Windows Analysis Report
H 05072022.xls

Overview

General Information

Sample Name: H 05072022.xls
Analysis ID: 672716
MD5: f0e821a13f85dad72bb345b2dd7c93e7
SHA1: 17b0e4f2bc946eb3c0f7deb0da78d5db58836a0c
SHA256: 3db2ab1966f944f46e4cb802f2d4e71d407d989766c20809d232552fe55d29d1
Infos:

Detection

Hidden Macro 4.0, Emotet
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (drops PE files)
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Document exploit detected (creates forbidden files)
Antivirus detection for URL or domain
Found malicious Excel 4.0 Macro
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Snort IDS alert for network traffic
Office process drops PE file
Found Excel 4.0 Macro with suspicious formulas
C2 URLs / IPs found in malware configuration
Drops PE files to the user root directory
Hides that the sample has been downloaded from the Internet (zone.identifier)
Document exploit detected (process start blacklist hit)
Document exploit detected (UrlDownloadToFile)
Queries the volume information (name, serial number etc) of a device
Yara signature match
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Potential document exploit detected (performs DNS queries)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Potential document exploit detected (unknown TCP traffic)
PE file contains an invalid checksum
Drops PE files
Uses a known web browser user agent for HTTP communication
Drops PE files to the windows directory (C:\Windows)
Detected TCP or UDP traffic on non-standard ports
Connects to several IPs in different countries
Potential key logger detected (key state polling based)
Registers a DLL
Drops PE files to the user directory
Found large amount of non-executed APIs
Potential document exploit detected (performs HTTP gets)
Creates a process in suspended mode (likely to inject code)

Classification

AV Detection

barindex
Source: H 05072022.xls Virustotal: Detection: 64% Perma Link
Source: H 05072022.xls Metadefender: Detection: 37% Perma Link
Source: H 05072022.xls ReversingLabs: Detection: 80%
Source: http://www.fundaciontheoz.cl/pensamientooccidental/tilKftYVgHoCu4pp/ Avira URL Cloud: Label: malware
Source: http://www.clinicaportalpsicologia.com.br/wp-content/rknwta6Ncgt9xnXu7S/ Avira URL Cloud: Label: malware
Source: https://174.138.33.49/F Avira URL Cloud: Label: malware
Source: https://flywithme.dk/wp-includes/xFbL/ Avira URL Cloud: Label: malware
Source: flywithme.dk Virustotal: Detection: 9% Perma Link
Source: fundaciontheoz.cl Virustotal: Detection: 16% Perma Link
Source: www.fundaciontheoz.cl Virustotal: Detection: 11% Perma Link
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll Metadefender: Detection: 48% Perma Link
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll ReversingLabs: Detection: 88%
Source: C:\Users\user\hhdt1.ocx Metadefender: Detection: 48% Perma Link
Source: C:\Users\user\hhdt1.ocx ReversingLabs: Detection: 88%
Source: C:\Windows\System32\IBmjgOoh\HPiQbOm.dll (copy) Metadefender: Detection: 48% Perma Link
Source: C:\Windows\System32\IBmjgOoh\HPiQbOm.dll (copy) ReversingLabs: Detection: 88%
Source: 00000004.00000002.1198679946.00000000002FA000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Emotet {"C2 list": ["174.138.33.49:7080", "188.165.79.151:443", "196.44.98.190:8080", "5.253.30.17:7080", "190.145.8.4:443", "54.37.228.122:443", "128.199.217.206:443", "175.126.176.79:8080", "104.248.225.227:8080", "54.37.106.167:8080", "198.199.70.22:8080", "139.59.80.108:8080", "103.85.95.4:8080", "165.232.185.110:8080", "103.224.241.74:8080", "178.62.112.199:8080", "178.238.225.252:8080", "62.171.178.147:8080", "202.134.4.210:7080", "103.71.99.57:8080", "103.41.204.169:8080", "139.196.72.155:8080", "188.225.32.231:4143", "87.106.97.83:7080", "103.126.216.86:443", "37.44.244.177:8080", "64.227.55.231:8080", "93.104.209.107:8080", "103.56.149.105:8080", "43.129.209.178:443", "202.29.239.162:443", "210.57.209.142:8080", "83.229.80.93:8080", "85.25.120.45:8080", "190.107.19.179:443", "157.230.99.206:8080", "195.77.239.39:8080", "36.67.23.59:443", "104.244.79.94:443", "118.98.72.86:443", "37.187.114.15:8080", "46.101.98.60:8080", "85.214.67.203:8080", "165.22.254.236:8080", "157.245.111.0:8080", "128.199.242.164:8080", "202.28.34.99:8080", "88.217.172.165:8080"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0rse5dX4AAJA=", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCWq8e5dX4AAIg="]}
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: unknown HTTPS traffic detected: 41.204.199.147:443 -> 192.168.2.22:49171 version: TLS 1.2
Source: unknown HTTPS traffic detected: 94.231.103.133:443 -> 192.168.2.22:49173 version: TLS 1.2
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001C9F0 FindFirstFileW,FindNextFileW, 4_2_000000018001C9F0

