5:$x1: NanoCore.ClientPluginHost
  • 0x5fe05:$x1: NanoCore.ClientPluginHost
  • 0x37e22:$x2: IClientNetworkHost
  • 0x5fe42:$x2: IClientNetworkHost
  • 0x3b955:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
  • 0x63975:$x3: #=qjgz7ljmpp0J7FvL9dmi8ctJILdgtcbw8JYUc6GC8MeJ9B11Crfg2Djxcf0p8PZGe
00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpJoeSecurity_NanocoreYara detected Nanocore RATJoe Security
    00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
    • 0x37b4d:$a: NanoCore
    • 0x37b5d:$a: NanoCore
    • 0x37d91:$a: NanoCore
    • 0x37da5:$a: NanoCore
    • 0x37de5:$a: NanoCore
    • 0x5fb6d:$a: NanoCore
    • 0x5fb7d:$a: NanoCore
    • 0x5fdb1:$a: NanoCore
    • 0x5fdc5:$a: NanoCore
    • 0x5fe05:$a: NanoCore
    • 0x37bac:$b: ClientPlugin
    • 0x37dae:$b: ClientPlugin
    • 0x37dee:$b: ClientPlugin
    • 0x5fbcc:$b: ClientPlugin
    • 0x5fdce:$b: ClientPlugin
    • 0x5fe0e:$b: ClientPlugin
    • 0x37cd3:$c: ProjectData
    • 0x5fcf3:$c: ProjectData
    • 0x386da:$d: DESCrypto
    • 0x606fa:$d: DESCrypto
    • 0x400a6:$e: KeepAlive
    Click to see the 49 entries

    Unpacked PEs

    SourceRuleDescriptionAuthorStrings
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x605:$x1: NanoCore.ClientPluginHost
    • 0x63e:$x2: IClientNetworkHost
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
    • 0x605:$x2: NanoCore.ClientPluginHost
    • 0x720:$s4: PipeCreated
    • 0x61f:$s5: IClientLoggingHost
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x2205:$x1: NanoCore.ClientPluginHost
    • 0x223e:$x2: IClientNetworkHost
    16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
    • 0x2205:$x2: NanoCore.ClientPluginHost
    • 0x2320:$s4: PipeCreated
    • 0x221f:$s5: IClientLoggingHost
    16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
    • 0x6da5:$x1: NanoCore.ClientPluginHost
    • 0x6dd2:$x2: IClientNetworkHost
    Click to see the 135 entries

    Sigma Overview

    AV Detection:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    E-Banking Fraud:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    Stealing of Sensitive Information:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    Remote Access Functionality:

    barindex
    Sigma detected: NanoCoreShow sources
    Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe, ProcessId: 6584, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmpMalware Configuration Extractor: NanoCore {"Version": "1.2.2.0", "Mutex": "28a7a9fa-8b88-4ff1-be22-9ecea4e9", "Group": "T-C", "Domain1": "185.222.57.149", "Domain2": "127.0.0.1", "Port": 4557, "KeyboardLogging": "Enable", "RunOnStartup": "Disable", "RequestElevation": "Disable", "BypassUAC": "Disable", "ClearZoneIdentifier": "Enable", "ClearAccessControl": "Disable", "SetCriticalProcess": "Disable", "PreventSystemSleep": "Enable", "ActivateAwayMode": "Disable", "EnableDebugMode": "Disable", "RunDelay": 0, "ConnectDelay": 4000, "RestartDelay": 5000, "TimeoutInterval": 5000, "KeepAliveTimeout": 30000, "MutexTimeout": 5000, "LanTimeout": 2500, "WanTimeout": 8000, "BufferSize": "ffff0000", "MaxPacketSize": "0000a000", "GCThreshold": "0000a000", "UseCustomDNS": "Enable", "PrimaryDNSServer": "8.8.8.8", "BackupDNSServer": "8.8.4.4"}
    Multi AV Scanner detection for submitted fileShow sources
    Source: Peixoto - QUOTATION LIST.exeVirustotal: Detection: 25%Perma Link
    Multi AV Scanner detection for domain / URLShow sources
    Source: 185.222.57.149Virustotal: Detection: 5%Perma Link
    Multi AV Scanner detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeVirustotal: Detection: 25%Perma Link
    Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeVirustotal: Detection: 25%Perma Link
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR
    Machine Learning detection for sampleShow sources
    Source: Peixoto - QUOTATION LIST.exeJoe Sandbox ML: detected
    Machine Learning detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJoe Sandbox ML: detected
    Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJoe Sandbox ML: detected
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpackAvira: Label: TR/Dropper.MSIL.Gen7
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpackAvira: Label: TR/NanoCore.fadte
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpackAvira: Label: TR/NanoCore.fadte
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp
    Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49751 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49752 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49773 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49779 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49780 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49781 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49782 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49783 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49801 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49813 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49814 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49815 -> 185.222.57.149:4557
    Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.7:49816 -> 185.222.57.149:4557
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: 127.0.0.1
    Source: Malware configuration extractorURLs: 185.222.57.149
    Source: Joe Sandbox ViewASN Name: ROOTLAYERNETNL ROOTLAYERNETNL
    Source: global trafficTCP traffic: 192.168.2.7:49751 -> 185.222.57.149:4557
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: unknownTCP traffic detected without corresponding DNS query: 185.222.57.149
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpString found in binary or memory: http://google.com
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000002.330286689.000000000073B000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmpBinary or memory string: RegisterRawInputDevices

    E-Banking Fraud:

    barindex
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR

    System Summary:

    barindex
    Malicious sample detected (through community Yara rule)Show sources
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.5cb0000.15.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7254c9f.30.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.725e8a4.31.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71b0000.21.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45f0a04.10.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e6dff.9.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71f0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.505641453.00000000046D8000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
    Initial sample is a PE file and has a suspicious nameShow sources
    Source: initial sampleStatic PE information: Filename: Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71e0000.23.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3484f60.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.348a998.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7180000.20.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.5cb0000.15.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.5cb0000.15.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7170000.19.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7220000.27.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7290000.32.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7254c9f.30.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7254c9f.30.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7200000.25.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3414250.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.725e8a4.31.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.725e8a4.31.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71b0000.21.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71b0000.21.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71d0000.22.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45f0a04.10.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45f0a04.10.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e6dff.9.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e6dff.9.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7240000.28.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71f0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.71f0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.474b5b6.14.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.45e2160.11.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.4734357.13.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7210000.26.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.7250000.29.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.473d186.12.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 0.2.Peixoto - QUOTATION LIST.exe.2485ef8.1.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.34235ec.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 16.2.Peixoto - QUOTATION LIST.exe.3470924.6.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.505641453.00000000046D8000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
    Source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354ACF0_2_02354ACF
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023536610_2_02353661
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02352E500_2_02352E50
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354A7D0_2_02354A7D
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354AAB0_2_02354AAB
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023552E70_2_023552E7
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023548C10_2_023548C1
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023549300_2_02354930
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_0235491A0_2_0235491A
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_0235495E0_2_0235495E
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_0235494D0_2_0235494D
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023549B30_2_023549B3
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354E340_2_02354E34
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354C1D0_2_02354C1D
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354CF40_2_02354CF4
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_02354D200_2_02354D20
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeCode function: 0_2_023525100_2_02352510
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_058EE48016_2_058EE480
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_058EE47116_2_058EE471
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_058EBBD416_2_058EBBD4
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A3F5F816_2_05A3F5F8
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A3978816_2_05A39788
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A335A816_2_05A335A8
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeCode function: 16_2_05A3A58016_2_05A3A580
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilename vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000003.325328970.00000000007A6000.00000004.00000001.sdmpBinary or memory string: OriginalFilenamenow-ConsoleApp13.exeB vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameZuqohptuwpijwgcwqzv.dll" vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilename vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilename vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameMyClientPlugin.dll@ vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507190685.00000000067D0000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameLzma#.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameSecurityClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameManagementClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameNanoCoreBase.dll< vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameMyClientPluginNew.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameFileBrowserClient.dllT vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameMyClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameNanoCoreStressTester.dll< vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameNetworkClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameToolsClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameAForge.Video.DirectShow.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameNAudio.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameSurveillanceClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameCoreClientPlugin.dll8 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameSurveillanceExClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.500613906.00000000016FA000.00000004.00000020.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameClientPlugin.dll4 vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeBinary or memory string: OriginalFilenamenow-ConsoleApp13.exeB vs Peixoto - QUOTATION LIST.exe
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: zhrtgdis.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: Peixoto - QUOTATION LIST.exe.0.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: zhrtgdis.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: Peixoto - QUOTATION LIST.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: Peixoto - QUOTATION LIST.exeVirustotal: Detection: 25%
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile read: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: unknownProcess created: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe 'C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe'
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32Jump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: classification engineClassification label: mal100.troj.evad.winEXE@5/9@0/1
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{28a7a9fa-8b88-4ff1-be22-9ecea4e92a97}
    Source: Peixoto - QUOTATION LIST.exe, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: zhrtgdis.exe.0.dr, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: Peixoto - QUOTATION LIST.exe.0.dr, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: 0.0.Peixoto - QUOTATION LIST.exe.20000.0.unpack, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: 0.2.Peixoto - QUOTATION LIST.exe.20000.0.unpack, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: 15.0.Peixoto - QUOTATION LIST.exe.10000.0.unpack, ExtensionMethods.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
    Source: Peixoto - QUOTATION LIST.exeStatic file information: File size 1203200 > 1048576
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\MyNanoCore RemoteScripting\MyClientPlugin\obj\Debug\MyClientPluginNew.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp
    Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp
    Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp

    Data Obfuscation:

    barindex
    .NET source code contains potential unpackerShow sources
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqjIje6jGWLd2EOkfZXKqBbgu003du003d.cs.Net Code: #=q_FL69pQf17BUSAFbWYu1SStMAbdu$R1GJ8VY8UL5_EA= System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqxoz66kOqvxr21iYXZYXWiumy9eZGwFWaiX4C5X8aecUu003d.cs.Net Code: #=qKU0J1fiP8KA33eFK1owekQ== System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
    Source: Peixoto - QUOTATION LIST.exeStatic PE information: 0xAEA5775B [Mon Nov 6 22:59:39 2062 UTC]
    Source: initial sampleStatic PE information: section name: .text entropy: 7.99870340819
    Source: initial sampleStatic PE information: section name: .text entropy: 7.99870340819
    Source: initial sampleStatic PE information: section name: .text entropy: 7.99870340819
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.csHigh entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs='
    Source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.csHigh entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK'
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to dropped file
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJump to dropped file

    Boot Survival:

    barindex
    Creates an undocumented autostart registry key Show sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeKey value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders StartupJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exeJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe\:Zone.Identifier:$DATAJump to behavior

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Hides that the sample has been downloaded from the Internet (zone.identifier)Show sources
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeFile opened: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe:Zone.Identifier read attributes | deleteJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe TID: 3264Thread sleep time: -922337203685477s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe TID: 6676Thread sleep time: -4611686018427385s >= -30000sJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: threadDelayed 4459Jump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: threadDelayed 3846Jump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: foregroundWindowGot 526Jump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWindow / User API: foregroundWindowGot 614Jump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess information queried: ProcessInformationJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeThread delayed: delay time: 922337203685477Jump to behavior
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501089724.0000000001775000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllA
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeProcess token adjusted: DebugJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory allocated: page read and write | page guardJump to behavior

    HIPS / PFW / Operating System Protection Evasion:

    barindex
    Writes to foreign memory regionsShow sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 400000Jump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 402000Jump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 420000Jump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 422000Jump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 113C008Jump to behavior
    Allocates memory in foreign processesShow sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory allocated: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 400000 protect: page execute and read and writeJump to behavior
    Injects a PE file into a foreign processesShow sources
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeMemory written: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe base: 400000 value starts with: 4D5AJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeProcess created: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeJump to behavior
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: uProgram Manager
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507484711.000000000706B000.00000004.00000001.sdmpBinary or memory string: Program Manager#
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507393672.0000000006B6C000.00000004.00000001.sdmpBinary or memory string: Program Manager
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: Progman
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507170704.00000000067CC000.00000004.00000001.sdmpBinary or memory string: Program Managerram Manager
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.503827465.0000000003755000.00000004.00000001.sdmpBinary or memory string: Program Manager|$
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.503113331.000000000356F000.00000004.00000001.sdmpBinary or memory string: Program ManagerHa_l(
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.501649740.0000000001D80000.00000002.00020000.sdmpBinary or memory string: Progmanlock
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.504994665.0000000003A47000.00000004.00000001.sdmpBinary or memory string: Program Manager4
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.504994665.0000000003A47000.00000004.00000001.sdmpBinary or memory string: Program Manager@lp
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
    Source: C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
    Source: C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct

