4.0
中危

05123db740f02a3867ab928d6aac43c85b09ab6ecac1d77225c0ea7b9897bf26

05123db740f02a3867ab928d6aac43c85b09ab6ecac1d77225c0ea7b9897bf26.exe

分析耗时

139s

最近分析

390天前

文件大小

50.5KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER ULISE
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.55
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Agent-ASIP [Trj] 20191001 18.4.3895.0
Baidu Win32.Trojan-Downloader.Small.ck 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20191001 2013.8.14.323
McAfee Downloader-FVF!18EAA61AAF04 20191001 6.0.6.653
Tencent None 20191001 1.0.0.1
静态指标
检查进程是否被调试器调试 (2 个事件)
Time & API Arguments Status Return Repeated
1727545298.625375
IsDebuggerPresent
failed 0 0
1727545299.109375
IsDebuggerPresent
failed 0 0
可执行文件包含未知的 PE 段名称,可能指示打包器(可能是误报) (1 个事件)
section .imports
行为判定
动态指标
提取了一个或多个潜在有趣的缓冲区,这些缓冲区通常包含注入的代码、配置数据等。
分配可读-可写-可执行内存(通常用于自解压) (6 个事件)
Time & API Arguments Status Return Repeated
1727545298.625375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03190000
region_size: 1708032
allocation_type: 8192 (MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2400
success 0 0
1727545298.625375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03330000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2400
success 0 0
1727545298.625375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03340000
region_size: 4194304
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2400
success 0 0
1727545299.109375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x031c0000
region_size: 1314816
allocation_type: 8192 (MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2656
success 0 0
1727545299.109375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03300000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2656
success 0 0
1727545299.109375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03310000
region_size: 4194304
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 2656
success 0 0
在文件系统上创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
投放一个二进制文件并执行它 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
将可执行文件投放到用户的 AppData 文件夹 (1 个事件)
file C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
一个进程创建了一个隐藏窗口 (1 个事件)
Time & API Arguments Status Return Repeated
1727545298.781375
ShellExecuteExW
filepath: C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
filepath_r: C:\Users\ADMINI~1\AppData\Local\Temp\hhcbrnaff.exe
parameters:
show_type: 0
success 1 0
检查适配器地址以检测虚拟网络接口 (50 out of 3320 个事件)
Time & API Arguments Status Return Repeated
1727545324.171375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545324.171375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545324.171375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545324.187375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545324.203375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545324.203375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545324.218375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545324.218375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545331.531375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545331.546375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545331.546375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545331.546375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545331.562375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545331.578375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545331.578375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545331.578375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545331.703375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545331.703375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545331.703375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545331.718375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545331.734375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545331.734375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545331.750375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545331.750375