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: yXlTTXSuSsUlL[1].dll.0.dr Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Section loaded: \KnownDlls\api-ms-win-downlevel-shlwapi-l2-1-0.dll origin: URLDownloadToFileA Jump to behavior
Source: global traffic DNS query: name: greenlizard.co.za
Source: global traffic DNS query: name: www.clinicaportalpsicologia.com.br
Source: global traffic DNS query: name: flywithme.dk
Source: global traffic DNS query: name: www.fundaciontheoz.cl
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 41.204.199.147:443 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 187.1.136.16:80 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 94.231.103.133:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 162.240.65.124:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 41.204.199.147:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 94.231.103.133:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 187.1.136.16:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 162.240.65.124:80

Networking

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 174.138.33.49 7080 Jump to behavior
Source: Traffic Snort IDS: 2404316 ET CNC Feodo Tracker Reported CnC Server TCP group 9 192.168.2.22:49175 -> 174.138.33.49:7080
Source: Malware configuration extractor IPs: 174.138.33.49:7080
Source: Malware configuration extractor IPs: 188.165.79.151:443
Source: Malware configuration extractor IPs: 196.44.98.190:8080
Source: Malware configuration extractor IPs: 5.253.30.17:7080
Source: Malware configuration extractor IPs: 190.145.8.4:443
Source: Malware configuration extractor IPs: 54.37.228.122:443
Source: Malware configuration extractor IPs: 128.199.217.206:443
Source: Malware configuration extractor IPs: 175.126.176.79:8080
Source: Malware configuration extractor IPs: 104.248.225.227:8080
Source: Malware configuration extractor IPs: 54.37.106.167:8080
Source: Malware configuration extractor IPs: 198.199.70.22:8080
Source: Malware configuration extractor IPs: 139.59.80.108:8080
Source: Malware configuration extractor IPs: 103.85.95.4:8080
Source: Malware configuration extractor IPs: 165.232.185.110:8080
Source: Malware configuration extractor IPs: 103.224.241.74:8080
Source: Malware configuration extractor IPs: 178.62.112.199:8080
Source: Malware configuration extractor IPs: 178.238.225.252:8080
Source: Malware configuration extractor IPs: 62.171.178.147:8080
Source: Malware configuration extractor IPs: 202.134.4.210:7080
Source: Malware configuration extractor IPs: 103.71.99.57:8080
Source: Malware configuration extractor IPs: 103.41.204.169:8080
Source: Malware configuration extractor IPs: 139.196.72.155:8080
Source: Malware configuration extractor IPs: 188.225.32.231:4143
Source: Malware configuration extractor IPs: 87.106.97.83:7080
Source: Malware configuration extractor IPs: 103.126.216.86:443
Source: Malware configuration extractor IPs: 37.44.244.177:8080
Source: Malware configuration extractor IPs: 64.227.55.231:8080
Source: Malware configuration extractor IPs: 93.104.209.107:8080
Source: Malware configuration extractor IPs: 103.56.149.105:8080
Source: Malware configuration extractor IPs: 43.129.209.178:443
Source: Malware configuration extractor IPs: 202.29.239.162:443
Source: Malware configuration extractor IPs: 210.57.209.142:8080
Source: Malware configuration extractor IPs: 83.229.80.93:8080
Source: Malware configuration extractor IPs: 85.25.120.45:8080
Source: Malware configuration extractor IPs: 190.107.19.179:443
Source: Malware configuration extractor IPs: 157.230.99.206:8080
Source: Malware configuration extractor IPs: 195.77.239.39:8080
Source: Malware configuration extractor IPs: 36.67.23.59:443
Source: Malware configuration extractor IPs: 104.244.79.94:443
Source: Malware configuration extractor IPs: 118.98.72.86:443
Source: Malware configuration extractor IPs: 37.187.114.15:8080
Source: Malware configuration extractor IPs: 46.101.98.60:8080
Source: Malware configuration extractor IPs: 85.214.67.203:8080
Source: Malware configuration extractor IPs: 165.22.254.236:8080
Source: Malware configuration extractor IPs: 157.245.111.0:8080
Source: Malware configuration extractor IPs: 128.199.242.164:8080
Source: Malware configuration extractor IPs: 202.28.34.99:8080
Source: Malware configuration extractor IPs: 88.217.172.165:8080
Source: Joe Sandbox View ASN Name: DIGITALOCEAN-ASNUS DIGITALOCEAN-ASNUS
Source: Joe Sandbox View JA3 fingerprint: 7dcce5b76c8b17472d024758970a406b
Source: Joe Sandbox View IP Address: 157.230.99.206 157.230.99.206