    Stealing of Sensitive Information:

    barindex
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR

    Remote Access Functionality:

    barindex
    Detected Nanocore RatShow sources
    Source: Peixoto - QUOTATION LIST.exe, 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmpString found in binary or memory: NanoCore.ClientPluginHost
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpString found in binary or memory: NanoCore.ClientPluginHost
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCoreBase.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainNanoCoreBaseClientPluginCommandHandlerResourcesNanoCoreBase.My.ResourcesMySettingsMySettingsPropertyCommandsMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostSendCommandparamsInitializePluginNanoCore.ClientPluginIClientNetwork_networkhost_loggingHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketHandleCommandHandleCommandOpenWebsiteHandleCommandMessageBoxSwapMouseButtonfSwapuser32.dllHandleCommandMouseSwapHandleCommandMouseUnswapmciSendStringlpszCommandlpszReturnStringcchReturnLengthhwndCallbackwinmm.dllmciSendStringAHandleCommandCDTrayHandleCommandCDTrayCloseSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CultureValueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsEnumvalue__OpenWebsiteMessageBoxCDTrayCDTrayCloseMouseSwapMouseUnswapSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeSendToServerParamArrayAttributeStringProcessStartSystem.Windows.FormsDialogResultShowConversionsReferenceEqualsSystem.ReflectionAssemblyget_AssemblyCompilerGeneratedAttributeSettingsBaseSynchronizedNanoCoreBase.Resources.resourcesDebuggableAttributeDebuggingModesCompilationRelaxationsAttributeRuntimeCompatibilityAttributeAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeNanoCoreBase.dll+set CDAudio door open/set CDAudio door closed-NanoCoreBase.Resources3
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationFileBrowserClient.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainFileBrowserClientClientPluginCommandHandlersResourcesFileBrowserClient.My.ResourcesMySettingsMySettingsPropertyFunctionsCommandTypesMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostCurrentDirectoryInitializePluginNanoCore.ClientPluginIClientNetwork_loggingHost_networkHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketparamsHandleCreateDirectoryremoteDirHandleDeleteFileremoteFileisDirectoryHandleOpenFileHandleReceiveFilelocalFileHandleRenameFilenewFileNameHandleSetCurrentDirectorypathHandleDeleteHandleDownloadHandleDrivesHandleFilesHandleGetCurrentDirectoryHandleMachineNameHandleOpenHandleSetCurrentDirectoryPacketHandleUploadHandleRenameHandleCreateSendCurrentDirectorySendDrivesSendFileSendFilesSendMachineNameSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CulturevalueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsSystem.Collections.GenericList`1RemoteFilesRemoteFoldersRemoteDrivesEnumerateRemoteFilesEnumerateRemoteDrivesLogMessagemessageEnumvalue__MachineNameDrivesFilesGetCurrentDirectorySetCurrentDirectoryDownloadUploadOpenDeleteCreateDirectoryRenameSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeEnvironmentSpecialFolderGetFolderPathStringFormatSystem.IODirectoryDirectoryInfoProjectDataExceptionSetProjectErrorClearProjectErrorFileLogClientExceptionProcessStartConvertFromBase64StringWriteAllBytesMoveSendToServerConversionsToBooleanInt32NewLateBindingLateIndexGetEnumeratorEmptyGetEnumeratorget_CurrentTrimConcatMoveNextIDisposableDisposeReadAllBytesToBase64StringIsNullOrEmptyget_MachineNameToUpperget_UserNameReferenceEqualsSystem.ReflectionAssemblyget_AssemblyCompilerGeneratedAttributeSettingsBaseSynchronizedFileInfoFileSystemInfoget_FullNameContainsGetDirectoriesget_NameAddGetF
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationMyClientPlugin.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainMyClientPluginClientPluginMiscCommandHandlerCommandTypeMiscCommandMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostInitializePluginNanoCore.ClientPluginIClientNetwork_loggingHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketparamsHandleMiscCommandHandleMiscCommandMessageInterpretRecievedcommandtodoloopkeysEnumvalue__MessageStringExceptionMicrosoft.VisualBasic.CompilerServicesOperatorsCompareStringServerComputerMicrosoft.VisualBasic.MyServicesRegistryProxyget_RegistryMicrosoft.Win32RegistryKeyget_LocalMachineConcatInt32SetValueProjectDataSetProjectErrorClearProjectErrorget_LengthStandardModuleAttributeSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeDebuggableAttributeDebuggingModesCompilationRelaxationsAttributeRuntimeCompatibilityAttributeSystem.ReflectionAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeMyClientPlugin.dll'DisableWebcamLights
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCoreStressTester.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainNanoCoreStressTesterClientPluginHTTPFloodSlowLorisSYNFloodTCPNanoCoreStressTester.FloodUDPSendSynCommandHandlerResourcesNanoCoreStressTester.My.ResourcesMySettingsMySettingsPropertyCommandsMethodsMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostIClientDataHostDataHostClientGUIDSendCommandparamsInitializePluginNanoCore.ClientPluginIClientNetwork_networkhost_loggingHost_DataHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketStartHostToAttackArrayUploadDataSiteUserAgentRefererValuesGeneratecodelengthSystem.ThreadingThreadThreadsPortToAttackTimeToAttackThreadstoUseThreadsEndedattacksAttackRunningFloodnewHostnewPortnewTimenewThreadslolStopSlowlorisStressThreadStart_floodingJob_floodingThreadSystem.NetIPEndPoint_ipEo_synClassHostIsEnabledPortSuperSynSocketsStartSuperSynStopSuperSynSystem.Net.SocketsSocketClientIPPacketsPacketSizeMaxPacketsStopFloodmPacketspSize_sockipEosuperSynSockets__1IAsyncResultOnConnectarSendFloodingstopHTTPBytesSentSYNConnectionsHTTPDataSentMethodTargetAddressTargetStatusupdateBytesnewSYNFloodHandleDDOSCommandHandleStopCommandSystem.TimersElapsedEventArgsbytesTimerElapsedsourceeHandleHTTPCommandHandleSlowlorisCommandHandleTCPCommandHandleUDPCommandHandleSYNCommandSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CultureValueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsEnumvalue__sendStressCommandupdateStatusColumnstopStressCommandHTTPSlowlorisSYNSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeExceptionSendToServerProjectDataSetProjectErrorClearProjectErrorTimerNanoCoreIClientNameObjectCollectionget_VariablesGetValueset_Intervalset_EnabledElapsedEventHandleradd_ElapsedParamArrayAttributeRandomGuidStringIsNullOrEmptyArgumentNullExceptionArgumentOutOfRangeExce
    Source: Peixoto - QUOTATION LIST.exe, 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCore.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1IClientNetworkNanoCore.ClientPluginIClientDataIClientAppIClientDataHostNanoCore.ClientPluginHostIClientNetworkHostIClientUIHostIClientLoggingHostIClientAppHostIClientNameObjectCollectionNanoCoreIClientReadOnlyNameObjectCollectionClientInvokeDelegateMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceReadPacketpipeNameparamsPipeCreatedPipeClosedConnectionStateChangedconnectedConnectionFailedhostportBuildingHostCacheVariableChangednameClientSettingChangedPluginUninstallingClientUninstallingget_Variablesget_ClientSettingsget_BuilderSettingsVariablesClientSettingsBuilderSettingsget_ConnectedClosePipePipeExistsRebuildHostCacheAddHostEntryDisconnectSendToServercompressConnectedInvokemethodstateLogClientMessagemessageExceptionLogClientExceptionexsiteRestartShutdownDisableProtectionRestoreProtectionUninstallEntryExistsSystem.Collections.GenericKeyValuePair`2GetEntriesGetValuedefaultValueSetValuevalueRemoveValueMulticastDelegateTargetObjectTargetMethodIAsyncResultAsyncCallbackBeginInvokeDelegateCallbackDelegateAsyncStateEndInvokeDelegateAsyncResultSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeParamArrayAttributeCompilationRelaxationsAttributeRuntimeCompatibilityAttributeSystem.ReflectionAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeClientPluginClientPlugin.dll
    Yara detected Nanocore RATShow sources
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6664629.16.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.444d049.7.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.357ac78.4.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.37306f0.5.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 0.2.Peixoto - QUOTATION LIST.exe.3552c58.3.raw.unpack, type: UNPACKEDPE
    Source: Yara matchFile source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, type: MEMORY
    Source: Yara matchFile source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 5460, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Peixoto - QUOTATION LIST.exe PID: 6584, type: MEMORYSTR

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management Instrumentation1Registry Run Keys / Startup Folder11Process Injection312Masquerading1Input Capture21Query Registry1Remote ServicesInput Capture21Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsRegistry Run Keys / Startup Folder11Disable or Modify Tools1LSASS MemorySecurity Software Discovery111Remote Desktop ProtocolArchive Collected Data11Exfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Virtualization/Sandbox Evasion21Security Account ManagerProcess Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationRemote Access Software1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection312NTDSVirtualization/Sandbox Evasion21Distributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol1SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDeobfuscate/Decode Files or Information1LSA SecretsApplication Window Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
    Replication Through Removable MediaLaunchdRc.commonRc.commonHidden Files and Directories1Cached Domain CredentialsSystem Information Discovery12VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
    External Remote ServicesScheduled TaskStartup ItemsStartup ItemsObfuscated Files or Information1DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
    Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobSoftware Packing13Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
    Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Timestomp1/etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    Peixoto - QUOTATION LIST.exe26%VirustotalBrowse
    Peixoto - QUOTATION LIST.exe100%Joe Sandbox ML

    Dropped Files

    SourceDetectionScannerLabelLink
    C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe100%Joe Sandbox ML
    C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe100%Joe Sandbox ML
    C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe26%VirustotalBrowse
    C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe26%VirustotalBrowse

    Unpacked PE Files

    SourceDetectionScannerLabelLinkDownload
    16.2.Peixoto - QUOTATION LIST.exe.400000.0.unpack100%AviraTR/Dropper.MSIL.Gen7Download File
    16.2.Peixoto - QUOTATION LIST.exe.6660000.17.unpack100%AviraTR/NanoCore.fadteDownload File
    16.2.Peixoto - QUOTATION LIST.exe.4448a20.8.unpack100%AviraTR/NanoCore.fadteDownload File

    Domains

    No Antivirus matches

    URLs

    SourceDetectionScannerLabelLink
    127.0.0.10%VirustotalBrowse
    127.0.0.10%Avira URL Cloudsafe
    185.222.57.1496%VirustotalBrowse
    185.222.57.1490%Avira URL Cloudsafe

    Domains and IPs

    Contacted Domains

    No contacted domains info

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    127.0.0.1true
    • 0%, Virustotal, Browse
    • Avira URL Cloud: safe
    unknown
    185.222.57.149true
    • 6%, Virustotal, Browse
    • Avira URL Cloud: safe
    unknown

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://google.comPeixoto - QUOTATION LIST.exe, 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmpfalse
      high

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      185.222.57.149
      unknownNetherlands
      51447ROOTLAYERNETNLtrue

      General Information

      Joe Sandbox Version:33.0.0 White Diamond
      Analysis ID:499570
      Start date:08.10.2021
      Start time:16:08:18
      Joe Sandbox Product:CloudBasic
      Overall analysis duration:0h 10m 2s
      Hypervisor based Inspection enabled:false
      Report type:full
      Sample file name:Peixoto - QUOTATION LIST.exe
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
      Number of analysed new started processes analysed:25
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • HDC enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal100.troj.evad.winEXE@5/9@0/1
      EGA Information:Failed
      HDC Information:
      • Successful, ratio: 0.1% (good quality ratio 0.1%)
      • Quality average: 84.1%
      • Quality standard deviation: 10.6%
      HCA Information:
      • Successful, ratio: 99%
      • Number of executed functions: 78
      • Number of non-executed functions: 2
      Cookbook Comments:
      • Adjust boot time
      • Enable AMSI
      • Found application associated with file extension: .exe
      Warnings:
      Show All
      • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
      • Excluded IPs from analysis (whitelisted): 95.100.216.89, 20.82.209.183, 20.54.110.249, 40.112.88.60, 2.20.178.24, 2.20.178.33
      • Excluded domains from analysis (whitelisted): iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, neu-displaycatalogrp.useroor.bigcatalog.commerce.microsoft.com, ris-prod.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, e1723.g.akamaiedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, ris.api.iris.microsoft.com, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtAllocateVirtualMemory calls found.

      Simulations

      Behavior and APIs

      TimeTypeDescription
      16:09:56API Interceptor655x Sleep call for process: Peixoto - QUOTATION LIST.exe modified

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      185.222.57.149MERMAID SUBSEA - purchase order RX86404382953.exeGet hashmaliciousBrowse

        Domains

        No context

        ASN

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        ROOTLAYERNETNLSecuriteInfo.com.Trojan.Win32.Save.a.20322.exeGet hashmaliciousBrowse
        • 45.137.22.115
        PaymentAdvice.exeGet hashmaliciousBrowse
        • 185.222.58.151
        PI009876789.exeGet hashmaliciousBrowse
        • 185.222.58.154
        Proforma invoice Shipping documents.exeGet hashmaliciousBrowse
        • 45.137.22.91
        Payment_Advice.exeGet hashmaliciousBrowse
        • 45.137.22.115
        PO. 2100002.xlsxGet hashmaliciousBrowse
        • 185.222.57.162
        2WK7SGkGVZ.exeGet hashmaliciousBrowse
        • 45.137.22.91
        PO1038845621.exeGet hashmaliciousBrowse
        • 45.137.22.70
        SecuriteInfo.com.Suspicious.Win32.Save.a.24632.exeGet hashmaliciousBrowse
        • 45.137.22.115
        Application Copy.exeGet hashmaliciousBrowse
        • 45.137.22.70
        Swift Copy.xlsxGet hashmaliciousBrowse
        • 185.222.57.85
        pre-shipment docs pdf.exeGet hashmaliciousBrowse
        • 45.137.22.131
        SOA_SEPT.exeGet hashmaliciousBrowse
        • 45.137.22.115
        MERMAID SUBSEA - purchase order RX86404382953.exeGet hashmaliciousBrowse
        • 185.222.57.149
        Application copy.exeGet hashmaliciousBrowse
        • 45.137.22.70
        New Purchase Order# 4502369263.exeGet hashmaliciousBrowse
        • 45.137.22.142
        swift0098765.exeGet hashmaliciousBrowse
        • 45.137.22.115
        bthGMpTA2L.exeGet hashmaliciousBrowse
        • 185.222.58.118
        New Order PO200305-01.exeGet hashmaliciousBrowse
        • 185.222.58.118
        PO. 2100002.xlsxGet hashmaliciousBrowse
        • 185.222.57.162

