http://127.0.0.1:HTTP/1.1
|
unknown
|
|
|
Name: |
http://127.0.0.1:HTTP/1.1
|
TargetID: |
1
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000001.00000002.520553295.0000000003151000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
low
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sakkal.comrm
|
unknown
|
|
|
Name: |
http://www.sakkal.comrm
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255282999.0000000006114000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255224533.0000000006113000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fonts.comjat
|
unknown
|
|
|
Name: |
http://www.fonts.comjat
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.251323429.00000000060EB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designers
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designers
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.258138745.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.259693042.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.265884768.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.257911788.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/Xx
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/Xx
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254595717.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254538096.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/Verd
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/Verd
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254595717.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254429222.00000000060DA000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254538096.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sajatypeworks.com
|
unknown
|
|
|
Name: |
http://www.sajatypeworks.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.250782932.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.250927671.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.250846587.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.250578869.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.250629587.00000000060EB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comas
|
unknown
|
|
|
Name: |
http://www.fontbureau.comas
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.271326038.00000000060D6000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.founder.com.cn/cn/cThe
|
unknown
|
|
|
Name: |
http://www.founder.com.cn/cn/cThe
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/jp/i9
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/jp/i9
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designersers
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designersers
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.258022793.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.258138745.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/?9g
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/?9g
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255290205.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254595717.00000000060DD000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255391228.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254429222.00000000060DA000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255232174.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254538096.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255439619.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255536119.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255031466.00000000060DD000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255607455.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255481061.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255099459.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sakkal.comf
|
unknown
|
|
|
Name: |
http://www.sakkal.comf
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255401180.00000000060E6000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255308698.00000000060E6000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255250069.00000000060E6000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/i9
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/i9
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.galapagosdesign.com/DPlease
|
unknown
|
|
|
Name: |
http://www.galapagosdesign.com/DPlease
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/Y0
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/Y0
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254595717.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.ascendercorp.com/typedesigners.html
|
unknown
|
|
|
Name: |
http://www.ascendercorp.com/typedesigners.html
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255262809.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255202145.0000000006101000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.urwpp.deDPlease
|
unknown
|
|
|
Name: |
http://www.urwpp.deDPlease
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.zhongyicts.com.cn
|
unknown
|
|
|
Name: |
http://www.zhongyicts.com.cn
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253689927.0000000006103000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com.TTF
|
unknown
|
|
|
Name: |
http://www.fontbureau.com.TTF
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.260416887.00000000060DB000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.259471570.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
https://api.ipify.org%
|
unknown
|
|
|
Name: |
https://api.ipify.org%
|
TargetID: |
1
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000001.00000002.521371650.00000000031F2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
low
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
|
unknown
|
|
|
Name: |
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.287383086.00000000046ED000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000001.00000000.269625557.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comtig
|
unknown
|
|
|
Name: |
http://www.carterandcone.comtig
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255750448.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255693586.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.253933848.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255516044.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.256346314.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255262809.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.256544652.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255635634.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254256532.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255461197.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254664468.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253917497.0000000006105000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253857719.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254357438.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255970374.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255202145.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255320276.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254571950.0000000006108000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254070990.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.256649188.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.galapagosdesign.com/M95
|
unknown
|
|
|
Name: |
http://www.galapagosdesign.com/M95
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261645746.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.261742667.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/Y0nf9
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/Y0nf9
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.galapagosdesign.com/
|
unknown
|
|
|
Name: |
http://www.galapagosdesign.com/