Source: global traffic HTTP traffic detected: GET /amanah/HJErj/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: greenlizard.co.zaConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /wp-includes/xFbL/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: flywithme.dkConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /wp-content/rknwta6Ncgt9xnXu7S/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.clinicaportalpsicologia.com.brConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /pensamientooccidental/tilKftYVgHoCu4pp/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.fundaciontheoz.clConnection: Keep-Alive
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 174.138.33.49:7080
Source: unknown Network traffic detected: IP country count 22
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49173
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49171
Source: unknown Network traffic detected: HTTP traffic on port 49171 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49173 -> 443
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 25 Jul 2022 08:27:29 GMTServer: ApacheX-Powered-By: PHP/5.6.40Expires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Link: <https://flywithme.dk/wp-json/>; rel="https://api.w.org/"Content-Security-Policy: upgrade-insecure-requests;Upgrade: h2Connection: Upgrade, closeX-Content-Type-Options: nosniffSimplyCom-Server: ApacheTransfer-Encoding: chunkedContent-Type: text/html; charset=UTF-8
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 25 Jul 2022 08:27:26 GMTServer: ApacheExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Link: <https://www.clinicaportalpsicologia.com.br/wp-json/>; rel="https://api.w.org/"Content-Encoding: gzipVary: Accept-EncodingSet-Cookie: Q-nRfEyNzlwbYUeh=AmQW%5B1; expires=Tue, 26-Jul-2022 08:27:26 GMT; Max-Age=86400; path=/Set-Cookie: LQXvDnbCi_V=T.IyOvg1ts; expires=Tue, 26-Jul-2022 08:27:26 GMT; Max-Age=86400; path=/Set-Cookie: fUqbTznEhHt=fEc%2A5lYHuAJ; expires=Tue, 26-Jul-2022 08:27:26 GMT; Max-Age=86400; path=/Set-Cookie: N_LhVXTlKtQ=%5B8zbNWgVGME7R; expires=Tue, 26-Jul-2022 08:27:26 GMT; Max-Age=86400; path=/Keep-Alive: timeout=5, max=500Connection: Keep-AliveTransfer-Encoding: chunkedContent-Type: text/html; charset=UTF-8Data Raw: 31 64 34 31 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ec 5a cd 92 db 38 92 3e 77 3d 05 8b 8e a9 12 c7 24 45 52 ff 52 cb dd ee 6a f7 ec a1 7b da e1 72 c7 c6 84 cb 51 01 91 90 44 9b 24 d8 00 54 2a 8d 5c 0f 33 b1 a7 39 cc 69 8e 7b d8 83 1f 68 5f 61 13 20 29 52 14 f5 ef 89 e8 99 1d 47 59 12 81 cc 2f 13 99 89 44 26 a4 ff fd ef ff f9 fa f2 fb 9f 6f de fe e9 f5 2b 65 ca c3 e0 c5 c5 d7 e2 4d 09 50 34 19 aa 31 37 be 7b a3 2a 31 c5 63 ff 71 a8 92 49 1f 88 78 dc af d7 c9 24 36 43 5c 8f d8 33 55 71 03 c4 d8 50 8d 88 f1 81 a9 2f 2e 00 01 23 4f bc 87 98 23 c5 9d 22 ca 30 1f aa bf bc fd c1 e8 aa 4a 1d 44 70 9f 07 f8 c5 eb cf 7f 99 f8 11 52 a2 cf ff 45 14 1c b9 24 e2 14 79 48 31 94 9b e0 f3 df 22 df 45 8a 87 95 98 f9 2e 09 c8 c4 47 0a 0e 95 9f 19 62 2e d1 73 8a d7 84 72 14 28 af 73 aa 8c 44 0c 7d fe 3b 8c 11 56 e4 94 94 31 f6 d0 84 4c 10 83 67 7f 45 b7 ce e3 47 63 14 71 3f 50 5c c4 40 c2 18 85 9f ff 16 00 be ef 11 46 80 91 a4 80 a0 f7 03 8e 7c a2 8f 40 7b 2c 87 50 e8 07 3a 00 70 4c c3 cf 7f f5 40 cf af eb c9 9a 53 a3 44 28 c4 c3 6b 4a 46 84 b3 6b 81 c0 71 c4 87 d7 21 7a 34 fc 10 4d b0 01 26 7f f0 f1 bc 1f 20 3a c1 d7 d2 68 39 a3 3a 26 34 44 dc f0 30 c7 2e f7 49 a4 ae 20 54 8e 03 1c 4f 49 84 87 11 51 d7 b9 04 60 0c e6 2a 50 cf 7d 8f 4f 87 1e c8 72 b1 21 1f 84 da 3e f7 51 60 30 17 05 78 68 27 1e 0b fc e8 a3 42 71 30 54 d9 14 20 dc 19 57 c0 8c 20 78 0a b1 31 54 45 54 30 08 8b f9 7c 6e ba 40 0b 2b 8e a5 63 72 ef 99 2e 09 cd 11 ad cf 63 23 15 5f 9f c5 01 41 1e ab 3b 96 dd ad 5b dd 7a 46 4c 0c 1c 1a 89 79 8d d5 18 cb Data Ascii: 1d41Z8>w=$ERRj{rQD$T*\39i{h_a )RGY/D&o+eMP417{*1cqIx$6C\3UqP/.#O#"0JDpRE$yH1"E.Gb.sr(sD};V1LgEGcq?P\@F|@{,P:pL@SD(kJFkq!z4M& :h9:&4D0.I TOIQ`*P}Or!>Q`0xh'Bq0T W x1TET0|n@+cr.c#_A;[zFLy