        JA3 Fingerprints

        No context

        Dropped Files

        No context

        Created / dropped Files

        C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Peixoto - QUOTATION LIST.exe.log
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:ASCII text, with CRLF line terminators
        Category:modified
        Size (bytes):425
        Entropy (8bit):5.340009400190196
        Encrypted:false
        SSDEEP:12:Q3La/KDLI4MWuPk21OKbbDLI4MWuPJKiUrRZ9I0ZKhav:ML9E4Ks2wKDE4KhK3VZ9pKhk
        MD5:CC144808DBAF00E03294347EADC8E779
        SHA1:A3434FC71BA82B7512C813840427C687ADDB5AEA
        SHA-256:3FC7B9771439E777A8F8B8579DD499F3EB90859AD30EFD8A765F341403FC7101
        SHA-512:A4F9EB98200BCAF388F89AABAF7EA57661473687265597B13192C24F06638C6339A3BD581DF4E002F26EE1BA09410F6A2BBDB4DA0CD40B59D63A09BAA1AADD3D
        Malicious:true
        Reputation:moderate, very likely benign file
        Preview: 1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..
        C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
        Category:dropped
        Size (bytes):1203200
        Entropy (8bit):7.928918657272288
        Encrypted:false
        SSDEEP:24576:Qi4th4HdHtaqrbvYfCxkRPaGynuJ4Bk0xdh1HVsx+aV3gyGw:P4tCvaqx0Ht+Bk0DNswq3g8
        MD5:0F129AA97048F7EC0557B211349A2CE0
        SHA1:B597185C94FAC60CD7E25DB83BFB39ED07409289
        SHA-256:FCF3B27FDC54C53A1F7510ABF8BDF748BD3199813D0294738FEBA29C7C1054D1
        SHA-512:0780847D48DDF9336633665560185E58C60BFD516D7CEB2139DE897C526E3D23236667A7BCC199009C37E1D8B153C40377D9717C51F97450967297F9D3BA759A
        Malicious:true
        Antivirus:
        • Antivirus: Joe Sandbox ML, Detection: 100%
        • Antivirus: Virustotal, Detection: 26%, Browse
        Reputation:low
        Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[w................0......~........... ........@.. ....................................@.....................................O.......xz........................................................................... ............... ..H............text...4.... ...................... ..`.rsrc...xz.......|..................@..@.reloc...............Z..............@..B........................H.......$&...............>...............................................0..+....... .......+..(...........X...2.(.........&..*.........''.......0..H.......(....o.....+!..(......r...p .......o....&..&....(....-...........o.....*.........+...........9.......0..U.......r...prS..prW..p(....(....rY..p ............%.(....(.....o....t.....s....%.o....o....*....0..Z.......( ...rc..po!....s"....s#....o$......o%.....o&....o'.......io(.......,..o.....o)...s*...z.*..........-C..........
        C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe:Zone.Identifier
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):26
        Entropy (8bit):3.95006375643621
        Encrypted:false
        SSDEEP:3:ggPYV:rPYV
        MD5:187F488E27DB4AF347237FE461A079AD
        SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
        SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
        SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
        Malicious:true
        Reputation:high, very likely benign file
        Preview: [ZoneTransfer]....ZoneId=0
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\catalog.dat
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:data
        Category:dropped
        Size (bytes):2088
        Entropy (8bit):7.024371743172393
        Encrypted:false
        SSDEEP:48:Ik/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrwfk/lCrw8:flC0IlC0IlC0IlC0IlC0IlC0IlC0IlCe
        MD5:0D6805D12813A857D50D42D6EE2CCAB0
        SHA1:78D83F009D842F21FE2AB0EAFFD00E5AAD1776F4
        SHA-256:182E0F8AA959549D61C66D049645BA8445D86AEAD2B8C3552A9836FA1E5BD484
        SHA-512:5B29496F3AB3CCB915CF37042F4956BB00E577B5F15457A5A739BE1BD50C481FB7E3297EED575DCA7A7BD30ECBC140DD3666CD7DEDD25DFB7AEB41A1B5BEDA4A
        Malicious:false
        Reputation:moderate, very likely benign file
        Preview: Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.....@.3..{...grv+V...B.......].P...W.4C}uL.....s~..F...}......E......E...6E.....{...{.yS...7..".hK.!.x.2..i..zJ... ....f..?._....0.:e[7w{1.!.4.....&.Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:Non-ISO extended-ASCII text, with no line terminators
        Category:dropped
        Size (bytes):8
        Entropy (8bit):3.0
        Encrypted:false
        SSDEEP:3:5v8:G
        MD5:05D3210DC0F332DAC884A349CADDF7D9
        SHA1:7F6BCF10E578609F26A193EA92E72D57AE5EABC8
        SHA-256:384569455A5A7717A1CF73331CD40A9B2CE31AE8F4915351AA1FD8425E3B4C72
        SHA-512:DEEB972E54621868049FCA22E406B42F83C10305972DDEF7D9ED061F7DE90C3BBC12229A1477B0AEA0538847B2451C7211CE1A275508270F09CDED8525FDBA49
        Malicious:true
        Reputation:low
        Preview: ).....H
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\settings.bin
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:data
        Category:dropped
        Size (bytes):40
        Entropy (8bit):5.153055907333276
        Encrypted:false
        SSDEEP:3:9bzY6oRDT6P2bfVn1:RzWDT621
        MD5:4E5E92E2369688041CC82EF9650EDED2
        SHA1:15E44F2F3194EE232B44E9684163B6F66472C862
        SHA-256:F8098A6290118F2944B9E7C842BD014377D45844379F863B00D54515A8A64B48
        SHA-512:1B368018907A3BC30421FDA2C935B39DC9073B9B1248881E70AD48EDB6CAA256070C1A90B97B0F64BBE61E316DBB8D5B2EC8DBABCD0B0B2999AB50B933671ECB
        Malicious:false
        Reputation:moderate, very likely benign file
        Preview: 9iH...}Z.4..f.~a........~.~.......3.U.
        C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\storage.dat
        Process:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        File Type:data
        Category:dropped
        Size (bytes):327432
        Entropy (8bit):7.99938831605763
        Encrypted:true
        SSDEEP:6144:oX44S90aTiB66x3Pl6nGV4bfD6wXPIZ9iBj0UeprGm2d7Tm:LkjYGsfGUc9iB4UeprKdnm
        MD5:7E8F4A764B981D5B82D1CC49D341E9C6
        SHA1:D9F0685A028FB219E1A6286AEFB7D6FCFC778B85
        SHA-256:0BD3AAC12623520C4E2031C8B96B4A154702F36F97F643158E91E987D317B480
        SHA-512:880E46504FCFB4B15B86B9D8087BA88E6C4950E433616EBB637799F42B081ABF6F07508943ECB1F786B2A89E751F5AE62D750BDCFFDDF535D600CF66EC44E926
        Malicious:false
        Preview: pT..!..W..G.J..a.).@.i..wpK.so@...5.=.^..Q.oy.=e@9.B...F..09u"3.. 0t..RDn_4d.....E...i......~...|..fX_...Xf.p^......>a..$...e.6:7d.(a.A...=.)*.....{B.[...y%.*..i.Q.<..xt.X..H.. ..HF7g...I.*3.{.n....L.y;i..s-....(5i...........J.5b7}..fK..HV..,...0.... ....n.w6PMl.......v."".v.......#..X.a....../...cC...i..l{>5n.._+.e.d'...}...[..../...D.t..GVp.zz......(...o......b...+`J.{....hS1G.^*I..v&.jm.#u..1..Mg!.E..U.T.....6.2>...6.l.K.w"o..E..."K%{....z.7....<...,....]t.:.....[.Z.u...3X8.QI..j_.&..N..q.e.2...6.R.~..9.Bq..A.v.6.G..#y.....O....Z)G...w..E..k(....+..O..........Vg.2xC......O...jc.....z..~.P...q../.-.'.h.._.cj.=..B.x.Q9.pu.|i4...i...;O...n.?.,. ....v?.5}.OY@.dG|<.._[.69@.2..m..I..oP=...xrK.?............b..5....i&...l.c\b}..Q..O+.V.mJ.....pz....>F.......H...6$...d...|m...N..1.R..B.i..........$....$........CY}..$....r.....H...8...li.....7 P......?h....R.iF..6...q(.@LI.s..+K.....?m..H....*. l..&<}....`|.B....3.....I..o...u1..8i=.z.W..7
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
        Category:dropped
        Size (bytes):1203200
        Entropy (8bit):7.928918657272288
        Encrypted:false
        SSDEEP:24576:Qi4th4HdHtaqrbvYfCxkRPaGynuJ4Bk0xdh1HVsx+aV3gyGw:P4tCvaqx0Ht+Bk0DNswq3g8
        MD5:0F129AA97048F7EC0557B211349A2CE0
        SHA1:B597185C94FAC60CD7E25DB83BFB39ED07409289
        SHA-256:FCF3B27FDC54C53A1F7510ABF8BDF748BD3199813D0294738FEBA29C7C1054D1
        SHA-512:0780847D48DDF9336633665560185E58C60BFD516D7CEB2139DE897C526E3D23236667A7BCC199009C37E1D8B153C40377D9717C51F97450967297F9D3BA759A
        Malicious:true
        Antivirus:
        • Antivirus: Joe Sandbox ML, Detection: 100%
        • Antivirus: Virustotal, Detection: 26%, Browse
        Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[w................0......~........... ........@.. ....................................@.....................................O.......xz........................................................................... ............... ..H............text...4.... ...................... ..`.rsrc...xz.......|..................@..@.reloc...............Z..............@..B........................H.......$&...............>...............................................0..+....... .......+..(...........X...2.(.........&..*.........''.......0..H.......(....o.....+!..(......r...p .......o....&..&....(....-...........o.....*.........+...........9.......0..U.......r...prS..prW..p(....(....rY..p ............%.(....(.....o....t.....s....%.o....o....*....0..Z.......( ...rc..po!....s"....s#....o$......o%.....o&....o'.......io(.......,..o.....o)...s*...z.*..........-C..........
        C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\zhrtgdis.exe:Zone.Identifier
        Process:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        File Type:ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):26
        Entropy (8bit):3.95006375643621
        Encrypted:false
        SSDEEP:3:ggPYV:rPYV
        MD5:187F488E27DB4AF347237FE461A079AD
        SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
        SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
        SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
        Malicious:true
        Preview: [ZoneTransfer]....ZoneId=0

        Static File Info

        General

        File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
        Entropy (8bit):7.928918657272288
        TrID:
        • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
        • Win32 Executable (generic) a (10002005/4) 49.78%
        • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
        • Generic Win/DOS Executable (2004/3) 0.01%
        • DOS Executable Generic (2002/1) 0.01%
        File name:Peixoto - QUOTATION LIST.exe
        File size:1203200
        MD5:0f129aa97048f7ec0557b211349a2ce0
        SHA1:b597185c94fac60cd7e25db83bfb39ed07409289
        SHA256:fcf3b27fdc54c53a1f7510abf8bdf748bd3199813d0294738feba29c7c1054d1
        SHA512:0780847d48ddf9336633665560185e58c60bfd516d7ceb2139de897c526e3d23236667a7bcc199009c37e1d8b153c40377d9717c51f97450967297f9d3ba759a
        SSDEEP:24576:Qi4th4HdHtaqrbvYfCxkRPaGynuJ4Bk0xdh1HVsx+aV3gyGw:P4tCvaqx0Ht+Bk0DNswq3g8
        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[w................0......~........... ........@.. ....................................@................................

        File Icon

        Icon Hash:b296d2c2a2868682

        Static PE Info

        General

        Entrypoint:0x4efa2e
        Entrypoint Section:.text
        Digitally signed:false
        Imagebase:0x400000
        Subsystem:windows gui
        Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
        DLL Characteristics:NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
        Time Stamp:0xAEA5775B [Mon Nov 6 22:59:39 2062 UTC]
        TLS Callbacks:
        CLR (.Net) Version:v4.0.30319
        OS Version Major:4
        OS Version Minor:0
        File Version Major:4
        File Version Minor:0
        Subsystem Version Major:4
        Subsystem Version Minor:0
        Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744

        Entrypoint Preview

        Instruction
        jmp dword ptr [00402000h]
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al
        add byte ptr [eax], al

        Data Directories

        NameVirtual AddressVirtual Size Is in Section
        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IMPORT0xef9dc0x4f.text
        IMAGE_DIRECTORY_ENTRY_RESOURCE0xf00000x37a78.rsrc
        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
        IMAGE_DIRECTORY_ENTRY_BASERELOC0x1280000xc.reloc
        IMAGE_DIRECTORY_ENTRY_DEBUG0xef9c00x1c.text
        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

        Sections

        NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
        .text0x20000xeda340xedc00False0.99087720163data7.99870340819IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
        .rsrc0xf00000x37a780x37c00False0.510588915359data7.04584846576IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
        .reloc0x1280000xc0x200False0.044921875data0.101910425663IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

        Resources

        NameRVASizeTypeLanguageCountry
        RT_ICON0xf02000xf9eePNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
        RT_ICON0xffc000x10828dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 1510015233, next used block 1359020289
        RT_ICON0x1104380x94a8data
        RT_ICON0x1198f00x5488data
        RT_ICON0x11ed880x4228dBase IV DBT of \200.DBF, blocks size 0, block length 16896, next free block index 40, next free block 0, next used block 16777216
        RT_ICON0x122fc00x25a8data
        RT_ICON0x1255780x10a8data
        RT_ICON0x1266300x988data
        RT_ICON0x126fc80x468GLS_BINARY_LSB_FIRST
        RT_GROUP_ICON0x1274400x84data
        RT_VERSION0x1274d40x3a4data
        RT_MANIFEST0x1278880x1eaXML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

        Imports

        DLLImport
        mscoree.dll_CorExeMain

        Version Infos

        DescriptionData
        Translation0x0000 0x04b0
        LegalCopyrightCopyright (C) 2014-2021
        Assembly Version3.1.1.0
        InternalNamenow-ConsoleApp13.exe
        FileVersion3.1.1.0
        CompanyNameTelegram FZ-LLC
        LegalTrademarks
        CommentsTelegram Desktop
        ProductNameTelegram Desktop
        ProductVersion3.1.1.0
        FileDescriptionTelegram Desktop
        OriginalFilenamenow-ConsoleApp13.exe