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545331.953375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545331.968375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545331.968375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545331.968375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545332.000375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545332.000375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545332.000375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545332.015375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545332.171375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545332.171375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545332.187375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545332.187375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545332.203375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545332.203375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545332.218375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545332.218375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545332.328375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545332.328375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545332.343375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545332.343375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545332.359375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545332.375375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727545332.375375
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727545332.375375
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727545332.578375
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727545332.578375
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': 'UPX1', 'virtual_address': '0x00007000', 'virtual_size': '0x00002000', 'size_of_data': '0x00002000', 'entropy': 7.139039520942322} entropy 7.139039520942322 description 发现高熵的节
entropy 0.2077922077922078 description 此PE文件的整体熵值较高
可执行文件使用UPX压缩 (2 个事件)
section UPX0 description 节名称指示UPX
section UPX1 description 节名称指示UPX
网络通信
一个或多个缓冲区包含嵌入的PE文件 (1 个事件)
buffer Buffer with sha1: 0d22af1d0d72870672eb36e666f9a5eb8cd9dd43
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 54 个反病毒引擎识别为恶意 (50 out of 54 个事件)
ALYac Gen:Variant.Ulise.44925
APEX Malicious
AVG Win32:Agent-ASIP [Trj]
Acronis suspicious
Ad-Aware Gen:Variant.Ulise.44925
AhnLab-V3 Trojan/Win32.Fakon.R257890
Antiy-AVL Trojan/Win32.AGeneric
Arcabit Trojan.Ulise.DAF7D
Avast Win32:Agent-ASIP [Trj]
Avira TR/Spy.Zbot.amoan
Baidu Win32.Trojan-Downloader.Small.ck
BitDefender Gen:Variant.Ulise.44925
CAT-QuickHeal TrojanDownloader.Upatre
ClamAV Win.Downloader.Upatre-5744087-0
Comodo Packed.Win32.MUPX.Gen@24tbus
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.aaf040
Cylance Unsafe
Cyren W32/S-348f8679!Eldorado
DrWeb Trojan.DownLoad3.28161
ESET-NOD32 Win32/TrojanDownloader.Small.AAB
Emsisoft Gen:Variant.Ulise.44925 (B)
Endgame malicious (high confidence)
F-Prot W32/S-348f8679!Eldorado
F-Secure Trojan.TR/Spy.Zbot.amoan
FireEye Generic.mg.18eaa61aaf040667
Fortinet W32/Agent.AEJB!tr
GData Gen:Variant.Ulise.44925
Ikarus Trojan-PWS.Win32.Fareit
Invincea heuristic
Jiangmin Trojan/Agent.hnzm
K7AntiVirus Trojan ( 0040f6941 )
K7GW Trojan ( 0040f6941 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=82)
Malwarebytes Trojan.Zbot
McAfee Downloader-FVF!18EAA61AAF04
McAfee-GW-Edition BehavesLike.Win32.Cutwail.qt
MicroWorld-eScan Gen:Variant.Ulise.44925
Microsoft TrojanDownloader:Win32/Upatre.A
NANO-Antivirus Trojan.Win32.DownLoad3.clryhy
Panda Trj/Genetic.gen
Qihoo-360 HEUR/QVM19.1.4239.Malware.Gen
Rising Trojan.Crypto!1.9E08 (CLASSIC)
SUPERAntiSpyware Trojan.Agent/Gen-Zbot
SentinelOne DFI - Malicious PE
Sophos Troj/Zbot-GTA
Symantec ML.Attribute.HighConfidence
Trapmine malicious.high.ml.score
VBA32 BScope.Trojan.Download
连接到不再响应请求的 IP 地址(合法服务通常会保持运行) (3 个事件)
dead_host 156.254.147.137:443
dead_host 124.225.27.62:80
dead_host 124.225.27.61:80
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-10-28 20:23:24