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 25 Jul 2022 08:27:31 GMTServer: ApacheExpires: Wed, 11 Jan 1984 05:00:00 GMTCache-Control: no-cache, must-revalidate, max-age=0Link: <https://www.fundaciontheoz.cl/wp-json/>; rel="https://api.w.org/"Set-Cookie: _learn_press_session_15e189b8b9570bad712e7dad4bf24da9=26f3617e47267a989187cbc2d8babc7c%7C%7C1658910451%7C%7Ce0d9bab5f1332bd3818d6e7c5ac2efa0; expires=Wed, 27-Jul-2022 08:27:31 GMT; Max-Age=172799; path=/; secureSet-Cookie: _wordpress_lp_guest=6db20933f83edee9a34774ce481c44f9; expires=Mon, 25-Jul-2022 09:27:32 GMT; Max-Age=3600; path=/; secureKeep-Alive: timeout=5, max=100Connection: Keep-AliveTransfer-Encoding: chunkedContent-Type: text/html; charset=UTF-8Data Raw: 31 64 61 38 0d 0a 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 73 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 6f 66 69 6c 65 22 20 68 72 65 66 3d 22 68 74 74 70 3a 2f 2f 67 6d 70 67 2e 6f 72 67 2f 78 66 6e 2f 31 31 22 3e 0a 0a 09 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 68 72 65 66 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 66 75 6e 64 61 63 69 6f 6e 74 68 65 6f 7a 2e 63 6c 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 74 68 65 6d 65 73 2f 75 6e 66 69 6e 69 74 79 70 6c 75 73 2f 69 6e 66 75 73 69 6f 6e 2f 66 72 61 6d 65 77 6f 72 6b 2f 66 73 73 2f 63 73 73 2f 66 73 73 2d 72 65 73 65 74 2d 67 6c 6f 62 61 6c 2e 63 73 73 22 20 2f 3e 0a 09 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 68 72 65 66 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 66 75 6e 64 61 63 69 6f 6e 74 68 65 6f 7a 2e 63 6c 2f 77 70 2d 63 6f 6e 74 65 6e 74 2f 74 68 65 6d 65 73 2f 75 6e 66 69 6e 69 74 79 70 6c 75 73 2f 69 6e 66 75 73 69 6f 6e 2f 66 72 61 6d 65 77 6f 72 6b 2f 66 73 73 2f 63 73 73 2f 66 73 73 2d 62 61 73 65 2d 67 6c 6f 62 61 6c 2e 63 73 73 22 20 2f 3e 0a 09 3c 6c 69 6e 6b 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 20 6d 65 64 69 61 3d 22 61 6c 6c 22 20 68 72 65 66 3d 22 68 74 74 70 3a 2f 2f 77 77 Data Ascii: 1da8<!doctype html><html lang="es"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="profile" href="http://gmpg.org/xfn/11"><link rel="stylesheet" type="text/css" media="all" href="http://www.fundaciontheoz.cl/wp-content/themes/unfinityplus/infusion/framework/fss/css/fss-reset-global.css" /><link rel="stylesheet" type="text/css" media="all"
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: unknown TCP traffic detected without corresponding DNS query: 174.138.33.49
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/server1.crl0
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
Source: regsvr32.exe, 00000004.00000002.1199003581.0000000002D90000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.4.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: regsvr32.exe, 00000004.00000003.974282903.000000000037E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000004.00000002.1198822487.000000000037E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabme
Source: regsvr32.exe, 00000004.00000002.1199003581.0000000002D90000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/eno
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0%
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0-
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0/
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com05
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net0D
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com.my/cps.htm02
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
Source: regsvr32.exe, 00000004.00000003.974282903.000000000037E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000004.00000002.1198822487.000000000037E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49/
Source: regsvr32.exe, 00000004.00000003.974282903.000000000037E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000004.00000002.1198822487.000000000037E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49/F
Source: regsvr32.exe, 00000004.00000002.1199003581.0000000002D90000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://174.138.33.49:7080/
Source: regsvr32.exe, 00000004.00000002.1199025968.0000000002DA8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.com/CPS0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll Jump to behavior
Source: unknown DNS traffic detected: queries for: greenlizard.co.za
Source: global traffic HTTP traffic detected: GET /amanah/HJErj/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: greenlizard.co.zaConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /wp-includes/xFbL/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: flywithme.dkConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /wp-content/rknwta6Ncgt9xnXu7S/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.clinicaportalpsicologia.com.brConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /pensamientooccidental/tilKftYVgHoCu4pp/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.fundaciontheoz.clConnection: Keep-Alive
Source: unknown HTTPS traffic detected: 41.204.199.147:443 -> 192.168.2.22:49171 version: TLS 1.2
Source: unknown HTTPS traffic detected: 94.231.103.133:443 -> 192.168.2.22:49173 version: TLS 1.2
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7042D1F GetKeyState,GetKeyState,GetKeyState, 3_2_000007FEF7042D1F