        Network Behavior

        Snort IDS Alerts

        TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
        10/08/21-16:09:58.908995TCP2025019ET TROJAN Possible NanoCore C2 60B497514557192.168.2.7185.222.57.149
        10/08/21-16:10:06.551810TCP2025019ET TROJAN Possible NanoCore C2 60B497524557192.168.2.7185.222.57.149
        10/08/21-16:10:13.338507TCP2025019ET TROJAN Possible NanoCore C2 60B497734557192.168.2.7185.222.57.149
        10/08/21-16:10:18.369904TCP2025019ET TROJAN Possible NanoCore C2 60B497794557192.168.2.7185.222.57.149
        10/08/21-16:10:24.464828TCP2025019ET TROJAN Possible NanoCore C2 60B497804557192.168.2.7185.222.57.149
        10/08/21-16:10:30.480115TCP2025019ET TROJAN Possible NanoCore C2 60B497814557192.168.2.7185.222.57.149
        10/08/21-16:10:38.372617TCP2025019ET TROJAN Possible NanoCore C2 60B497824557192.168.2.7185.222.57.149
        10/08/21-16:10:44.482585TCP2025019ET TROJAN Possible NanoCore C2 60B497834557192.168.2.7185.222.57.149
        10/08/21-16:10:50.550682TCP2025019ET TROJAN Possible NanoCore C2 60B498014557192.168.2.7185.222.57.149
        10/08/21-16:10:56.622820TCP2025019ET TROJAN Possible NanoCore C2 60B498134557192.168.2.7185.222.57.149
        10/08/21-16:11:01.719619TCP2025019ET TROJAN Possible NanoCore C2 60B498144557192.168.2.7185.222.57.149
        10/08/21-16:11:07.735436TCP2025019ET TROJAN Possible NanoCore C2 60B498154557192.168.2.7185.222.57.149
        10/08/21-16:11:13.858199TCP2025019ET TROJAN Possible NanoCore C2 60B498164557192.168.2.7185.222.57.149

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        Oct 8, 2021 16:09:58.445188046 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.467081070 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:58.467223883 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.908994913 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.948772907 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:58.959141016 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:58.981297970 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:58.999886036 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.082442045 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087639093 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087661028 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087677956 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087693930 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087722063 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.087759018 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111536026 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111576080 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111620903 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111644983 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111663103 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111685038 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111686945 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111706018 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111715078 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111731052 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111737013 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.111748934 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.111763954 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133198023 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133235931 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133256912 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133275986 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133299112 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133315086 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133321047 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133342028 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133346081 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133363008 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133366108 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133383989 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133404016 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133405924 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133424997 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133440018 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133444071 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133466959 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133486986 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133491039 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133506060 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133524895 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133527994 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.133541107 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.133572102 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155138016 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155175924 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155200958 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155220032 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155237913 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155256033 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155275106 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155298948 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155323029 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155345917 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155363083 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155365944 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155390024 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155390978 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155394077 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155396938 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155414104 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155436039 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155456066 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155457973 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155482054 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155504942 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155504942 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155528069 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155560017 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155567884 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155584097 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155594110 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155610085 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155698061 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155734062 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155765057 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155786991 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155800104 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155810118 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155831099 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155853033 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155855894 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155874014 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155893087 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155908108 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155914068 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155935049 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155941963 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155960083 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.155982018 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.155982018 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.156001091 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.156023979 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178304911 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178339005 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178359985 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178383112 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178404093 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178431034 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178438902 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178455114 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178473949 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178476095 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178498030 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178519011 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178522110 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178539991 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178560019 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178565025 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178581953 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178606987 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178608894 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178632021 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178652048 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178653955 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178673983 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178695917 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178713083 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178716898 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178735018 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178752899 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178771019 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178796053 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178812027 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178813934 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178837061 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178865910 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178879023 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.178922892 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178945065 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178966999 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178987980 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.178989887 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179009914 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179014921 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179032087 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179053068 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179076910 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179080009 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179097891 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179132938 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179142952 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179166079 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179187059 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179214954 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179251909 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179261923 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179286003 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179308891 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179326057 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179347038 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179348946 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179363966 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179389954 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179392099 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179414034 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179435015 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179461002 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179476023 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179497957 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179502010 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.179519892 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179538965 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.179569960 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201317072 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201371908 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201395035 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201421022 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201443911 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201459885 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201467037 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201484919 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201493979 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201517105 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201528072 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201538086 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201558113 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201560974 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201579094 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201603889 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201606989 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201627970 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201647997 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201657057 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201669931 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201692104 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201694012 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201715946 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201761961 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201762915 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201783895 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201812029 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201817036 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201862097 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.201869011 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201894999 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201917887 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201939106 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201963902 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.201991081 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202012062 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202049017 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202071905 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202095032 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202115059 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202137947 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202140093 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202162027 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202167988 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202184916 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202207088 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202217102 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202244043 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202244997 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202266932 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202284098 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202301025 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202316999 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202333927 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202358007 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202379942 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202400923 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202420950 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202449083 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202467918 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202488899 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202507973 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202508926 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202523947 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202531099 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202552080 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202567101 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.202572107 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202586889 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.202620983 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224551916 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224582911 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224601030 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224617004 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224633932 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224652052 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224669933 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224689007 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224701881 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224704981 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224716902 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224730015 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224730015 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224750042 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224750996 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224766016 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224767923 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224786043 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224798918 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224802017 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224816084 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224833965 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224841118 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224850893 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224857092 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224864006 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224879980 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224891901 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224898100 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224904060 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224920034 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224929094 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224936008 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224946976 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224957943 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.224961996 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224980116 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.224988937 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225001097 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225017071 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225025892 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225033045 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225047112 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225059032 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225063086 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225075006 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225079060 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225099087 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225105047 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225116014 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225131035 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225147009 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225147009 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225162029 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225168943 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225178003 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225193024 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225199938 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225208998 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225234032 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225238085 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225250959 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225265980 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225285053 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225290060 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225301981 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225317001 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225317955 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225333929 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225344896 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.225347042 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.225380898 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247231960 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247283936 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247323036 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247376919 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247416019 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247451067 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247456074 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247493029 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247493982 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247534037 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247536898 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247579098 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247594118 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247617006 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247656107 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247694969 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247701883 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247733116 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247744083 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247771025 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247808933 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247853041 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247854948 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247889996 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247920036 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247934103 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247953892 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.247960091 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.247987986 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248025894 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248063087 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248075008 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248099089 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248105049 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248141050 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248173952 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248200893 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248218060 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248228073 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248244047 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248255014 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248280048 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248306036 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248320103 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248331070 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248347998 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248363972 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248394012 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248420000 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248436928 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248447895 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248465061 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248476028 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248501062 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248528957 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248543978 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248555899 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248573065 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248588085 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248617887 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248631001 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248644114 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248670101 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248697042 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248713970 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248723030 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248744011 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248760939 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248786926 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248801947 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248820066 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248842955 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248867989 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248888969 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248894930 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248920918 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248946905 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248961926 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.248974085 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.248996019 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.249000072 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249032974 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249062061 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249072075 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.249089003 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249100924 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.249115944 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249142885 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249169111 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249187946 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.249195099 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249217033 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.249222040 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249254942 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249284029 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:09:59.249298096 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.249324083 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:09:59.286514997 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:00.505369902 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:00.582973957 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:01.081789970 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:01.160643101 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:01.197211027 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:01.268606901 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:01.273061037 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:01.404055119 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:01.425709009 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:01.547303915 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:01.851687908 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:01.924982071 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:02.119013071 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:02.140748024 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:02.140830040 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:02.162915945 CEST455749751185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:02.250391006 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:02.289642096 CEST497514557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.481775999 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.504235029 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.504355907 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.551810026 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.592740059 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.615036964 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.636976957 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.640353918 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.721746922 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.853254080 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.854895115 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.921000004 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.969551086 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:06.991219044 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:06.991600990 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:07.013422012 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:07.013648987 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:07.039884090 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:07.039997101 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:07.112405062 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:07.115176916 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:07.190438986 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:07.296479940 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:07.362454891 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:08.298584938 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:08.378065109 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:08.927525997 CEST455749752185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:08.969665051 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:09.298360109 CEST497524557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.315257072 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.336702108 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.337646008 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.338506937 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.368393898 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.423259974 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.444803953 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.448911905 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.470750093 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.517009974 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.560178041 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.643660069 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.728127003 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.729103088 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.750686884 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.798269033 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.819678068 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.820065022 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.841775894 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.842304945 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:13.864140987 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:13.907618999 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:14.010519028 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:14.085700035 CEST455749773185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:14.330106974 CEST497734557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.347032070 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.368604898 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.368741035 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.369904041 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.407936096 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.408050060 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.471956015 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.472026110 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.493709087 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.494812012 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.565515995 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.663340092 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.664364100 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.685712099 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.736129999 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.757600069 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.780626059 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.802288055 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.802401066 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.824356079 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:18.876797915 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:18.934940100 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:19.002912045 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:19.393182993 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:19.471728086 CEST455749779185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:20.424706936 CEST497794557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.441729069 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.463625908 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.463826895 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.464828014 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.512686014 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.519903898 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.542283058 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.548458099 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.627964020 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.755842924 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.799253941 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.805850983 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.820830107 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.861685038 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.877991915 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.878062010 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.908303976 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.955425978 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:24.976959944 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:24.977886915 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:25.052215099 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:25.348813057 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:25.393018961 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:25.469674110 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:25.549992085 CEST455749780185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:26.440546036 CEST497804557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.457884073 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.479389906 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:30.479525089 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.480114937 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.514966011 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:30.565325022 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.581738949 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.663094044 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:30.665920973 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.688076973 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:30.737198114 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.766314983 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:30.835072994 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:30.996539116 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:31.012214899 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:31.033647060 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:31.035672903 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:31.057387114 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:31.059101105 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:31.080846071 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:31.121073008 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:31.209956884 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:31.917495012 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:31.991303921 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:33.341097116 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:33.413275957 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:34.305382013 CEST455749781185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:34.332602978 CEST497814557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.349806070 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.371367931 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.371494055 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.372617006 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.409135103 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.410535097 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.432465076 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.432622910 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.506856918 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.507038116 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.584918022 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.716922045 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.719108105 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.740734100 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.784838915 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.806246042 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.806988955 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.828732967 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.829437017 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.852670908 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:38.894128084 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.916450977 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:38.991293907 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:39.461493969 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:39.538208961 CEST455749782185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:40.442454100 CEST497824557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.458820105 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.481653929 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.481895924 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.482584953 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.521353006 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.521537066 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.600683928 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.600908995 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.626802921 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.628880978 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.710032940 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.809999943 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.811402082 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.847915888 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.894639015 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.915972948 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.917057991 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.938786030 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:44.938950062 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:44.960798025 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:45.004044056 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:45.064726114 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:45.147559881 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:45.551848888 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:45.631834984 CEST455749783185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:46.501169920 CEST497834557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.525602102 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.547059059 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.547229052 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.550682068 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.587205887 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.587388039 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.663254023 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.663597107 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.685353994 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.686827898 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.756885052 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.846043110 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.847080946 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.868319988 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.886856079 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.908359051 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.908516884 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:50.930550098 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:50.973299026 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:51.028034925 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:51.100682974 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:51.584022999 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:51.663187027 CEST455749801185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:52.584222078 CEST498014557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.599992990 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.621850014 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:56.621978998 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.622819901 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.680768013 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:56.723915100 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.746278048 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:56.764576912 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.798032045 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:56.800060987 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:56.882894993 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:57.220191956 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:57.221816063 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:57.243351936 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:57.286335945 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:57.287625074 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:57.309328079 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:57.309524059 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:57.332417965 CEST455749813185.222.57.149192.168.2.7
        Oct 8, 2021 16:10:57.380204916 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:57.676593065 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:10:57.678689003 CEST498134557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:01.694780111 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:01.717854023 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:01.718055010 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:01.719619036 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:01.803900957 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:01.807846069 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:01.808521986 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:01.830502033 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:01.832273006 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:01.913264990 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.100760937 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.123517036 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:02.145337105 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.194178104 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:02.215804100 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.216200113 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:02.255141020 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.255275965 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:02.283941031 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.284733057 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:02.350792885 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:02.695777893 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:02.772556067 CEST455749814185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:03.694515944 CEST498144557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.711828947 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.733836889 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:07.734021902 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.735435963 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.771205902 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:07.771949053 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.794641018 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:07.805156946 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.881920099 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:07.882021904 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:07.960153103 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:08.081257105 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:08.091378927 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:08.112813950 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:08.117377043 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:08.139348030 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:08.139477015 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:08.161391020 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:08.209171057 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:08.234276056 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:08.303914070 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:08.819588900 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:08.897559881 CEST455749815185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:09.819621086 CEST498154557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:13.835728884 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:13.857471943 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:13.857650995 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:13.858198881 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:13.894273996 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:13.894578934 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:13.916412115 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:13.917212963 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:13.988375902 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.088043928 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.088809967 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:14.110502005 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.162847996 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:14.184340000 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.184668064 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:14.206595898 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.206748962 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:14.237214088 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.287947893 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:14.911642075 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:14.960776091 CEST498164557192.168.2.7185.222.57.149
        Oct 8, 2021 16:11:18.896718025 CEST455749816185.222.57.149192.168.2.7
        Oct 8, 2021 16:11:18.944417953 CEST498164557192.168.2.7185.222.57.149

        Code Manipulations

        Statistics

        CPU Usage

        Click to jump to process

        Memory Usage

        Click to jump to process

        High Level Behavior Distribution

        Click to dive into process behavior distribution

        Behavior

        Click to jump to process

        System Behavior

        General

        Start time:16:09:09
        Start date:08/10/2021
        Path:C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe
        Wow64 process (32bit):true
        Commandline:'C:\Users\user\Desktop\Peixoto - QUOTATION LIST.exe'
        Imagebase:0x20000
        File size:1203200 bytes
        MD5 hash:0F129AA97048F7EC0557B211349A2CE0
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:.Net C# or VB.NET
        Yara matches:
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.331468267.000000000352B000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.331768876.00000000035CA000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.332453140.00000000036CA000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, Author: Florian Roth
        • Rule: NanoCore, Description: unknown, Source: 00000000.00000002.330874333.0000000002449000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        Reputation:low

        General

        Start time:16:09:53
        Start date:08/10/2021
        Path:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Wow64 process (32bit):false
        Commandline:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Imagebase:0x10000
        File size:1203200 bytes
        MD5 hash:0F129AA97048F7EC0557B211349A2CE0
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Antivirus matches:
        • Detection: 100%, Joe Sandbox ML
        • Detection: 26%, Virustotal, Browse
        Reputation:low