PE Imphash

81570638ac265a5d003f10d4aed45e1d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00006000 0x00006000 3.2379371706857465
UPX1 0x00007000 0x00002000 0x00002000 7.139039520942322
.rsrc 0x00009000 0x00002000 0x00001800 4.6122840734911525
.imports 0x0000b000 0x00001000 0x00000200 3.5346881655003766

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000917c 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_DIALOG 0x00006020 0x000000e8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x0000a028 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x0000a040 0x00000324 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_MANIFEST 0x0000a368 0x00000193 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library KERNEL32.DLL:
0x4040b0 ExitProcess
0x4040b4 FreeLibrary
0x4040b8 GetModuleHandleA
0x4040bc GetProcAddress
0x4040c0 HeapCreate
0x4040c4 HeapAlloc
Library Msacm32.dll:
0x4041fc acmStreamOpen
Library user32.dll:
0x40414c LoadIconA
0x404150 LoadCursorA
0x404154 RegisterClassA
0x404158 CreateWindowExA
0x40415c GetMessageA
0x404160 DispatchMessageA
0x404164 DefWindowProcA
0x404168 PostQuitMessage
Library Winmm.dll:
0x40421c mciSendStringA

L!This program cannot be run in DOS mode.
.imports
f?MZue
W<f:PEuYUBx
D$(D$,
1P>?GFFP
open waveaudio
TranslateMessage
LoadLibraryExA
user32.dll
ExitProcess
FreeLibrary
GetModuleHandleA
GetProcAddress
HeapCreate
HeapAlloc
acmStreamOpen
LoadIconA
LoadCursorA
RegisterClassA
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
mciSendStringA
`.data
.idata
open waveaudio
TranslateMessage/
LoadLibryExA
user32.dllR'
f#|8on6
@&dIdI&&
gAL2$2$e*#LI
{C$L$L2M2
GHEIDdYJ/
C?+++eCGG&_qc
G|8Qq0X
igG?l3
#o5_;|
;YY)O^
Aaswk=
p#6q?XlA8}?z
u!C_KwGM
]7Fo-"8B
;,Y*WG
!?[0`w
doMm_9WB
0XM'31!I9;
#_!k?K
_tCAgCV3%CYu
B@&dKe;;
bEK>33
@r]w;
%kK!Km3f@qG:]w
IgG}A
\!FA`W=
U(5\tN
U(Yh[7
a~uk56
R#AkZ64M
m4ol[;
4pA|6M
TuxaxP
]k-%ZG{
/PMQIM
[X(Q=i
PjU*)Fvy
&mV-t6
10`n[_b
T8i-[x
_ProcessFree
GetModuleHand
*Addr.HeapC
[A1acmStmOAfk
Cursor
sLrCla^
bf,oM6Qui3
2mc$hsiSd/gCRPE
<WnR&%JK
-,`.dat!`aM
n.i(@KS6"'.rK`cPS&'
XPTPSWXaD$j
#######
###;KK>
26;2+##########
#########
#####+bEXL
+######+
#####3
######3#
PD[>J22Ib|tLx63
#######3#>>
vDDP>2
########3+ug
DW[[FvV####
########3#J~~3#5gJIk#
3333333333+g +zT
##++++######
3333333333#J%Tz+33#3333######
33333333333+
#3#############
33333333333@II#3#3###########
33333333333@+333##3#########
33333333@?a
+23333##3#######
332@j+23333333#######
j@33333333#######
2+jj23333333333####
$2+I@33333333333##
$$$$$2+@2333333333#
$$$$$$$
al2333333333
$$$233333333
C&SCCCSCS&&&&
&&&&$$
7:::::::****************ss****@$$$$$
788888881;111n;;;11p;11111111;
))))))
o,,,,,,,L6,6Lr66rq6,,,,,,,E
)f/HHHH/
8(((((,Lx|>>Eq6,(,((,EM&/-999N/
K((((((XmV#R?DlV((((((EMC/N9<<<<<
,444444X|JJVT
DRmXF4444F4VMC-9<UUU
(444444X3?
DPIDP#F04440tM
4000000y2WIWRIuRI
0000050
5y{kkJ0? D~`f9f
0%%%%%%_
3^%%%%%y`f\f#
%%%%%%%%^_a%G_a%%G=%%%%%%^`f\f#
%%%%%%%%%BB%%%BB%GG%BB%GGGGG%G`f
G.......'''''''''''''''''''''.
-----------------d-)/
&&&&$$$&
$$$$$$$
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
KERNEL32.DLL
Msacm32.dll
user32.dll
Winmm.dll