E-Banking Fraud

barindex
Source: Yara match File source: 00000004.00000002.1198679946.00000000002FA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 3.2.regsvr32.exe.160000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.regsvr32.exe.150000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.160000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.regsvr32.exe.150000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000003.00000002.914740891.0000000000160000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.1198622373.0000000000150000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.915078556.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.1199191486.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: Screenshot number: 4 Screenshot OCR: Enable Editing and click Enable Content. 1 " 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 1
Source: Screenshot number: 4 Screenshot OCR: Enable Content. 1 " 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
Source: H 05072022.xls Macro extractor: Sheet: Sheet7 contains: URLDownloadToFileA
Source: H 05072022.xls Macro extractor: Sheet: Sheet7 contains: URLDownloadToFileA
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhdt1.ocx Jump to dropped file
Source: H 05072022.xls Initial sample: EXEC
Source: H 05072022.xls Initial sample: EXEC
Source: H 05072022.xls, type: SAMPLE Matched rule: SUSP_Excel4Macro_AutoOpen date = 2020-03-26, author = John Lambert @JohnLaTwC, description = Detects Excel4 macro use with auto open / close, score = 2fb198f6ad33d0f26fb94a1aa159fef7296e0421da68887b8f2548bbd227e58f
Source: C:\Users\user\Desktop\H 05072022.xls, type: DROPPED Matched rule: SUSP_Excel4Macro_AutoOpen date = 2020-03-26, author = John Lambert @JohnLaTwC, description = Detects Excel4 macro use with auto open / close, score = 2fb198f6ad33d0f26fb94a1aa159fef7296e0421da68887b8f2548bbd227e58f
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\system32\IBmjgOoh\ Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70428B0 3_2_000007FEF70428B0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7099CD4 3_2_000007FEF7099CD4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7095AA0 3_2_000007FEF7095AA0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7087890 3_2_000007FEF7087890
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70967FC 3_2_000007FEF70967FC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF708C490 3_2_000007FEF708C490
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70864D8 3_2_000007FEF70864D8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70983C4 3_2_000007FEF70983C4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF708615C 3_2_000007FEF708615C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7084EA8 3_2_000007FEF7084EA8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7041B09 3_2_000007FEF7041B09
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7041B09 3_2_000007FEF7041B09
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7095750 3_2_000007FEF7095750
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF709B70C 3_2_000007FEF709B70C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF706D520 3_2_000007FEF706D520
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF709906C 3_2_000007FEF709906C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70950BC 3_2_000007FEF70950BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00130000 3_2_00130000
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180017414 3_2_0000000180017414
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002B6BC 3_2_000000018002B6BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001A804 3_2_000000018001A804
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001EB08 3_2_000000018001EB08
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180005B18 3_2_0000000180005B18
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180018B3C 3_2_0000000180018B3C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180011B88 3_2_0000000180011B88
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000CCC8 3_2_000000018000CCC8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001BD64 3_2_000000018001BD64
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180027E28 3_2_0000000180027E28
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000AFE4 3_2_000000018000AFE4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180001014 3_2_0000000180001014
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180024020 3_2_0000000180024020
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001B028 3_2_000000018001B028
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001406C 3_2_000000018001406C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180004078 3_2_0000000180004078
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002A088 3_2_000000018002A088
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800030BC 3_2_00000001800030BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800090D4 3_2_00000001800090D4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002B0EC 3_2_000000018002B0EC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000B0F8 3_2_000000018000B0F8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180016110 3_2_0000000180016110
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001A130 3_2_000000018001A130
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180017144 3_2_0000000180017144
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180005198 3_2_0000000180005198
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800041A8 3_2_00000001800041A8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000B1A8 3_2_000000018000B1A8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800031F0 3_2_00000001800031F0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013210 3_2_0000000180013210
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F238 3_2_000000018001F238
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001D254 3_2_000000018001D254
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000E254 3_2_000000018000E254
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000F290 3_2_000000018000F290
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000B2BC 3_2_000000018000B2BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800072E0 3_2_00000001800072E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800212FC 3_2_00000001800212FC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000D300 3_2_000000018000D300
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002A304 3_2_000000018002A304
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180023304 3_2_0000000180023304
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002632C 3_2_000000018002632C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180024330 3_2_0000000180024330
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180014368 3_2_0000000180014368
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180001368 3_2_0000000180001368
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800093AC 3_2_00000001800093AC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800193E0 3_2_00000001800193E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000B3E4 3_2_000000018000B3E4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800213FC 3_2_00000001800213FC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001A408 3_2_000000018001A408
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180016418 3_2_0000000180016418
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002344C 3_2_000000018002344C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000C458 3_2_000000018000C458
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180005484 3_2_0000000180005484
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800114A0 3_2_00000001800114A0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001E4A8 3_2_000000018001E4A8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001D4D0 3_2_000000018001D4D0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800284DC 3_2_00000001800284DC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800124E4 3_2_00000001800124E4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180026520 3_2_0000000180026520
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001B558 3_2_000000018001B558
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002155C 3_2_000000018002155C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002B570 3_2_000000018002B570
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010578 3_2_0000000180010578
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000F580 3_2_000000018000F580
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180014594 3_2_0000000180014594
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180016594 3_2_0000000180016594
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001C5AC 3_2_000000018001C5AC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800025D8 3_2_00000001800025D8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013610 3_2_0000000180013610
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F61C 3_2_000000018001F61C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001D620 3_2_000000018001D620
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001762C 3_2_000000018001762C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180022638 3_2_0000000180022638
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010680 3_2_0000000180010680
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000B698 3_2_000000018000B698
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180006698 3_2_0000000180006698
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002369C 3_2_000000018002369C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800276A4 3_2_00000001800276A4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800216A8 3_2_00000001800216A8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800146B4 3_2_00000001800146B4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800036E0 3_2_00000001800036E0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180002708 3_2_0000000180002708
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180019720 3_2_0000000180019720
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001C720 3_2_000000018001C720
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013724 3_2_0000000180013724
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001F764 3_2_000000018001F764
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001E7A4 3_2_000000018001E7A4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800127A4 3_2_00000001800127A4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800207D0 3_2_00000001800207D0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180002820 3_2_0000000180002820
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180004848 3_2_0000000180004848
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001484C 3_2_000000018001484C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000F850 3_2_000000018000F850
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180023894 3_2_0000000180023894