        General

        Start time:16:09:53
        Start date:08/10/2021
        Path:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Wow64 process (32bit):true
        Commandline:C:\Users\user\AppData\Local\Temp\Peixoto - QUOTATION LIST.exe
        Imagebase:0xeb0000
        File size:1203200 bytes
        MD5 hash:0F129AA97048F7EC0557B211349A2CE0
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:.Net C# or VB.NET
        Yara matches:
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507935886.0000000007200000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.508012010.0000000007240000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507918779.00000000071F0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.508028677.0000000007250000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.502803015.000000000345F000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507861382.00000000071D0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.505140332.0000000004437000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.506764545.0000000005CB0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507701529.0000000007170000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.497755666.0000000000402000.00000040.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507798744.00000000071B0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.508130383.0000000007290000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507974739.0000000007220000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507735759.0000000007180000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.505641453.00000000046D8000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.507029930.0000000006660000.00000004.00020000.sdmp, Author: Joe Security
        • Rule: JoeSecurity_Nanocore, Description: Yara detected Nanocore RAT, Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, Author: Joe Security
        • Rule: NanoCore, Description: unknown, Source: 00000010.00000002.502657660.00000000033E1000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507958323.0000000007210000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Gen_2, Description: Detetcs the Nanocore RAT, Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, Author: Florian Roth
        • Rule: Nanocore_RAT_Feb18_1, Description: Detects Nanocore RAT, Source: 00000010.00000002.507891553.00000000071E0000.00000004.00020000.sdmp, Author: Florian Roth
        Reputation:low

        Disassembly

        Code Analysis

        Reset < >

          Executed Functions

          Strings
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID: X~t
          • API String ID: 0-2067416903
          • Opcode ID: b548c87e053b137c10948a9e081a6d751edcce63dc7108a420c592b40a67dd54
          • Instruction ID: a7cab281579641078a88b7e80380a0680b5e669d839bee3b67a04981038ebe30
          • Opcode Fuzzy Hash: b548c87e053b137c10948a9e081a6d751edcce63dc7108a420c592b40a67dd54
          • Instruction Fuzzy Hash: 89E1A430608654CFD724CF28D494BA6B7F5FB44344F1089AEE84E8BB91C739D999CB92
          Uniqueness