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
acmStreamOpen
LoadIconA
mciSendStringA
KERNEL32.DLL
ExitProcess
FreeLibrary
GetModuleHandleA
GetProcAddress
HeapCreate
HeapAlloc
Msacm32.dll
acmStreamOpen
user32.dll
LoadIconA
LoadCursorA
RegisterClassA
CreateWindowExA
GetMessageA
DispatchMessageA
DefWindowProcA
PostQuitMessage
Winmm.dll
mciSendStringA
About
MS Sans Serif
VS_VERSION_INFO
StringFileInfo
08000025
Comments
CompanyName
MS Corporation
FileDescrsiption
note.exe
FileVersion
2.0.0.2
InternalName
note.exe
LegalCopyright
Copyright (C) 2005
LegalTrademarks
OriginalFilename
note.exe
PrivateBuild
ProductName
ProductVersion
3.0.0.3
SpecialBuild
VarFileInfo
Translation
C:\DOCUME~1\7B5C~1\LOCALS~1\Temp\Rar$EX00.797\20131028123874512.exe
C:\yHYVpVPJ.exe
C:\T3QZlL_W.exe
C:\4YrXDc03.exe
C:\0zqwrF4p.exe
C:\SBxmHrrQ.exe
C:\O_1JoWHK.exe
C:\V4dhZuhh.exe
C:\xUH9uoqB.exe
C:\WyERJps4.exe
C:\aqlMXXNu.exe
C:\_5N47dL7.exe
C:\7t8MLn9S.exe
C:\BQhnoydG.exe
C:\p4NX5EYG.exe
C:\6gdhCqjr.exe
C:\Q1tcJMlS.exe
C:\WIxyldE8.exe
C:\sHk7BWPD.exe
C:\wiCTHv5Z.exe
C:\l9gMSP2j.exe
C:\I9uU8Hue.exe
C:\hwF_6Qo5.exe
C:\bSh9UlPJ.exe
C:\a5hz_nsE.exe
C:\YEfwxWFW.exe
C:\pR1Wuw8H.exe
C:\_l57L4Gc.exe
C:\cHaMPbts.exe
C:\YFzmNsSd.exe
C:\nFrMRXUv.exe
C:\253a7ad5d469934c1e4c521904dfa0a1ac55cf6887d7a5c3925f87d9d5bca088
C:\o8IP2_H7.exe
C:\sKI_1QRr.exe
C:\QvFzM1Ht.exe
C:\96fd9538ce4e7f79a2f473bdd4571e207da0b190c6dd8dc51016fb748fcb8227
C:\1d92b8fc540be4139a66c8737de15125aa54aa97b161ccbcb3b177f323c6c88a
C:\onOWsTNS.exe
C:\80f1cccf83ad1fe80e65c10b30121650e5f48a1e2e54d61078de44b53ce6c9ce
C:\PpyJ3PkH.exe
C:\7e6aafce59756002a8e28aa313786aab5961e0f4c84331197172cff54719e8d3
C:\4ee2ff54b499a9a84c41936b9e81b4599c4cb0dfe7c59e19826b5dccb82d0331
C:\535eabb09e405d25c0b9e64cb195b2526338fb62ebf74cd4ee0bd92a6f948c3e
C:\e8157c9fa247ca2f627becf6ab15dea810c22084756008c93703f221b3aaf35e
C:\324181edbad8ce72dd25072fc44988ff236cd1836fd58018f8bad9782060303b
C:\b3077ca0151df4b09a83733db7a15e7592a909a235b2a1c04fda77ade9fcc5f8
C:\ibpS3_68.exe
C:\Users\Lisa\Desktop\uNsZiF6I.exe
C:\8f75379131e87c16378823299eb5cef87c936ca7c5aebe7ac68eb0a99e45e41e
C:\Documents and Settings\Administrator\Desktop\lsIVepY1.exe
C:\RinZSR3O.exe
C:\4c48cbba920b33fd2e9538e009a7334db99e70d2436a823247734e0040b16a85
C:\60c8c7f24fbfc5bcd349bd9bf5fb872172b196265b2e7ab0bc0e79ff70c666cf
C:\0c675fc2ab7609dd5768e6b22ac8e77f0bbb00e496d97628961095205f2ee7e7
C:\a33ca48cf7558df2a1f15962bbabae107fed01e81d60a89e54450cb165f71a4d
C:\0ae887282523b05a68172da6682d2580cad1ac98655b73bd1c17cad4a651ce1a
C:\a90bd3da471ae934d6ac12609fcecf937d864f6d1b296323cd2879657877055c
C:\c80599679cc281ff413334a8ba199fa3d15d6fe36835e1f6a2d3da59358ddaa1
C:\ba1f3323e2aef6df7e011a7b473805a415e2835573a9a55422bafaa4cf678cce
C:\c94bd0dca4f4c726b9fada1156f63299ccf0b3ca6de5e8ebdb0cfddcf7d4fff5
c:\analyse\1554010980.4735847_ee342b06-78f0-426b-ac35-7d197724436f
C:\Users\Virtual\AppData\Local\Temp\89ec80228b91dd37cd52c5f167a222ae945392fe745ec6fb2e396753f8c9b269.exe
C:\34dedfeaa08bcfe2479ce42aa1b4f82262cdace49f7d83d3af917734d16a2f4b
C:\1827ba1528b5a22178f51a75a771f733143e92fab9ce5dbf9f28d600e362b530