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261645746.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.261742667.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/t9
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/t9
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254634935.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254595717.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254429222.00000000060DA000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254538096.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255031466.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255099459.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comf
|
unknown
|
|
|
Name: |
http://www.carterandcone.comf
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253857719.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253819477.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.253804133.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253836809.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comcoma
|
unknown
|
|
|
Name: |
http://www.fontbureau.comcoma
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.260416887.00000000060DB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comd
|
unknown
|
|
|
Name: |
http://www.carterandcone.comd
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253857719.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253819477.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.253836809.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sajatypeworks.comegr
|
unknown
|
|
|
Name: |
http://www.sajatypeworks.comegr
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.250782932.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.250578869.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.250629587.00000000060EB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
|
unknown
|
|
|
Name: |
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
|
TargetID: |
1
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000001.00000002.520553295.0000000003151000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/jp/W8
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/jp/W8
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255031466.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255099459.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.jiyu-kobo.co.jp/M95
|
unknown
|
|
|
Name: |
http://www.jiyu-kobo.co.jp/M95
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254794551.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255290205.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255391228.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255232174.00000000060DD000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254860385.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255439619.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.255031466.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255099459.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.coml
|
unknown
|
|
|
Name: |
http://www.carterandcone.coml
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254070990.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254099387.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253979663.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253997155.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254013548.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.founder.com.cn/cn/
|
unknown
|
|
|
Name: |
http://www.founder.com.cn/cn/
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253482553.0000000006103000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designers/frere-jones.html
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designers/frere-jones.html
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comont
|
unknown
|
|
|
Name: |
http://www.carterandcone.comont
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254070990.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254099387.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.agfamonotype.A
|
unknown
|
|
|
Name: |
http://www.agfamonotype.A
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.257939001.0000000006113000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://MBStZn.com
|
unknown
|
|
|
Name: |
http://MBStZn.com
|
TargetID: |
1
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000001.00000002.520553295.0000000003151000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sajatypeworks.comria
|
unknown
|
|
|
Name: |
http://www.sajatypeworks.comria
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.250629587.00000000060EB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comionF
|
unknown
|
|
|
Name: |
http://www.fontbureau.comionF
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.271326038.00000000060D6000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comsig
|
unknown
|
|
|
Name: |
http://www.carterandcone.comsig
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253933848.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253917497.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.253857719.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254070990.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254099387.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.253979663.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253819477.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253997155.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253836809.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254013548.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253897098.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.zhongyicts.com.cn=
|
unknown
|
|
|
Name: |
http://www.zhongyicts.com.cn=
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253689927.0000000006103000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
low
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designersG
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designersG
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designers/?
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designers/?
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designers/cabarga.html/
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designers/cabarga.html/
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.259471570.00000000060DD000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.founder.com.cn/cn/bThe
|
unknown
|
|
|
Name: |
http://www.founder.com.cn/cn/bThe
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comcin
|
unknown
|
|
|
Name: |
http://www.carterandcone.comcin
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253997155.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254013548.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designers?
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designers?
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comams
|
unknown
|
|
|
Name: |
http://www.carterandcone.comams
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253933848.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.255262809.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254256532.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254664468.0000000006101000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253917497.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253857719.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254357438.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255202145.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254571950.0000000006108000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254070990.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.255068805.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254099387.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253979663.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254516942.0000000006103000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254933421.0000000006108000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254150676.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254821011.0000000006108000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254466136.0000000006101000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254991909.0000000006101000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253997155.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fonts.com//w