          Uniqueness Score: -1.00%

          Strings
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID: {z}
          • API String ID: 0-1552007774
          • Opcode ID: 55b9cb582a674a10ee59308af2171d0138654a14b8f795ece7c2ebb3bc8a35f0
          • Instruction ID: 3ecabf66634c0ad4d4fa776691c3ef5bb7f11d15fd9bef720f4d1ba246c7fdbf
          • Opcode Fuzzy Hash: 55b9cb582a674a10ee59308af2171d0138654a14b8f795ece7c2ebb3bc8a35f0
          • Instruction Fuzzy Hash: DE91C870A04214CFCB14DBA8C454F9EBBF6FF89304F54896AD80AEB691CB789D42CB55
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: f727ff9de261ac82c03d3ba7df57b8f28eee75952019ae3b74d785c6f45fd55f
          • Instruction ID: ac3445810c97502ab6e6df0c29fe431ad417429ac20876aa22d29d83d0664306
          • Opcode Fuzzy Hash: f727ff9de261ac82c03d3ba7df57b8f28eee75952019ae3b74d785c6f45fd55f
          • Instruction Fuzzy Hash: C8C1E470914258CFDB09CFA8C495BEDBFB1FF51304F51859ACA0A9B682D734E986CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 4ab5088b148490db60632364363c9af91358582975309f9c32851653f139119c
          • Instruction ID: 287769ac716488db6d6e9d06a9d1e7f531d65a730fcce6a567ab669dc8ae0a4b
          • Opcode Fuzzy Hash: 4ab5088b148490db60632364363c9af91358582975309f9c32851653f139119c
          • Instruction Fuzzy Hash: F3C1F270918258CFDB08CF98C495BEDBBB1FF51304F51859ACA0A9B692D734E9C2CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 8dc12eea24c3b07860bc3f4dc92fcc6cc9f2e20eb53dc24c741ee0c91bcb3457
          • Instruction ID: 3829fcfa852d88035d816fac3d3855c8195c0d6be4a5f0800301ef4e9384fb61
          • Opcode Fuzzy Hash: 8dc12eea24c3b07860bc3f4dc92fcc6cc9f2e20eb53dc24c741ee0c91bcb3457
          • Instruction Fuzzy Hash: C3B1D270914258CFDB08CF98C495BADBFB1FF51304F55859ACA0A9B692D734E9C2CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 6cb58a65f8b3e6ee75bcf4e9bdda9eda4f69074dac5a79d6bd16332a2898505c
          • Instruction ID: 2a92c51a0e44245979dfabb486f4755c2896ec5eeffaefdc7bbc269aaf213e86
          • Opcode Fuzzy Hash: 6cb58a65f8b3e6ee75bcf4e9bdda9eda4f69074dac5a79d6bd16332a2898505c
          • Instruction Fuzzy Hash: DBB1D170914258CFDB08CFA8C495BEDBBB1FF51304F55859ACA0A9B682D734E9C2CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: a7af3fc3c2bd0b6048052aeb1a62841d9e4d8fb0722d0c961254f7c62a963651
          • Instruction ID: 86878d72565c6e32426120b5fbb3005acd8ed70b53a54c4c73bb870bec967051
          • Opcode Fuzzy Hash: a7af3fc3c2bd0b6048052aeb1a62841d9e4d8fb0722d0c961254f7c62a963651
          • Instruction Fuzzy Hash: 48B1D370914258CFDB08CFA8C495BEDBFB1FF51304F55859AC94A9B682D334E986CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: d9cd5f86f3606465efbfe24b90a7b7d27772afc7149296f874a4a1f1f0360ba3
          • Instruction ID: a2122ceaf0a734a6a67f0227c4d18be84a6cc61a1ab0d0e977ec5948090749f9
          • Opcode Fuzzy Hash: d9cd5f86f3606465efbfe24b90a7b7d27772afc7149296f874a4a1f1f0360ba3
          • Instruction Fuzzy Hash: 27B1B170918258CFDB08CF98C095BADBFB1FF51304F55859ACA4A9B692D734E9C2CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 6214a915a92335c8a22f247c507c10df61df36ed8726882fd1c696605635a790
          • Instruction ID: 816c057922a131000ce4ed26513ac28d2d24320d584257e4a93ca883e914c43f
          • Opcode Fuzzy Hash: 6214a915a92335c8a22f247c507c10df61df36ed8726882fd1c696605635a790
          • Instruction Fuzzy Hash: A9B1C070914258CFDB08CFA8C495BEDBBB1FF51304F51859ACA0A9B692D334E9C6CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 2ef9d0f8bb477f5ca178c5ad5e9fe78b4857e4df1b559746a17b8b1c7fadad07
          • Instruction ID: b9ab7743ec3445b7525a1e683d9ae732f1416d66875f5bbcec3d51fba9cb28c6
          • Opcode Fuzzy Hash: 2ef9d0f8bb477f5ca178c5ad5e9fe78b4857e4df1b559746a17b8b1c7fadad07
          • Instruction Fuzzy Hash: 4BB1B170914258CFDB08CFA8C495BEDBBB1FF51304F55859ACA0A9B682D734E9C6CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 80e70d1740eea611a8f557f09496329860e244b839d5d2636df460ec3bde10e0
          • Instruction ID: 6d444ececd412b3c9a7048054ec30f6f0cf0db5315d37c370c01400f777de766
          • Opcode Fuzzy Hash: 80e70d1740eea611a8f557f09496329860e244b839d5d2636df460ec3bde10e0
          • Instruction Fuzzy Hash: 08B1C070914258CFDB08CFA8C095BADBFB1FF51304F55859ACA0A9B692D334E9C6CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 4e4f93709fbb079e463e4b99d1e3eb018511db9ee40ba9bf53f67d1a534cd29b
          • Instruction ID: 4db220ac057d56447fab91c86b1e3e17d933ec53ad929c2ac38acd8817a6196d
          • Opcode Fuzzy Hash: 4e4f93709fbb079e463e4b99d1e3eb018511db9ee40ba9bf53f67d1a534cd29b
          • Instruction Fuzzy Hash: 47B1D070914258CFDB08CFA8C495BADBFB1FF51304F51859ACA0A9B682D334E9C2CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 1e3bc67dff22e8cc36270535cba690d44d37197b351dcba89722e13a3dcf8096
          • Instruction ID: 763de6886242fce6c200d7e58c3b27b3e56e25487b06aedd4223a4971b6c2f56
          • Opcode Fuzzy Hash: 1e3bc67dff22e8cc36270535cba690d44d37197b351dcba89722e13a3dcf8096
          • Instruction Fuzzy Hash: AEB1C270914258CFDB08CFA8C495BEDBFB1FF51304F55859ACA0A9B682D734E986CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 7c7c6caac28b73dc280e002fae620f68d6d05b8132252501f96a148d7ab17f1e
          • Instruction ID: 941998c254a760b9d6b8c4254995fff2e8008a5141b7126708ef3ef183944310
          • Opcode Fuzzy Hash: 7c7c6caac28b73dc280e002fae620f68d6d05b8132252501f96a148d7ab17f1e
          • Instruction Fuzzy Hash: CEB1C070914258CFDB08CFA8C095BEDBFB1FF51304F51859AC90A9B692D734E986CB81
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 651cb06ec0de247d797ab0948d700f85ce4354ae4a8a246896879743ceba9ff6
          • Instruction ID: b7e04a5f3146dff719209552c1fb8dd0b0c2979d509a403f70fb01253ac10ff3
          • Opcode Fuzzy Hash: 651cb06ec0de247d797ab0948d700f85ce4354ae4a8a246896879743ceba9ff6
          • Instruction Fuzzy Hash: A8A1E170918258CFDB08CFA4C495BEDBFB1FF51304F55859ACA4A9B682D734E982CB81
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateProcessA.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 0235929E
          Strings
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: CreateProcess
          • String ID: q
          • API String ID: 963392458-4110462503
          • Opcode ID: 82bd17f16d474e8fd18c4957d1518f080e86fd728abad64d5f3f6a10675c771c
          • Instruction ID: 7c80584bb38e69c3b57c3d60530ae5f1b57506dde57fe2bb86adcd61761b9725
          • Opcode Fuzzy Hash: 82bd17f16d474e8fd18c4957d1518f080e86fd728abad64d5f3f6a10675c771c
          • Instruction Fuzzy Hash: BBA14B71D00669CFDB10CFA8C885BEDBBB2BB48304F1485A9DC19A7290D7749A86CF91
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CopyFileW.KERNELBASE(?,00000000,?), ref: 02357221
          Strings
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: CopyFile
          • String ID: 8^0m
          • API String ID: 1304948518-2663131134
          • Opcode ID: 3a84995ae9cd26a94f62f0277a2b69346809604540a9f1c2b4ad662dd613178b
          • Instruction ID: d1292c0bac12f08d3d85d7b3ae5cff5fe1f4b9440aeeeadfb65e7af08a05baeb
          • Opcode Fuzzy Hash: 3a84995ae9cd26a94f62f0277a2b69346809604540a9f1c2b4ad662dd613178b
          • Instruction Fuzzy Hash: B161D275B141208FCB10DF68D488EADB7F6AF48324F158169E90ADB3A2DB35DC42CB91
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateProcessA.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 0235929E
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: CreateProcess
          • String ID:
          • API String ID: 963392458-0
          • Opcode ID: 122c30fcf967d45846843a0587bc97bd3d7853082a18ebdc9489b6277666604e
          • Instruction ID: f75ae5da4be949520b6eee65ea7a018d8c67ec7747708f37ba9f626933f91fe1
          • Opcode Fuzzy Hash: 122c30fcf967d45846843a0587bc97bd3d7853082a18ebdc9489b6277666604e
          • Instruction Fuzzy Hash: 87914B71D00229CFDB10CFA8C885BEDBBB2BF48314F0485A9DC19A7290DB749A85CF91
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • K32GetModuleBaseNameA.KERNEL32(?,?,?,?), ref: 0235B249
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: BaseModuleName
          • String ID:
          • API String ID: 595626670-0
          • Opcode ID: 691b29a2f09a86d6f2fc8b038d38ccf9fb12d3aae9615ea544d5ac24199ce59f
          • Instruction ID: e9d17d211dd99ad1e7b6d3d52c807e6a2266f5c80c123e597cf61bca5a44b146
          • Opcode Fuzzy Hash: 691b29a2f09a86d6f2fc8b038d38ccf9fb12d3aae9615ea544d5ac24199ce59f
          • Instruction Fuzzy Hash: CC4146B0D006688FDB04CFA9C894BDEFBF2BF48318F148129E819AB254D7749945CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • K32GetModuleBaseNameA.KERNEL32(?,?,?,?), ref: 0235B249
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: BaseModuleName
          • String ID:
          • API String ID: 595626670-0
          • Opcode ID: 8dd84003f057a67e4f15adeeb0158051e60acbf90ae087f91a834617c1aed549
          • Instruction ID: 7c41cb1a0e076ea2a7adf8c7a0b016f2491efa3271e44194ab1ae70d26234c4a
          • Opcode Fuzzy Hash: 8dd84003f057a67e4f15adeeb0158051e60acbf90ae087f91a834617c1aed549
          • Instruction Fuzzy Hash: 1A4157B0D002188FDB04CFA9C894BDEFBF2BF48318F148129E819AB254D7749945CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • VirtualProtect.KERNELBASE(?,?,?,?), ref: 02356C1B
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ProtectVirtual
          • String ID:
          • API String ID: 544645111-0
          • Opcode ID: 8ceb67d65a94f3abdc76bded1385353dcf990daf5b6d91fc93616c38ae32be35
          • Instruction ID: 9337817daf7cdc8dc542ae20694d20230589884b830128e866a55294c7fa0846
          • Opcode Fuzzy Hash: 8ceb67d65a94f3abdc76bded1385353dcf990daf5b6d91fc93616c38ae32be35
          • Instruction Fuzzy Hash: 2A2180B2900628CFEB10CF99D846BEEB7BCEB44315F408435D919A7151D339A599CF51
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CopyFileW.KERNELBASE(?,00000000,?), ref: 02357221
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: CopyFile
          • String ID:
          • API String ID: 1304948518-0
          • Opcode ID: 9b9bd4a137b1d1ec25a2ee046a423ad63442bc38c04b38e021edcd68d0baafa5
          • Instruction ID: d080c098a9db7e54bad4f1773d52c5661a1fd46ff1913e53ee4924cf8a829d57
          • Opcode Fuzzy Hash: 9b9bd4a137b1d1ec25a2ee046a423ad63442bc38c04b38e021edcd68d0baafa5
          • Instruction Fuzzy Hash: 9D2137B5D012199FCB50CFA9D884BEEFBF5AF48310F14816AE808AB241D7349A45CFA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 02358F50
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: MemoryProcessWrite
          • String ID:
          • API String ID: 3559483778-0
          • Opcode ID: a97ddabfe29cba1c592a9fe3e77e59a165920ee8d7128113b865d0a6bcf24e38
          • Instruction ID: eb631db84779ee45554584778558931e752fb99bea65164a9509a9512d2020d6
          • Opcode Fuzzy Hash: a97ddabfe29cba1c592a9fe3e77e59a165920ee8d7128113b865d0a6bcf24e38
          • Instruction Fuzzy Hash: 0D215CB59003599FCF10CFA9D884BEEBBF6FF48314F148429E919A7240C7789945CBA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • LoadLibraryA.KERNELBASE(?), ref: 023569E1
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: LibraryLoad
          • String ID:
          • API String ID: 1029625771-0
          • Opcode ID: 5f6298f51b5ebad6c8bc3c2ed6e2e6b9fe30c138f94397d52d689a2ecc04a8f0
          • Instruction ID: 9c577b96500d3f92581cee6a61f0fd63692c5a55715a7d56f662e74cda915cee
          • Opcode Fuzzy Hash: 5f6298f51b5ebad6c8bc3c2ed6e2e6b9fe30c138f94397d52d689a2ecc04a8f0
          • Instruction Fuzzy Hash: 8431E2B4D01208DFDB14CF99D584BCEBBF9AF48318F248469E409AB350DB756985CF94
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CopyFileW.KERNELBASE(?,00000000,?), ref: 02357221
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: CopyFile
          • String ID:
          • API String ID: 1304948518-0
          • Opcode ID: 0d1fa67498d0c7fa65f21a953b08c59f3d1b9258053fc457536deac0fafaad98
          • Instruction ID: 1ed9be2bbd91be00181580162e1867a6049d4c29ba0f68ee4b62633d04ec77bc
          • Opcode Fuzzy Hash: 0d1fa67498d0c7fa65f21a953b08c59f3d1b9258053fc457536deac0fafaad98
          • Instruction Fuzzy Hash: C0212BB5D012199FCB50CF99D984BEEFBF5AF48310F14816AE808A7245D7349A45CBA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 02358F50
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: MemoryProcessWrite
          • String ID:
          • API String ID: 3559483778-0
          • Opcode ID: 5e36bc7da0cec6db2991ecf674fe674cd21ab6f68b4d53d8c7a05d40e7203811
          • Instruction ID: 43515f224a78233e20f8114b53fca7c3edbcc6f460d664952b1b361b860b7780
          • Opcode Fuzzy Hash: 5e36bc7da0cec6db2991ecf674fe674cd21ab6f68b4d53d8c7a05d40e7203811
          • Instruction Fuzzy Hash: CA2127B59003599FCF10CFA9D884BEEBBF5FF48314F14882AE919A7240C7789954CBA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • EnumChildWindows.USER32(?,00000000,?), ref: 0235B5B8
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ChildEnumWindows
          • String ID:
          • API String ID: 3555792229-0
          • Opcode ID: 5d2bbf431882d0f19813db71c9fe3ac00c2ebd3ba74ff925622ce2fd076c3571
          • Instruction ID: c49018735e7fe0f4e03efb08028a74537738f8c267e289fc3922746285a75e66
          • Opcode Fuzzy Hash: 5d2bbf431882d0f19813db71c9fe3ac00c2ebd3ba74ff925622ce2fd076c3571
          • Instruction Fuzzy Hash: 3321CF719042198FCB10CFA9C844BEEFBF6FF88324F04886AD458A7291C734A945CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SetThreadContext.KERNELBASE(?,00000000), ref: 02358DA6
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ContextThread
          • String ID:
          • API String ID: 1591575202-0
          • Opcode ID: 785bf1e2664d1a2e519bc0a90a9c8cfd66a20b8743179a768746485a9d130661
          • Instruction ID: 51a4f8f3c3ae121ce90341851d72b1e9b041566369b6196f24dee9716727b75c
          • Opcode Fuzzy Hash: 785bf1e2664d1a2e519bc0a90a9c8cfd66a20b8743179a768746485a9d130661
          • Instruction Fuzzy Hash: 93213AB5D002198FDB50DFA9C884BEEBBF5EF58314F14842ED919A7240CB789949CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • ReadProcessMemory.KERNELBASE(?,?,?,?,?), ref: 02359528
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: MemoryProcessRead
          • String ID:
          • API String ID: 1726664587-0
          • Opcode ID: 0f3a6568e60ee3169f9b4ae4a76d4b33107f27deedfe0f8a035ad30c499e9e7e
          • Instruction ID: f1637aad2fcd1dc7c85f876dbec2a2172945d5add650683d5c577bb2a2bcf001
          • Opcode Fuzzy Hash: 0f3a6568e60ee3169f9b4ae4a76d4b33107f27deedfe0f8a035ad30c499e9e7e
          • Instruction Fuzzy Hash: C72134B5D002598FCB00CFA9D884BEEBBF5FF48314F14882AE919A7240C7389955CBA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • ReadProcessMemory.KERNELBASE(?,?,?,?,?), ref: 02359528
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: MemoryProcessRead
          • String ID:
          • API String ID: 1726664587-0
          • Opcode ID: eb24f22262da6af263491647c45675336f4db26e962935445f639e540b9553b0
          • Instruction ID: 263e0c445876a208fd049a3a25ccd0d996a60c14cc81ffafb848e8fa480421f1
          • Opcode Fuzzy Hash: eb24f22262da6af263491647c45675336f4db26e962935445f639e540b9553b0
          • Instruction Fuzzy Hash: 7A212AB59002199FCF00CFA9D884BEEFBF5FF48314F148829D519A7240D7789955CBA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • EnumChildWindows.USER32(?,00000000,?), ref: 0235B5B8
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ChildEnumWindows
          • String ID:
          • API String ID: 3555792229-0
          • Opcode ID: f10994e908cbddd2b93c3a4c89c93f97c388af32bc998ce10f5aaf85a7b57f49
          • Instruction ID: d7f28bbed22e23acbd450ff3cc2112766b8f8b299d9fa30c99dff6969c6892c9
          • Opcode Fuzzy Hash: f10994e908cbddd2b93c3a4c89c93f97c388af32bc998ce10f5aaf85a7b57f49
          • Instruction Fuzzy Hash: E2214C759002198FDB14CF9AC944BEEFBF6FF48324F148429D419A3250D774A945CFA5
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SetThreadContext.KERNELBASE(?,00000000), ref: 02358DA6
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ContextThread
          • String ID:
          • API String ID: 1591575202-0
          • Opcode ID: f5f96970501ba04ba2b6179d7082a76815b961aef8e02e47b0b07cafe7a44610
          • Instruction ID: 731378b0ad29df497939a210964baa8b133d461bf5805ddac74ca1440426fe04
          • Opcode Fuzzy Hash: f5f96970501ba04ba2b6179d7082a76815b961aef8e02e47b0b07cafe7a44610
          • Instruction Fuzzy Hash: A8213875D002198FDB10DFAAC484BEEBBF5AF48218F14842AD919A7240DB789945CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • EnumChildWindows.USER32(?,00000000,?), ref: 0235B5B8
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ChildEnumWindows
          • String ID:
          • API String ID: 3555792229-0
          • Opcode ID: 697725753e4bb4f886a6b53896c7ffc7001810c8bc213d3b72b7bb0ef7f9f779
          • Instruction ID: 4f4b0811bddcadbe92e63aa8498e60cafcaef982c0260b9735e0b4a26287d7a0
          • Opcode Fuzzy Hash: 697725753e4bb4f886a6b53896c7ffc7001810c8bc213d3b72b7bb0ef7f9f779
          • Instruction Fuzzy Hash: 2E2149B19042198FDB14CF9AC944BEEFBF6FF88314F148829E519A3250D778A945CFA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • K32EnumProcesses.KERNEL32(00000000,?,?), ref: 0235AD9B
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: EnumProcesses
          • String ID:
          • API String ID: 84517404-0
          • Opcode ID: 32147a472195ea34116c87593f9007ddc85412ce155f8a9cb219916d8e3ae005
          • Instruction ID: f25d0e8e01fede4047cfc792d70ca06699ba9e357daa9e88af3dce8ca6e204b2
          • Opcode Fuzzy Hash: 32147a472195ea34116c87593f9007ddc85412ce155f8a9cb219916d8e3ae005
          • Instruction Fuzzy Hash: E92107B5D016199FCB00CF99D884BEEFBF4BF48314F14826AE918A7240D7749944CFA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • K32EnumProcesses.KERNEL32(00000000,?,?), ref: 0235AD9B
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: EnumProcesses
          • String ID:
          • API String ID: 84517404-0
          • Opcode ID: 15b062af45dd6aaf000d4178cf2361f2accd56aaf3fa1f2ec1463fcb118fa961
          • Instruction ID: 0c5be99cc2d510f1a2dcdd3eb861e9083c8a0c412338d7adb9044c65d2cfd9ac
          • Opcode Fuzzy Hash: 15b062af45dd6aaf000d4178cf2361f2accd56aaf3fa1f2ec1463fcb118fa961
          • Instruction Fuzzy Hash: 852107B5D006199FCB00CF99D884BDEFBF4BB48314F04822AE918A7240D774A9448FA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • K32EnumProcessModules.KERNEL32(?,?,?,?), ref: 0235B0F3
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: EnumModulesProcess
          • String ID:
          • API String ID: 1082081703-0
          • Opcode ID: 5b7eaf8f533bc4d5e83f1710fbcefe0a0db21f7b9e1713129cfd48a8080a74c2
          • Instruction ID: 6f6232d60e7bfb2eec8878f5b7441b11dc681a370e976965a73e5be2495bc200
          • Opcode Fuzzy Hash: 5b7eaf8f533bc4d5e83f1710fbcefe0a0db21f7b9e1713129cfd48a8080a74c2
          • Instruction Fuzzy Hash: 702115B69002099FCB10CF9AC484BDEFBF5FF48324F148469E958A7240D779A945CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • VirtualProtect.KERNELBASE(?,?,?,?), ref: 02356C1B
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ProtectVirtual
          • String ID:
          • API String ID: 544645111-0
          • Opcode ID: a165cfd285ed2ee148c608e8065893e9c8cdb006af7d6db099f0d012a914f0e1
          • Instruction ID: e5dec487be97f4f68240694570607a4015739bb17181bca7baf344b011318086
          • Opcode Fuzzy Hash: a165cfd285ed2ee148c608e8065893e9c8cdb006af7d6db099f0d012a914f0e1
          • Instruction Fuzzy Hash: 622124B59006499FCB10CF9AC884BEEBBF4FB48324F108469E859A7250D378A645CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • K32EnumProcessModules.KERNEL32(?,?,?,?), ref: 0235B0F3
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: EnumModulesProcess
          • String ID:
          • API String ID: 1082081703-0
          • Opcode ID: 5adc8738caa7352e29d53c2ada5193238de1ba639c06a74b4f76a3eefe73e09b
          • Instruction ID: 3a38b0e8b22e44919be037605ee6e5e7c67b0b9d8df8c8e2984bd4b5a1f6bfde
          • Opcode Fuzzy Hash: 5adc8738caa7352e29d53c2ada5193238de1ba639c06a74b4f76a3eefe73e09b
          • Instruction Fuzzy Hash: C82106B59006099FCB10CF9AC484BDEFBF5FF48324F148429E959A7240D779A945CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • VirtualProtect.KERNELBASE(?,?,?,?), ref: 02356C1B
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ProtectVirtual
          • String ID:
          • API String ID: 544645111-0
          • Opcode ID: 113e7404e93a06c36a6bc44b1894d1e34d2f5d78b77392bcc042165d4ca2d2b3
          • Instruction ID: 959e6e573777bc0a7e439d45a98adf7c22e85896ba27617d3563a76843558207
          • Opcode Fuzzy Hash: 113e7404e93a06c36a6bc44b1894d1e34d2f5d78b77392bcc042165d4ca2d2b3
          • Instruction Fuzzy Hash: D82126B59006099FCB10CF9AC984BDEFBF8FF48324F108429E958A7240D378A545CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 02358E6E
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: AllocVirtual
          • String ID:
          • API String ID: 4275171209-0
          • Opcode ID: 0a9c52f99dace78ea17f48e6c7e9340e1ad9602da99e88bc6fb8f3b9ed58b2a8
          • Instruction ID: 4a9ecd2efa43944b9ace1a8adddb254b0241c64099763e2675a97c8e0226e8ab
          • Opcode Fuzzy Hash: 0a9c52f99dace78ea17f48e6c7e9340e1ad9602da99e88bc6fb8f3b9ed58b2a8
          • Instruction Fuzzy Hash: 041179759002498FDF10CFA9D844BEFBBF6EF88318F14882AD519A7250C7799945CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 02358E6E
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: AllocVirtual
          • String ID:
          • API String ID: 4275171209-0
          • Opcode ID: 987ffd571b222b66c0ca96cb241d59aafc458d6a9b00f2b7d2be8fb956ffd357
          • Instruction ID: c2d78c1ef534c69719bbb151731566abf5f3cc367639e0653c122bceb54e561e
          • Opcode Fuzzy Hash: 987ffd571b222b66c0ca96cb241d59aafc458d6a9b00f2b7d2be8fb956ffd357
          • Instruction Fuzzy Hash: 961137759002499FCF10CFAAC844BEFBBFAEF48328F148819D519A7250C7759954CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ResumeThread
          • String ID:
          • API String ID: 947044025-0
          • Opcode ID: 9182669f59a15cdffeb219e1cf8dec0df989b219bcfa216ba66ab563d599580d
          • Instruction ID: 0a706bec3ceb24d01e19b3762a58447c1471890f864c50572cd6b794e07e0a12
          • Opcode Fuzzy Hash: 9182669f59a15cdffeb219e1cf8dec0df989b219bcfa216ba66ab563d599580d
          • Instruction Fuzzy Hash: F71158B5D002598FDB10DFA9D8447EFFBF6AF88218F14882AC419A7240C779A945CF94
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • FindCloseChangeNotification.KERNELBASE ref: 0235B357
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ChangeCloseFindNotification
          • String ID:
          • API String ID: 2591292051-0
          • Opcode ID: de4e4c343e795e7bb53d7a4591f0e9cdfd759d2ea6ed1f70c6fd8fe31ad0065a
          • Instruction ID: 6c021fc5f97668d326490c975a41144d06f569e0d72505c4a381e89d4384d656
          • Opcode Fuzzy Hash: de4e4c343e795e7bb53d7a4591f0e9cdfd759d2ea6ed1f70c6fd8fe31ad0065a
          • Instruction Fuzzy Hash: 321158B58006198FCB10CF9AC444BEEFBF5AF48328F148469D518B7240D738A945CFA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • FindCloseChangeNotification.KERNELBASE ref: 0235B357
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ChangeCloseFindNotification
          • String ID:
          • API String ID: 2591292051-0
          • Opcode ID: d3d0b20c4d080e9ab8099d17e3243a502137610759160785e1fe98d2ddc09f59
          • Instruction ID: bb6964ea3b9ed943e99c2eeff949c1ee2784a5304e4b318548be241c32b1fe1f
          • Opcode Fuzzy Hash: d3d0b20c4d080e9ab8099d17e3243a502137610759160785e1fe98d2ddc09f59
          • Instruction Fuzzy Hash: 381136B58006198FCB10CF9AC444BEEFBF9EF48328F14886AD518B7240D778A945CFA5
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID: ResumeThread
          • String ID:
          • API String ID: 947044025-0
          • Opcode ID: e5cb5f9b7f83d7c489c0dd1a442c22a93f7371c170887fa7cf571be285a2c9f4
          • Instruction ID: f5d008e33fd8dde2cf2035384a49170baf549e8f65184b388cf44636c2089c70
          • Opcode Fuzzy Hash: e5cb5f9b7f83d7c489c0dd1a442c22a93f7371c170887fa7cf571be285a2c9f4
          • Instruction Fuzzy Hash: A3113AB5D002598FDB10DFAAC4447EFFBF9AF48228F148859C519A7240C779A945CF94
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330203208.000000000071D000.00000040.00000001.sdmp, Offset: 0071D000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 3ca4f0b18791e23c4a9c69df62d6d499550d75f6dbc4b31d478221c9762c0d88
          • Instruction ID: 698ee2af5d805029cfe849c9ec25d7b953aac1af350fcf5486d9004203479b22
          • Opcode Fuzzy Hash: 3ca4f0b18791e23c4a9c69df62d6d499550d75f6dbc4b31d478221c9762c0d88
          • Instruction Fuzzy Hash: 572108B5504244DFDB20DF18D5C4BA6BBA9FBC8714F24C569D8494B281C33EDC87CA61
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000000.00000002.330203208.000000000071D000.00000040.00000001.sdmp, Offset: 0071D000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: fabee74a0debb7bec119389b1670c8dcca565360048185edcea793448a0ba982
          • Instruction ID: 0d020ad19d8611a74a308d22e8b63723585c16ef77c1c2549b78d716b3ea4c7f
          • Opcode Fuzzy Hash: fabee74a0debb7bec119389b1670c8dcca565360048185edcea793448a0ba982
          • Instruction Fuzzy Hash: 1211E375508684CFCB21DF14D6C4B56FB71FB89324F24C6AAC8484B682C33AD84BCB92
          Uniqueness