C:\0d6210ee2c78d032e46124bd4c3483091a388738d86f350052633341396e4080
C:\Users\Lisa\Desktop\yBuPZokL.exe
C:\Lj5VSOl_.exe
C:\c30666d378fc5f7e69ade4dd8bfbcf8f5e24d3a3f5f18a66b1999ec174a08fb4
C:\Users\Petra\AppData\Local\Temp\hhcbrnaff.pe32
C:\Users\Lisa\Desktop\KUDPbSyC.exe
C:\ZJOzVq2h.exe
C:\Documents and Settings\Administrator\Desktop\vC3miaV8.exe
C:\mmN9OphC.exe
C:\7f60ab3edc97316bb927ea16945ae556cee7c60478556ac73eaa3ebc42c67993
C:\777762df35f2646b871c21b49de5208c7f6e32de5c982fce15bd45b8d47f3399
C:\z1RuCPbe.exe
C:\9835a0ac3ec9c13f24e575d6e2165442be6c597650a272c745acf85c6007c374
C:\c5324a71a1bf3ed23729ddd9ae0a35b7e6354049ef985bb685935f395c59d9d3
C:\ffb898044a83cab152c522baf7e0702e577c8be2a51567eae9a4503a38539d99
C:\Users\Lisa\Desktop\e7rd1ARA.exe
C:\f0227b369cae909077b109cf821fa8c4c96bec98fc497d43466e4dea6426e2e6
C:\282a3e0f84b51218e7ec28739d7acc08e2325a5823facde6b6a63a742f8ecf33
C:\3b39f3e3548c8bda83386325f4bef1e29fa492f1f842ecca414f22a3af865a88
C:\Documents and Settings\luser\Desktop\p6uI6Zz9.exe
C:\yidK2wer.exe
C:\a40de7f2366ee0dc6f5ea4b2b566fd764f265ff767eb6302ad9eabebe24eab82
C:\Documents and Settings\Administrator\Desktop\yAvM5Z9d.exe
C:\6GaXkbuz.exe
C:\af2d6d948f47f5e275301f719623bc6de46b12af66397021429399628f94ed40
C:\a6a83c41f82a94359c23f0e44e70f6c146521495ff96e9f6e8d7f56f3bc64f7a
C:\Users\Virtual\AppData\Local\Temp\dcbf8f27c800cb1d8a223ce388e7555377fc830f05f0bd33c3267fbf9e0bbf08.exe
C:\1c271b6c8870ef19c70e01ff03ecb9d01197b5d629ba5da7413472736cd8c3a9
C:\f74bea5cd4b5155947e3c323b75cf3f8b06ee11560aab6037798ed5405d152ab
C:\HMOPBFnK.exe
C:\Users\admin\Downloads\important_document.exe
C:\Users\admin\Downloads\important_document.exe
C:\89d2a8c1a60f49be0b8c828490dce7a774beaa07566e61a317315bcf7e01cc23
C:\Users\admin\Downloads\factura.exe
C:\e146350bde54adcb6133df1a4bc75c39a49732b49ff1fd14d691bb942de30c2e
C:\Users\admin\Downloads\invoice.exe
C:\4642dabe91aebcc19467ce0b3feaf3efae43831d85f7a168da3ba48e80ba9c73
C:\Users\admin\Downloads\important_document.exe
C:\Users\admin\Downloads\invoice.exe
C:\3c076ad14840b2979256b65a20857ac8078e1ad617e11dde68262db7302bd76f
C:\07d756a908f39567858bc992c26e000c2cc8d89ffe99c9e04bb73ed50b0c0f62
C:\Documents and Settings\Administrator\Desktop\xCfe07a5.exe
C:\915d1afcf61cbd8d5d658531497164aed1573a75dc4638de0a64b5ef4d803131
C:\Users\Petra\AppData\Local\Temp\hhcbrnaff.pe32
C:\Users\admin\Downloads\important_document.exe
C:\77281d53e181a8d676ca1622d7a4b9f109ab9cc7f04b47d38e4e652bdce33b11
C:\Users\admin\Downloads\sample.exe
C:\9f3e06438b5f006da2049926c917a899288169985c0ef410388819b5cc9cd11d
C:\2e89d341ad5866ff26279a4c78c9874531b2625268dbdb817314509c4811d738
C:\CpIaEMGQ.exe
C:\Users\admin\Downloads\sample.exe
C:\f3a9fd0d52fa922e2ec2cdfcf1794555d9bf664f70aaf9f1257481e95b935da4
C:\Documents and Settings\Administrator\Desktop\EPkG9JPJ.exe
C:\8h0mX5xc.exe
C:\e95c62a605f2670a2f28bcb4e2d876dd5bacbc8d9307e990e720ad01724be439
C:\baba485139cb1853dac6fa31af8d305bdb02b21e8297787a148fee46efc1d249
C:\Users\admin\Downloads\hhcbrnaff.exe
C:\Users\Petra\AppData\Local\Temp\hhcbrnaff.pe32
C:\Users\admin\Downloads\49650f725a9fdbde_hhcbrnaff.exe