|
unknown
|
|
|
Name: |
http://www.fonts.com//w
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.251283967.00000000060EB000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.monotype.UC
|
unknown
|
|
|
Name: |
http://www.monotype.UC
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261855251.00000000060E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.261539461.00000000060DD000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.262337254.00000000060E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261656122.00000000060E2000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.262264309.00000000060E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comW8
|
unknown
|
|
|
Name: |
http://www.fontbureau.comW8
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.260416887.00000000060DB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.tiro.com
|
unknown
|
|
|
Name: |
http://www.tiro.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designersZ
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designersZ
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.257433913.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.257374815.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.goodfont.co.kr
|
unknown
|
|
|
Name: |
http://www.goodfont.co.kr
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.com
|
unknown
|
|
|
Name: |
http://www.carterandcone.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253897098.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.typography.netD
|
unknown
|
|
|
Name: |
http://www.typography.netD
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designersh
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designersh
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.258710516.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.258780346.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.galapagosdesign.com/staff/dennis.htm
|
unknown
|
|
|
Name: |
http://www.galapagosdesign.com/staff/dennis.htm
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261855251.00000000060E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.262337254.00000000060E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261656122.00000000060E2000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.262264309.00000000060E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://fontfabrik.com
|
unknown
|
|
|
Name: |
http://fontfabrik.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comw.m
|
unknown
|
|
|
Name: |
http://www.carterandcone.comw.m
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254256532.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254070990.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254099387.0000000006104000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.254150676.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254013548.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comits
|
unknown
|
|
|
Name: |
http://www.carterandcone.comits
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253933848.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253917497.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.254029297.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253979663.0000000006105000.00000004.00000800.00020000.00000000.sdmp,
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253997155.0000000006105000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.254013548.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designerse
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designerse
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.265995122.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.266070435.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.265884768.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.founder.ce
|
unknown
|
|
|
Name: |
http://www.founder.ce
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253405708.0000000006103000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
https://api.ipify.org%GETMozilla/5.0
|
unknown
|
|
|
Name: |
https://api.ipify.org%GETMozilla/5.0
|
TargetID: |
1
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000001.00000002.520553295.0000000003151000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
low
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com/designersv
|
unknown
|
|
|
Name: |
http://www.fontbureau.com/designersv
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.259946306.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.259985359.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comttoF
|
unknown
|
|
|
Name: |
http://www.fontbureau.comttoF
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.260416887.00000000060DB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fonts.com
|
unknown
|
|
|
Name: |
http://www.fonts.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sandoll.co.kr
|
unknown
|
|
|
Name: |
http://www.sandoll.co.kr
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.founder.com.cn/cnf
|
unknown
|
|
|
Name: |
http://www.founder.com.cn/cnf
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253366138.0000000006103000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253347704.0000000006103000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.galapagosdesign.com/staff/dennis.htmQ
|
unknown
|
|
|
Name: |
http://www.galapagosdesign.com/staff/dennis.htmQ
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.261586821.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.261709013.0000000006104000.00000004.00000800.00020000.00000000.sdmp, SWIFT copy.29112022.Pdf.exe,
00000000.00000003.261757335.0000000006104000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sakkal.com
|
unknown
|
|
|
Name: |
http://www.sakkal.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comsiva
|
unknown
|
|
|
Name: |
http://www.fontbureau.comsiva
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.260416887.00000000060DB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
unknown
|
|
|
Name: |
http://www.apache.org/licenses/LICENSE-2.0
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp, SWIFT
copy.29112022.Pdf.exe, 00000000.00000003.253632184.00000000060EA000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.carterandcone.comexc
|
unknown
|
|
|
Name: |
http://www.carterandcone.comexc
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.253857719.0000000006105000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.com
|
unknown
|
|
|
Name: |
http://www.fontbureau.com
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000002.290363546.00000000072E2000.00000004.00000800.00020000.00000000.sdmp
|
Reputation: |
high
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://DynDns.comDynDNS
|
unknown
|
|
|
Name: |
http://DynDns.comDynDNS
|
TargetID: |
1
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000001.00000002.520553295.0000000003151000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.fontbureau.comF
|
unknown
|
|
|
Name: |
http://www.fontbureau.comF
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.260416887.00000000060DB000.00000004.00000800.00020000.00000000.sdmp
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
http://www.sajatypeworks.comu
|
unknown
|
|
|
Name: |
http://www.sajatypeworks.comu
|
TargetID: |
0
|
From Memory: |
true
|
Current Path: |
C:\Users\user\Desktop\SWIFT copy.29112022.Pdf.exe
|
Source: |
SWIFT copy.29112022.Pdf.exe, 00000000.00000003.250782932.00000000060EB000.00000004.00000800.00020000.00000000.sdmp, SW | |