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001C8C0 3_2_000000018001C8C0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800178C4 3_2_00000001800178C4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180024918 3_2_0000000180024918
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000D92C 3_2_000000018000D92C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002093C 3_2_000000018002093C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180004948 3_2_0000000180004948
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002796C 3_2_000000018002796C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180016978 3_2_0000000180016978
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028990 3_2_0000000180028990
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800129BC 3_2_00000001800129BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001D9C4 3_2_000000018001D9C4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001C9F0 3_2_000000018001C9F0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_00000001800199F4 3_2_00000001800199F4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180029A40 3_2_0000000180029A40
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180003A9C 3_2_0000000180003A9C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180020AC4 3_2_0000000180020AC4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000FAD0 3_2_000000018000FAD0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180021AE0 3_2_0000000180021AE0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180002AE4 3_2_0000000180002AE4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180022AFC 3_2_0000000180022AFC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180017B24 3_2_0000000180017B24
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028B28 3_2_0000000180028B28
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180026B40 3_2_0000000180026B40
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010B60 3_2_0000000180010B60
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000CB6C 3_2_000000018000CB6C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000DB74 3_2_000000018000DB74
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013BB4 3_2_0000000180013BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180007BB4 3_2_0000000180007BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001ABD8 3_2_000000018001ABD8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000BC08 3_2_000000018000BC08
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180017C30 3_2_0000000180017C30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180022C48 3_2_0000000180022C48
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180015C50 3_2_0000000180015C50
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180004C64 3_2_0000000180004C64
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180020C68 3_2_0000000180020C68
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180010C68 3_2_0000000180010C68
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001FC70 3_2_000000018001FC70
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180007CAC 3_2_0000000180007CAC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180008CE0 3_2_0000000180008CE0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180003CE8 3_2_0000000180003CE8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001ACEC 3_2_000000018001ACEC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013D1C 3_2_0000000180013D1C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002BD20 3_2_000000018002BD20
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000BD24 3_2_000000018000BD24
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180021D2C 3_2_0000000180021D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180019D5C 3_2_0000000180019D5C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000ED84 3_2_000000018000ED84
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180029DA8 3_2_0000000180029DA8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180017DB0 3_2_0000000180017DB0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180020DBC 3_2_0000000180020DBC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180002DC0 3_2_0000000180002DC0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180023DD4 3_2_0000000180023DD4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180022E04 3_2_0000000180022E04
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180013E18 3_2_0000000180013E18
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180025E30 3_2_0000000180025E30
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000FE58 3_2_000000018000FE58
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001EE5C 3_2_000000018001EE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018002BE90 3_2_000000018002BE90
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180019EC0 3_2_0000000180019EC0
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180028EE8 3_2_0000000180028EE8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180024EF4 3_2_0000000180024EF4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180022F3C 3_2_0000000180022F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180026F3C 3_2_0000000180026F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180003F40 3_2_0000000180003F40
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180008F5C 3_2_0000000180008F5C
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180012F94 3_2_0000000180012F94
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001EFAC 3_2_000000018001EFAC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000DFCC 3_2_000000018000DFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018000EFCC 3_2_000000018000EFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00140000 4_2_00140000
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180017FEC 4_2_0000000180017FEC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001C9F0 4_2_000000018001C9F0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001A804 4_2_000000018001A804
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001A408 4_2_000000018001A408
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180027E28 4_2_0000000180027E28
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000F850 4_2_000000018000F850
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001406C 4_2_000000018001406C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180023894 4_2_0000000180023894
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180007CAC 4_2_0000000180007CAC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001C8C0 4_2_000000018001C8C0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002A304 4_2_000000018002A304
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180016110 4_2_0000000180016110
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180005B18 4_2_0000000180005B18
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180022F3C 4_2_0000000180022F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180018B3C 4_2_0000000180018B3C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001BD64 4_2_000000018001BD64
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180014368 4_2_0000000180014368
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180001368 4_2_0000000180001368
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800041A8 4_2_00000001800041A8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000AFE4 4_2_000000018000AFE4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000B3E4 4_2_000000018000B3E4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800031F0 4_2_00000001800031F0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800199F4 4_2_00000001800199F4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800213FC 4_2_00000001800213FC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180022E04 4_2_0000000180022E04
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000BC08 4_2_000000018000BC08
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180013210 4_2_0000000180013210
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180013610 4_2_0000000180013610
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180017414 4_2_0000000180017414
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180001014 4_2_0000000180001014
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180016418 4_2_0000000180016418
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180013E18 4_2_0000000180013E18
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001F61C 4_2_000000018001F61C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180024020 4_2_0000000180024020
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001D620 4_2_000000018001D620
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180002820 4_2_0000000180002820
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001B028 4_2_000000018001B028
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001762C 4_2_000000018001762C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180025E30 4_2_0000000180025E30
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180017C30 4_2_0000000180017C30
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180022638 4_2_0000000180022638
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001F238 4_2_000000018001F238
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180029A40 4_2_0000000180029A40
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180022C48 4_2_0000000180022C48
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180004848 4_2_0000000180004848
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002344C 4_2_000000018002344C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001484C 4_2_000000018001484C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180015C50 4_2_0000000180015C50
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001D254 4_2_000000018001D254
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000E254 4_2_000000018000E254
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000FE58 4_2_000000018000FE58
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000C458 4_2_000000018000C458
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001EE5C 4_2_000000018001EE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180004C64 4_2_0000000180004C64
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180020C68 4_2_0000000180020C68
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180010C68 4_2_0000000180010C68
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001FC70 4_2_000000018001FC70
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180004078 4_2_0000000180004078
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180010680 4_2_0000000180010680
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180005484 4_2_0000000180005484
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002A088 4_2_000000018002A088
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002BE90 4_2_000000018002BE90
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000F290 4_2_000000018000F290
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180006698 4_2_0000000180006698