Process Tree


05123db740f02a3867ab928d6aac43c85b09ab6ecac1d77225c0ea7b9897bf26.exe, PID: 2400, Parent PID: 2948

default registry file network process services synchronisation iexplore office pdf

hhcbrnaff.exe, PID: 2656, Parent PID: 2400

default registry file network process services synchronisation iexplore office pdf

TCP

Source Source Port Destination Destination Port
192.168.56.101 49164 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49165 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49166 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49167 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49168 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49169 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49170 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49171 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49172 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49173 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49174 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49175 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49176 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49177 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49178 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49179 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49180 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49181 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49182 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49183 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49184 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49185 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49186 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49187 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49188 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49189 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49190 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49191 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49192 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49193 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49194 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49195 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49196 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49197 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49198 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49199 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49200 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49201 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49202 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49203 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49204 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49205 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49206 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49207 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49208 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49209 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49210 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49211 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49212 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49213 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49214 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49215 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49216 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49217 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49218 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49219 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49220 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49221 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49222 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49223 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49224 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49225 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49226 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49227 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49228 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49229 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49230 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49231 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49232 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49233 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49234 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49235 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49236 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49237 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49238 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49239 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49240 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49241 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49242 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49243 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49244 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49245 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49246 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49247 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49248 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49249 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49250 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49251 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49252 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49253 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49254 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49255 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49256 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49257 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49258 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49259 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49260 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49261 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49262 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49263 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49264 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49265 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49266 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49267 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49268 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49269 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49270 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49271 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49272 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49273 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49274 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49275 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49276 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49277 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49278 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49279 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49280 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49281 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49282 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49283 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49284 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49285 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49286 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49287 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49288 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49289 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49290 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49291 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49292 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49293 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49294 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49295 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49296 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49297 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49298 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49299 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49300 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49301 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49302 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49303 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49304 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49305 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49306 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49307 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49308 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49309 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49310 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49311 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49312 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49313 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49314 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49315 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49316 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49317 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49318 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49319 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49320 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49321 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49322 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49323 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49324 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49325 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49326 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49327 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49328 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49329 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49330 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49331 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49332 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49333 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49334 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49335 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49336 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49337 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49338 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49339 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49340 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49341 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49342 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49343 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49344 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49345 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49346 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49347 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49348 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49349 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49350 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49351 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49352 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49353 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49354 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49355 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49356 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49357 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49358 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49359 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49360 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49361 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49362 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49363 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49364 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49365 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49366 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49367 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49368 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49369 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49370 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49371 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49372 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49373 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49374 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49375 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49376 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49377 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49378 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49379 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49380 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49381 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49382 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49383 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49384 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49385 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49386 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49387 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49388 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49389 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49390 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49391 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49392 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49393 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49394 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49395 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49396 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49397 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49398 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49399 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49400 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49401 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49402 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49403 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49404 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49405 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49406 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49407 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49408 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49409 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49410 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49411 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49412 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49413 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49414 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49415 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49416 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49417 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49418 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49419 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49420 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49421 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49422 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49423 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49424 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49425 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49426 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49427 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49428 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49429 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49430 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49431 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49432 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49433 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49434 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49435 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49436 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49437 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49438 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49439 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49440 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49441 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49442 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49443 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49444 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49445 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49446 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49447 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49448 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49449 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49450 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49451 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49452 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49453 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49454 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49455 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49456 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49457 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49458 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49459 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49460 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49461 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49462 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49463 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49464 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49465 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49466 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49467 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49468 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49469 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49470 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49471 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49472 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49473 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49474 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49475 124.225.27.62 www.download.windowsupdate.com 80
192.168.56.101 49476 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49477 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49478 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49479 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49480 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49481 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49482 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49483 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49484 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49485 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49486 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49487 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49488 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49489 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49490 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49491 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49492 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49493 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49494 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49495 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49496 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49497 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49498 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49499 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49500 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49501 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49502 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49503 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49504 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49505 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49506 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49507 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49508 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49509 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49510 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49511 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49512 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49513 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49514 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49515 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49516 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49517 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49518 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49519 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49520 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49521 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49522 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49523 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49524 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49525 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49526 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49527 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49528 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49529 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49530 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49531 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49532 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49533 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49534 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49535 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49536 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49537 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49538 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49539 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49540 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49541 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49542 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49543 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49544 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49545 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49546 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49547 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49548 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49549 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49550 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49551 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49552 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49553 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49554 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49555 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49556 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49557 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49558 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49559 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49560 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49561 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49562 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49563 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49564 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49565 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49566 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49567 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49568 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49569 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49570 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49571 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49572 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49573 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49574 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49575 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49576 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49577 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49578 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49579 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49580 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49581 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49582 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49583 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49584 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49585 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49586 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49587 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49588 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49589 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49590 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49591 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49592 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49593 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49594 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49595 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49596 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49597 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49598 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49599 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49600 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49601 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49602 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49603 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49604 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49605 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49606 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49607 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49608 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49609 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49610 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49611 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49612 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49613 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49614 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49615 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49616 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49617 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49618 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49619 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49620 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49621 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49622 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49623 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49624 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49625 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49626 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49627 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49628 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49629 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49630 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49631 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49632 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49633 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49634 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49635 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49636 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49637 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49638 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49639 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49640 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49641 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49642 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49643 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49644 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49645 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49646 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49647 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49648 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49649 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49650 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49651 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49652 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49653 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49654 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49655 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49656 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49657 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49658 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49659 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49660 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49661 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49662 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49663 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49664 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49665 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49666 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49667 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49668 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49669 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49670 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49671 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49672 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49673 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49674 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49675 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49676 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49677 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49678 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49679 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49680 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49681 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49682 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49683 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49684 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49685 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49686 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49687 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49688 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49689 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49690 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49691 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49692 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49694 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49695 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49696 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49697 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49698 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49699 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49700 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49701 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49702 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49703 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49704 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49705 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49706 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49707 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49708 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49709 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49710 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49711 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49712 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49713 156.254.147.137 mokoshoponline.com 443
192.168.56.101 49714 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49715 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49716 124.225.27.61 www.download.windowsupdate.com 80
192.168.56.101 49717 156.254.147.137 mokoshoponline.com 443