          Uniqueness Score: -1.00%

          Non-executed Functions

          Strings
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID: X~t
          • API String ID: 0-2067416903
          • Opcode ID: 7599da8426cb20faa8474a055c6e53683705f3458e651ee2cf1350c53c3cba6d
          • Instruction ID: 7db50d9c9c9c625b65e26923a52658c3a17b0524ceac73598a1926b1b2f7578c
          • Opcode Fuzzy Hash: 7599da8426cb20faa8474a055c6e53683705f3458e651ee2cf1350c53c3cba6d
          • Instruction Fuzzy Hash: 353189A792D2E00BD7034F3454B77E37FB19E6B52438A04DAC8C4AE887E549D92BC784
          Uniqueness

          Uniqueness Score: -1.00%

          Strings
          Memory Dump Source
          • Source File: 00000000.00000002.330686363.0000000002350000.00000040.00000001.sdmp, Offset: 02350000, based on PE: false
          Similarity
          • API ID:
          • String ID: X~t
          • API String ID: 0-2067416903
          • Opcode ID: 6c0c35f44543210b7df02efedbc9ac2b76543fb8c7a5fba5bbb802885ef7dd23
          • Instruction ID: 963baa11daa3f785915f2e8d3d410e0dfae08074a487abf3cbf1c84e14c09b8d
          • Opcode Fuzzy Hash: 6c0c35f44543210b7df02efedbc9ac2b76543fb8c7a5fba5bbb802885ef7dd23
          • Instruction Fuzzy Hash: 2E2128F29281548FDB05CF68C4957EABFB5AFA9300FC1849AD949C6142E634E583CB50
          Uniqueness