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000B698 4_2_000000018000B698
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002369C 4_2_000000018002369C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180003A9C 4_2_0000000180003A9C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800114A0 4_2_00000001800114A0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800276A4 4_2_00000001800276A4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800216A8 4_2_00000001800216A8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001E4A8 4_2_000000018001E4A8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800146B4 4_2_00000001800146B4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002B6BC 4_2_000000018002B6BC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800030BC 4_2_00000001800030BC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000B2BC 4_2_000000018000B2BC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180019EC0 4_2_0000000180019EC0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180020AC4 4_2_0000000180020AC4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800178C4 4_2_00000001800178C4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000CCC8 4_2_000000018000CCC8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001D4D0 4_2_000000018001D4D0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000FAD0 4_2_000000018000FAD0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800090D4 4_2_00000001800090D4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800284DC 4_2_00000001800284DC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180021AE0 4_2_0000000180021AE0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800036E0 4_2_00000001800036E0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800072E0 4_2_00000001800072E0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180008CE0 4_2_0000000180008CE0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800124E4 4_2_00000001800124E4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180002AE4 4_2_0000000180002AE4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180028EE8 4_2_0000000180028EE8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180003CE8 4_2_0000000180003CE8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002B0EC 4_2_000000018002B0EC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001ACEC 4_2_000000018001ACEC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180024EF4 4_2_0000000180024EF4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000B0F8 4_2_000000018000B0F8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800212FC 4_2_00000001800212FC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180022AFC 4_2_0000000180022AFC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000D300 4_2_000000018000D300
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180023304 4_2_0000000180023304
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001EB08 4_2_000000018001EB08
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180002708 4_2_0000000180002708
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180024918 4_2_0000000180024918
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180013D1C 4_2_0000000180013D1C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002BD20 4_2_000000018002BD20
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180026520 4_2_0000000180026520
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001C720 4_2_000000018001C720
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180019720 4_2_0000000180019720
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180013724 4_2_0000000180013724
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180017B24 4_2_0000000180017B24
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000BD24 4_2_000000018000BD24
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180028B28 4_2_0000000180028B28
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180021D2C 4_2_0000000180021D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002632C 4_2_000000018002632C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000D92C 4_2_000000018000D92C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180024330 4_2_0000000180024330
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001A130 4_2_000000018001A130
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002093C 4_2_000000018002093C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180026F3C 4_2_0000000180026F3C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180026B40 4_2_0000000180026B40
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180003F40 4_2_0000000180003F40
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180017144 4_2_0000000180017144
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180004948 4_2_0000000180004948
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001B558 4_2_000000018001B558
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002155C 4_2_000000018002155C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180019D5C 4_2_0000000180019D5C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180008F5C 4_2_0000000180008F5C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180010B60 4_2_0000000180010B60
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001F764 4_2_000000018001F764
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002796C 4_2_000000018002796C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000CB6C 4_2_000000018000CB6C
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018002B570 4_2_000000018002B570
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000DB74 4_2_000000018000DB74
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180016978 4_2_0000000180016978
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180010578 4_2_0000000180010578
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000F580 4_2_000000018000F580
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000ED84 4_2_000000018000ED84
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180011B88 4_2_0000000180011B88
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180028990 4_2_0000000180028990
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180012F94 4_2_0000000180012F94
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180014594 4_2_0000000180014594
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180016594 4_2_0000000180016594
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180005198 4_2_0000000180005198
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001E7A4 4_2_000000018001E7A4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800127A4 4_2_00000001800127A4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180029DA8 4_2_0000000180029DA8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000B1A8 4_2_000000018000B1A8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001C5AC 4_2_000000018001C5AC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001EFAC 4_2_000000018001EFAC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800093AC 4_2_00000001800093AC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180017DB0 4_2_0000000180017DB0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180013BB4 4_2_0000000180013BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180007BB4 4_2_0000000180007BB4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180020DBC 4_2_0000000180020DBC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800129BC 4_2_00000001800129BC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180002DC0 4_2_0000000180002DC0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001D9C4 4_2_000000018001D9C4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000DFCC 4_2_000000018000DFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018000EFCC 4_2_000000018000EFCC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800207D0 4_2_00000001800207D0
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_0000000180023DD4 4_2_0000000180023DD4
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001ABD8 4_2_000000018001ABD8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800025D8 4_2_00000001800025D8
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_00000001800193E0 4_2_00000001800193E0
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF70417C6 appears 85 times
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF7041861 appears 208 times
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF70E54C8 appears 46 times
Source: H 05072022.xls Virustotal: Detection: 64%
Source: H 05072022.xls Metadefender: Detection: 37%
Source: H 05072022.xls ReversingLabs: Detection: 80%
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: unknown Process created: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt1.ocx
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\IBmjgOoh\HPiQbOm.dll"
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt2.ocx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt3.ocx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt4.ocx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt1.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt2.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt3.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhdt4.ocx Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\IBmjgOoh\HPiQbOm.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhdt1.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\CVR5466.tmp Jump to behavior
Source: classification engine Classification label: mal100.troj.expl.evad.winXLS@11/14@4/52
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70799B0 CoCreateInstance,SysAllocString,SendDlgItemMessageW,SysFreeString,SysFreeString, 3_2_000007FEF70799B0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: H 05072022.xls OLE indicator, Workbook stream: true
Source: H 05072022.xls.0.dr OLE indicator, Workbook stream: true
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000000018001A804 Process32FirstW,CreateToolhelp32Snapshot,Process32NextW,CloseHandle, 3_2_000000018001A804
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7042342 FindResourceW,LoadResource,LockResource, 3_2_000007FEF7042342
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: H 05072022.xls Initial sample: OLE indicators vbamacros = False
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_0000000180008C72 push ebp; ret 3_2_0000000180008C7D
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7092518 EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, 3_2_000007FEF7092518
Source: hhdt1.ocx.0.dr Static PE information: real checksum: 0xdba5b should be: 0xe1d25
Source: yXlTTXSuSsUlL[1].dll.0.dr Static PE information: real checksum: 0xdba5b should be: 0xe1d25
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\IBmjgOoh\HPiQbOm.dll"
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\IBmjgOoh\HPiQbOm.dll (copy) Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhdt1.ocx Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\IBmjgOoh\HPiQbOm.dll (copy) Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhdt1.ocx Jump to dropped file