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 57665 114.114.114.114 53
192.168.56.101 57665 8.8.8.8 53
192.168.56.101 51758 114.114.114.114 53
192.168.56.101 51758 8.8.8.8 53
192.168.56.101 52215 8.8.8.8 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 69d88f3214c7bd70_94308059b57b3142e455b38a6eb92015
Filepath C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
Size 342.0B
Processes 2656 (hhcbrnaff.exe)
Type data
MD5 7e9a28eae8821da7229c100f7c97436d
SHA1 0a3a0bbbb01ca30168860992b267e9e006659760
SHA256 69d88f3214c7bd70e7772a671eb3fcc710aa9911ad6aa8e3b3da868a0c58c992
CRC32 A4CF875B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a9a20ed0913123f8_tar90c6.tmp
Filepath C:\Users\Administrator\AppData\Local\Temp\Tar90C6.tmp
Size 181.9KB
Processes 2656 (hhcbrnaff.exe)
Type data
MD5 4ea6026cf93ec6338144661bf1202cd1
SHA1 a1dec9044f750ad887935a01430bf49322fbdcb7
SHA256 8efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8
CRC32 6CA8AF0B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e9df1f030e70d63e_hhcbrnaff.exe
Filepath C:\Users\Administrator\AppData\Local\Temp\hhcbrnaff.exe
Size 50.8KB
Processes 2400 (05123db740f02a3867ab928d6aac43c85b09ab6ecac1d77225c0ea7b9897bf26.exe)
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed
MD5 e36efd53472ab8f118e8a8cfa8dfefaa
SHA1 0322bb0650b2fb0fb351980c645741f97a2a2850
SHA256 e9df1f030e70d63e609f5e50cafcbcebf184a8668e5f61f383f9b3df699ebcdd
CRC32 4BD942D0
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 0d22af1d0d72870672eb36e666f9a5eb8cd9dd43
Size 4.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 52adfff604af1d0434bbadc9c9859061
SHA1 0d22af1d0d72870672eb36e666f9a5eb8cd9dd43
SHA256 f14074d4ec44eb3c708ff1fc4b07f459a396a87542112d80e5cd268304abe580
CRC32 BAEF690E
ssdeep None
Yara None matched
VirusTotal Search for analysis