          Uniqueness Score: -1.00%

          Executed Functions

          APIs
          • GetModuleHandleW.KERNELBASE(00000000), ref: 058E962E
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: HandleModule
          • String ID:
          • API String ID: 4139908857-0
          • Opcode ID: 035ebcc89d4ddcd8a8a1837aa3c0fb14f80b0165845c2e2d3f49a8e353239781
          • Instruction ID: 6792d40f9025895e68b99fc4e20a679eb812fbddfba5f38f5dd31f7677c554a0
          • Opcode Fuzzy Hash: 035ebcc89d4ddcd8a8a1837aa3c0fb14f80b0165845c2e2d3f49a8e353239781
          • Instruction Fuzzy Hash: F5712970A00B058FDB24DF6AC4457AABBF6BF89214F008A2DD846DBB50D774E845CF91
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 058EFD0A
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: CreateWindow
          • String ID:
          • API String ID: 716092398-0
          • Opcode ID: 691273ee6982361d69d6ae1855f5484330ace746ce17c275a7484edfdc75825f
          • Instruction ID: 1e40fd7dd23beeb2ad4b61f9582501788ac5340c381b1dfeb2eb7252b438d43e
          • Opcode Fuzzy Hash: 691273ee6982361d69d6ae1855f5484330ace746ce17c275a7484edfdc75825f
          • Instruction Fuzzy Hash: 6F511371D04249AFDF01CFA9C880ADEBFB6FF49314F14816AE908AB220D7759955CF90
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 058EFD0A
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: CreateWindow
          • String ID:
          • API String ID: 716092398-0
          • Opcode ID: e9f14e9cd8b83665aef147de0b2b455dd9f6bca41da9e4059fb3757942c54ac7
          • Instruction ID: 6bc497cfa70bf69271597f6f8ca82721bb55f955394966c3562d8996acfb064a
          • Opcode Fuzzy Hash: e9f14e9cd8b83665aef147de0b2b455dd9f6bca41da9e4059fb3757942c54ac7
          • Instruction Fuzzy Hash: 8251CDB1D04308AFDB14CFA9C884ADEBBB6BF49314F24852AE919AB210D7749945CF90
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,058EBCC6,?,?,?,?,?), ref: 058EBD87
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: DuplicateHandle
          • String ID:
          • API String ID: 3793708945-0
          • Opcode ID: e165443fec101e4b5b2cad20c53c677d5cb33ee4d67fff03f196fe7a9b2634d0
          • Instruction ID: 15c708f3f28f637c1d8814db20831edf421442793467bfd827078f185c3e4b3b
          • Opcode Fuzzy Hash: e165443fec101e4b5b2cad20c53c677d5cb33ee4d67fff03f196fe7a9b2634d0
          • Instruction Fuzzy Hash: FF418CB8A00644DFEB019F61E886BBA7BB9FB49301F104269EA519B3C6DB384C40DF11
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateActCtxA.KERNEL32(?), ref: 05A346B1
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: Create
          • String ID:
          • API String ID: 2289755597-0
          • Opcode ID: 4852fbf894ae1064c3f142933c5bb175f641dd7957aa56a7b8a46894b0ad1be1
          • Instruction ID: c9e9ca58e793e1fcf8d4b3679bf78fc8af3f96508f394a8ecacc99a9ed71bd4c
          • Opcode Fuzzy Hash: 4852fbf894ae1064c3f142933c5bb175f641dd7957aa56a7b8a46894b0ad1be1
          • Instruction Fuzzy Hash: 6941F371C0061CCBDF24CFA9C989BDEBBB5BF49308F148469D408AB250DB756949CF90
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateActCtxA.KERNEL32(?), ref: 05A346B1
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: Create
          • String ID:
          • API String ID: 2289755597-0
          • Opcode ID: a39e9c0b3704320cae186581c9f467a54fb3d48c3f3b3a0a61940d568f73c7a5
          • Instruction ID: ee3e2aa4fc3e9073072cabc99193642438a80331e552d464eca8f5a1218fba68
          • Opcode Fuzzy Hash: a39e9c0b3704320cae186581c9f467a54fb3d48c3f3b3a0a61940d568f73c7a5
          • Instruction Fuzzy Hash: 1E41F370C0465CCBDF24CFA9C989BDEBBB5BF49308F108469D408AB250D7716949CF90
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CallWindowProcW.USER32(?,?,?,?,?), ref: 05A32531
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: CallProcWindow
          • String ID:
          • API String ID: 2714655100-0
          • Opcode ID: b56b386f3f8827ba8e1340c79510a518b5c0ac947dabe1dcb6fd989687a47c06
          • Instruction ID: 788cfe8c091e5296a1dd35b79c8b983a01c7fde7b367c207560dd84a57347df5
          • Opcode Fuzzy Hash: b56b386f3f8827ba8e1340c79510a518b5c0ac947dabe1dcb6fd989687a47c06
          • Instruction Fuzzy Hash: 9E411AB9A003058FDB14CF99C449FAABBF6FF88318F148459E519AB321D774A945CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: CreateFromIconResource
          • String ID:
          • API String ID: 3668623891-0
          • Opcode ID: 75f6c22f27946b462b7e8c557be29867f6ff79b83f3843feb62e1aa9b23d04c5
          • Instruction ID: 34515f9308ef5f7a2a353229c98ba49f854300099716290a4295d960ab5d636d
          • Opcode Fuzzy Hash: 75f6c22f27946b462b7e8c557be29867f6ff79b83f3843feb62e1aa9b23d04c5
          • Instruction Fuzzy Hash: 8C31697290434D9FCB11CFA9C845AEABFF9EF09324F04845AF654A7211C3359854DFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,058EBCC6,?,?,?,?,?), ref: 058EBD87
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: DuplicateHandle
          • String ID:
          • API String ID: 3793708945-0
          • Opcode ID: d00a1cafa34b1cd631c174728e22a20b588f9b5918fe394f5320453cf573270f
          • Instruction ID: 96d1c8a438efae93593a0c515ff0698cff3202ff0f8f5b958e7bd8055493c112
          • Opcode Fuzzy Hash: d00a1cafa34b1cd631c174728e22a20b588f9b5918fe394f5320453cf573270f
          • Instruction Fuzzy Hash: 6E21E5B590020CAFDB10CF99D584AEEBBF9FB49324F14841AE914A7310D378A954CFA5
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • PostMessageW.USER32(?,033B53E8,00000000,?), ref: 05A3E73D
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessagePost
          • String ID:
          • API String ID: 410705778-0
          • Opcode ID: 31e4c09d08d7ffe092d06e581694ff9ae1a44f1b0e774590656c1686c9cf0266
          • Instruction ID: 3041298e36a24d13324f72f036e8af5cc22e28cc4eaff1268483ea2cfc9a66e2
          • Opcode Fuzzy Hash: 31e4c09d08d7ffe092d06e581694ff9ae1a44f1b0e774590656c1686c9cf0266
          • Instruction Fuzzy Hash: 142189B68043499FDB10CFA5C986BEEBBF8FF09324F14845AE554A3241D338A549CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,058EBCC6,?,?,?,?,?), ref: 058EBD87
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: DuplicateHandle
          • String ID:
          • API String ID: 3793708945-0
          • Opcode ID: e12c7f1c49205baeb14a24a02726d8f46b1b5893cb505c21f9ba4ca015bf58ed
          • Instruction ID: a39f60c961c5c0d2b7074f96700243db47d11e7c4dabadd12bc398b5f40878af
          • Opcode Fuzzy Hash: e12c7f1c49205baeb14a24a02726d8f46b1b5893cb505c21f9ba4ca015bf58ed
          • Instruction Fuzzy Hash: 2921DFB59002099FDB00CFA9D584AEEFBF9AB49324F14845AE954A7210D378A954CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • CreateIconFromResourceEx.USER32(?,?,?,?,?,?,?,?,?,?,05A3B8B2,?,?,?,?,?), ref: 05A3B957
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: CreateFromIconResource
          • String ID:
          • API String ID: 3668623891-0
          • Opcode ID: f9003b64baae50341801f907fe33d219ca26411b4e183b73df0eccb4dcdc5bc3
          • Instruction ID: 8d169daa1b6cf240018e195e9d1d31f9810b21e06d1ddc76fc21ef5ffa3c893d
          • Opcode Fuzzy Hash: f9003b64baae50341801f907fe33d219ca26411b4e183b73df0eccb4dcdc5bc3
          • Instruction Fuzzy Hash: D01156B580020D9FDB10CF9AC844BEEBFF9EB48324F14841AE514B7210C379A954CFA0
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,058E96A9,00000800,00000000,00000000), ref: 058E98BA
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: LibraryLoad
          • String ID:
          • API String ID: 1029625771-0
          • Opcode ID: 61518d537efea828789d30f84e30f6fb90c5e16e48a57304c4726af824f5068e
          • Instruction ID: 89005e0a2a0a39e81f66b6787e7bc070132d37bb9bc13ba3aeb747ea00f7ac7c
          • Opcode Fuzzy Hash: 61518d537efea828789d30f84e30f6fb90c5e16e48a57304c4726af824f5068e
          • Instruction Fuzzy Hash: 271133B6D002088FDB10CF9AC444ADEFBF8EB49324F04842AD919A7600C3B5A948CFA4
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,058E96A9,00000800,00000000,00000000), ref: 058E98BA
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: LibraryLoad
          • String ID:
          • API String ID: 1029625771-0
          • Opcode ID: bb3e98cf94c6762de9f1cb8845870cda33173bef4d12cd220f2224bcacd8ac11
          • Instruction ID: ab45636164a1f62c35ac0e30a94b6f3443b8c6d81514bbc15a962c9f21b64196
          • Opcode Fuzzy Hash: bb3e98cf94c6762de9f1cb8845870cda33173bef4d12cd220f2224bcacd8ac11
          • Instruction Fuzzy Hash: 6F1114B6D002099FDB10CF9AC444ADEFBF9EB49324F14842AD915A7700C379A949CFA5
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • PostMessageW.USER32(?,033B53E8,00000000,?), ref: 05A3E73D
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessagePost
          • String ID:
          • API String ID: 410705778-0
          • Opcode ID: a6a5e0f2e6e7ef2fdcc95f3f6993c8ff53ae37630aeebfc641de49699cdae8f6
          • Instruction ID: ee207bb82b71c07b4962e7f3957d22ddb07fb6166c9eafe180d93ca5026bc8fe
          • Opcode Fuzzy Hash: a6a5e0f2e6e7ef2fdcc95f3f6993c8ff53ae37630aeebfc641de49699cdae8f6
          • Instruction Fuzzy Hash: A21125B58003099FDB10CF9AC985BEEFBF8FB48324F14846AE554A3240D378A944CFA5
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SendMessageW.USER32(?,00000018,00000001,?), ref: 05A3D29D
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessageSend
          • String ID:
          • API String ID: 3850602802-0
          • Opcode ID: 0a79d7288e6c564f3e98c877eefbd2803863ee86a4d749a0d8b57714a5ef85c1
          • Instruction ID: cd1335691015c103884b9bee6ebc67ff4ec5f8532733e1774c63a327b8e280dd
          • Opcode Fuzzy Hash: 0a79d7288e6c564f3e98c877eefbd2803863ee86a4d749a0d8b57714a5ef85c1
          • Instruction Fuzzy Hash: 6011F2B58003099FDB10CF99D985BDEBBF8FB48324F14885AE914A7600C374A944CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • GetModuleHandleW.KERNELBASE(00000000), ref: 058E962E
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: HandleModule
          • String ID:
          • API String ID: 4139908857-0
          • Opcode ID: ec0d2f6cf6f6b74d9a133674ff3a58df0047482b99d3b5857ce9e950cbdcff96
          • Instruction ID: 4eb0e1a9959d495651961edbf1011e525623c97784620810ea7256f42d6b3973
          • Opcode Fuzzy Hash: ec0d2f6cf6f6b74d9a133674ff3a58df0047482b99d3b5857ce9e950cbdcff96
          • Instruction Fuzzy Hash: 661113B5C002098FDB10CF9AC444BDEFBF4BF89324F14841AD919A7210D374A549CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SetWindowLongW.USER32(?,?,?,?,?,?,?,?,058EFE28,?,?,?,?), ref: 058EFE9D
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: LongWindow
          • String ID:
          • API String ID: 1378638983-0
          • Opcode ID: ec13741c6f32e2e61ebeed4bfc2649e1a10e694d391e319d64247fa73d1f8df7
          • Instruction ID: 13ed5daef21c39c387033ca4bb8ad5ee78fba9ba53d6a0be1205cf78637377e2
          • Opcode Fuzzy Hash: ec13741c6f32e2e61ebeed4bfc2649e1a10e694d391e319d64247fa73d1f8df7
          • Instruction Fuzzy Hash: BE1133B59002099FDB10CF99D585BDFFBF8EB48324F14845AD954A7341C378A944CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SetWindowLongW.USER32(?,?,?,?,?,?,?,?,058EFE28,?,?,?,?), ref: 058EFE9D
          Memory Dump Source
          • Source File: 00000010.00000002.506001434.00000000058E0000.00000040.00000001.sdmp, Offset: 058E0000, based on PE: false
          Similarity
          • API ID: LongWindow
          • String ID:
          • API String ID: 1378638983-0
          • Opcode ID: e0a1ad6bc951b641afb7840814b8ec78ccc41639a014ea37b5f119e68a575f60
          • Instruction ID: 2aac9167ca9f42a64dd6369c9fe2b84e46e1a0bffa7ec6ee1cce561ac954cd5e
          • Opcode Fuzzy Hash: e0a1ad6bc951b641afb7840814b8ec78ccc41639a014ea37b5f119e68a575f60
          • Instruction Fuzzy Hash: 031133B59002099FDB10CF8AD584BEFFBF8EB49324F10845AEA55A7301C374A944CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SendMessageW.USER32(?,0000020A,?,?,?,?,?,?,05A3226A,?,00000000,?), ref: 05A3C435
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessageSend
          • String ID:
          • API String ID: 3850602802-0
          • Opcode ID: 941a3174b14ea02e8f40e8a2df697dbe047188ea74cf6ad82a294e003e4c461c
          • Instruction ID: 50abbbb3d931a55a3b079134fd97ceb6ba75cf38af8f06411a5752cc039b76dd
          • Opcode Fuzzy Hash: 941a3174b14ea02e8f40e8a2df697dbe047188ea74cf6ad82a294e003e4c461c
          • Instruction Fuzzy Hash: 8511F2B58003489FDB10CF99D989BEEFBF8EB49324F108859E615A7600C374A954CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SendMessageW.USER32(?,?,?,?,?,?,?,?,00000000), ref: 05A3BCBD
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessageSend
          • String ID:
          • API String ID: 3850602802-0
          • Opcode ID: 670b3bc12afa33062ed8df128e62ad9df730cd94fb43f9e91bd2916e6d890b47
          • Instruction ID: 18cbfa79b667d2af849feda53e534b17161cc6f684c9d3c39827fee4e6380fe2
          • Opcode Fuzzy Hash: 670b3bc12afa33062ed8df128e62ad9df730cd94fb43f9e91bd2916e6d890b47
          • Instruction Fuzzy Hash: DD11E0B59003489FDB20CF9AD585BDEBBF9EB48324F148859E515A7210C375A944CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SendMessageW.USER32(?,00000018,00000001,?), ref: 05A3D29D
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessageSend
          • String ID:
          • API String ID: 3850602802-0
          • Opcode ID: 74a6c6f8e797502640240a4f9b28085fb9895bcfb69123788062747de29937da
          • Instruction ID: d0fed3bbfc819ff6335eaf2b8a26471e296d793ba9a096d346da5b98f163b783
          • Opcode Fuzzy Hash: 74a6c6f8e797502640240a4f9b28085fb9895bcfb69123788062747de29937da
          • Instruction Fuzzy Hash: 6F11F2B5800308DFDB10DF9AD585BDEBBF8EB49324F108859E915A7200C3B5A954CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • SendMessageW.USER32(?,0000020A,?,?,?,?,?,?,05A3226A,?,00000000,?), ref: 05A3C435
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: MessageSend
          • String ID:
          • API String ID: 3850602802-0
          • Opcode ID: e0b07e7f1defdab722d48f48a3adf837f291d50ecea17c8757e46e1544c6e268
          • Instruction ID: 882e2c7171cee5fa78f7a447bd83d61c0cb50b5158b3046cd5b714ff8762123d
          • Opcode Fuzzy Hash: e0b07e7f1defdab722d48f48a3adf837f291d50ecea17c8757e46e1544c6e268
          • Instruction Fuzzy Hash: 9B11F2B58003489FDB10CF99C989BDFBBF8FB48324F148859E555A7600C374A944CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • OleInitialize.OLE32(00000000), ref: 05A3F435
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: Initialize
          • String ID:
          • API String ID: 2538663250-0
          • Opcode ID: d57eaef7695e58d2115e0ab6f4532ad3feeaf481d0aa06e3ae50741b8482f669
          • Instruction ID: b008e972ee04bd6c36ae9c630a46da01f9c05b4d11bbe92121d363cce71e984a
          • Opcode Fuzzy Hash: d57eaef7695e58d2115e0ab6f4532ad3feeaf481d0aa06e3ae50741b8482f669
          • Instruction Fuzzy Hash: 2A1103B5D043488FCB10CF99D589BDEBBF8EB48328F14885AE519A7300D378A944CFA5
          Uniqueness

          Uniqueness Score: -1.00%

          APIs
          • OleInitialize.OLE32(00000000), ref: 05A3F435
          Memory Dump Source
          • Source File: 00000010.00000002.506361668.0000000005A30000.00000040.00000001.sdmp, Offset: 05A30000, based on PE: false
          Similarity
          • API ID: Initialize
          • String ID:
          • API String ID: 2538663250-0
          • Opcode ID: 90735badfc64ff4ba3f8680773736812a6b0590bde5f131bbc34c67bc76a27cd
          • Instruction ID: ffdaa27529191d0afca0cdb3adb81c78c7527ce1a2bf88b938ca5fa1d9dec915
          • Opcode Fuzzy Hash: 90735badfc64ff4ba3f8680773736812a6b0590bde5f131bbc34c67bc76a27cd
          • Instruction Fuzzy Hash: BB1103B5D002098FDB10CFA9D545BDEFBF4AF08328F14895AD619B7600D378A558CFA1
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.500487908.00000000016ED000.00000040.00000001.sdmp, Offset: 016ED000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 701b20bdfa743f0aab50c36377911376030ed3d38dec526f1b51f7b88ebf43ae
          • Instruction ID: 7452d6aec94afadcbb86ad23fd5887d013c1bb6581cf3057ac59595a930220b8
          • Opcode Fuzzy Hash: 701b20bdfa743f0aab50c36377911376030ed3d38dec526f1b51f7b88ebf43ae
          • Instruction Fuzzy Hash: 1A21F4B1505240DFDB01CF94D9C8B66BBA6FB84328F248669E9050B256C336D856CAA1
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.500487908.00000000016ED000.00000040.00000001.sdmp, Offset: 016ED000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 94b056dda0bdb3a49a7e868c8e14ea8c1ba69a0c48d133d6901a62dcafe9fa82
          • Instruction ID: 909ebbf865823d849c427df6ceb84b62e39a16ae71afa35065aa224cb27be997
          • Opcode Fuzzy Hash: 94b056dda0bdb3a49a7e868c8e14ea8c1ba69a0c48d133d6901a62dcafe9fa82
          • Instruction Fuzzy Hash: 932103B1506244DFDB01CF94D9C8FA6BBA6FB94324F24C669E9050B346C336E856C6A1
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.501981889.000000000319D000.00000040.00000001.sdmp, Offset: 0319D000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: c4cce8df0905052ddd142781147855d07452da45382e4e732c91cfb9d97360f4
          • Instruction ID: dbc75005ed4dda4299a8120e28b9bc89ad248f3d498e53380057b5b90854c69f
          • Opcode Fuzzy Hash: c4cce8df0905052ddd142781147855d07452da45382e4e732c91cfb9d97360f4
          • Instruction Fuzzy Hash: 29212575504240DFEF14CF24E4C4B26BBA9FB88314F28C9AAD8090B246C33AD847CA61
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.501981889.000000000319D000.00000040.00000001.sdmp, Offset: 0319D000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: b2cce088c95841fa949d84056f4e2279022238003ca04edc5a1fe24617978e52
          • Instruction ID: 6f6cafe7b126036d2ca03bef619d7d2e23a745879ab1cf6c5e893efb0ac7b0d2
          • Opcode Fuzzy Hash: b2cce088c95841fa949d84056f4e2279022238003ca04edc5a1fe24617978e52
          • Instruction Fuzzy Hash: D52180755093808FDB02CF24D994B15BF71EB4A214F2DC5DBD8498F657C33A940ACB62
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.500487908.00000000016ED000.00000040.00000001.sdmp, Offset: 016ED000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 569a6f0108899acddfcda51f0ae5d6682c26a74976b15f1d2897a196d0080c86
          • Instruction ID: 2fc270fc41faee1c11956a7f03bc10378db1e6d94bc5578601508a627e971c21
          • Opcode Fuzzy Hash: 569a6f0108899acddfcda51f0ae5d6682c26a74976b15f1d2897a196d0080c86
          • Instruction Fuzzy Hash: 3111B1B6405280DFCB12CF54D9C4B56BFB1FB94324F24C6A9D8450B756C33AE45ACBA1
          Uniqueness

          Uniqueness Score: -1.00%

          Memory Dump Source
          • Source File: 00000010.00000002.500487908.00000000016ED000.00000040.00000001.sdmp, Offset: 016ED000, based on PE: false
          Similarity
          • API ID:
          • String ID:
          • API String ID:
          • Opcode ID: 569a6f0108899acddfcda51f0ae5d6682c26a74976b15f1d2897a196d0080c86
          • Instruction ID: c26656125b8aa0911c32c532011f07475f71c6a5cdd73e857570215c6054f52d
          • Opcode Fuzzy Hash: 569a6f0108899acddfcda51f0ae5d6682c26a74976b15f1d2897a196d0080c86
          • Instruction Fuzzy Hash: 9211AF76404280DFDB12CF54D9C4B16BFB1FB84324F24C6A9D9050B756C33AD46ACBA2
          Uniqueness

          Uniqueness Score: -1.00%

          Non-executed Functions