Boot Survival

barindex
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhdt1.ocx Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\IBmjgOoh\HPiQbOm.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 672 Thread sleep time: -120000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 2020 Thread sleep time: -300000s >= -30000s Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\yXlTTXSuSsUlL[1].dll Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe API coverage: 1.4 %
Source: C:\Windows\System32\regsvr32.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF707F8AC VirtualQuery,GetSystemInfo,SetThreadStackGuarantee,VirtualAlloc,VirtualProtect, 3_2_000007FEF707F8AC
Source: C:\Windows\System32\regsvr32.exe Code function: 4_2_000000018001C9F0 FindFirstFileW,FindNextFileW, 4_2_000000018001C9F0
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70807C4 IsDebuggerPresent,__crtUnhandledException,GetCurrentProcess,TerminateProcess,TerminateProcess,HeapReAlloc, 3_2_000007FEF70807C4
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7092518 EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, 3_2_000007FEF7092518
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7092518 EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, 3_2_000007FEF7092518
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF709DE10 _lseeki64_nolock,_lseeki64_nolock,GetProcessHeap,HeapAlloc,_errno,_errno,_setmode_nolock,_write_nolock,__doserrno,_errno,_setmode_nolock,GetProcessHeap,HeapFree,_lseeki64_nolock,_get_osfhandle,SetEndOfFile,_errno,__doserrno,GetLastError,_lseeki64_nolock, 3_2_000007FEF709DE10
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70E4FD8 SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_000007FEF70E4FD8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70E4FD8 SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_000007FEF70E4FD8
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF708930C SetUnhandledExceptionFilter,UnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_000007FEF708930C

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 174.138.33.49 7080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\IBmjgOoh\HPiQbOm.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: _getptd,__lc_wcstolc,__get_qualified_locale,GetLocaleInfoEx,GetACP,_lock,free,_lock,__freetlocinfo,free, 3_2_000007FEF70864D8
Source: C:\Windows\System32\regsvr32.exe Code function: __crtGetLocaleInfoA,GetLastError,__crtGetLocaleInfoA,_calloc_crt,__crtGetLocaleInfoA,_calloc_crt,free,free,GetLocaleInfoEx,_calloc_crt,GetLocaleInfoEx,free, 3_2_000007FEF7088F14
Source: C:\Windows\System32\regsvr32.exe Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, 3_2_000007FEF709AF38
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoEx, 3_2_000007FEF70E4F38
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoEx,GetLocaleInfoEx,WideCharToMultiByte,free, 3_2_000007FEF709ADDC
Source: C:\Windows\System32\regsvr32.exe Code function: _getptd,TranslateName,GetLocaleNameFromLangCountry,GetLocaleNameFromLanguage,TranslateName,GetLocaleNameFromLangCountry,ProcessCodePage,IsValidCodePage,GetLocaleInfoEx,GetLocaleInfoEx,GetLocaleInfoEx,_itow_s,GetLocaleNameFromLanguage,CompareStringEx, 3_2_000007FEF7095750
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoEx, 3_2_000007FEF70955DC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoEx,GetLocaleInfoEx,GetACP, 3_2_000007FEF7095528
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoEx, 3_2_000007FEF709F2CB
Source: C:\Windows\System32\regsvr32.exe Code function: _getptd,GetLocaleInfoEx,GetLocaleInfoEx,TestDefaultCountry,GetLocaleInfoEx,TestDefaultCountry,_getptd,GetLocaleInfoEx, 3_2_000007FEF70950BC
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF7084CF8 cpuid 3_2_000007FEF7084CF8
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 3_2_000007FEF70E4F88 GetSystemTimeAsFileTime, 3_2_000007FEF70E4F88

Stealing of Sensitive Information

barindex
Source: Yara match File source: 00000004.00000002.1198679946.00000000002FA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 3.2.regsvr32.exe.160000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.regsvr32.exe.150000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.regsvr32.exe.160000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.regsvr32.exe.150000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000003.00000002.914740891.0000000000160000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.1198622373.0000000000150000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.915078556.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000004.00000002.1199191486.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs