Time & API | Arguments | Status | Return | Repeated |
---|---|---|---|---|
1621013287.295874 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
1621013294.389999 GetComputerNameW |
computer_name:
OSKAR-PC
|
success | 1 | 0 |
section | .ndata |
request | GET http://www.google-analytics.com/collect?v=1&t=pageview&tid=&z=835147829&cid=2409ecdf-da11-4ad7-9f60-73a0f1e4c856&ua=Mozilla%2F5.0+%28Windows+NT+6.1%3B+Win64%3B+x64%3B+rv%3A47.0%29+Gecko%2F20100101+Firefox%2F47.0&sr=800x600&de=cp936&ul=zh_CN&dl=%2Finstaller%2FinstallSuccess&cd1=Win6.1%28x64%29&cd4= |
request | GET http://www.google-analytics.com/collect?v=1&t=pageview&tid=&z=413705617&cid=2409ecdf-da11-4ad7-9f60-73a0f1e4c856&ua=Mozilla%2F5.0+%28Windows+NT+6.1%3B+Win64%3B+x64%3B+rv%3A47.0%29+Gecko%2F20100101+Firefox%2F47.0&sr=800x600&de=cp936&ul=zh_CN&dl=%2Fgen%2Ftrack%2Flaunch&cd1=Win6.1%28x64%29&cd4= |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\libcrypto-1_1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nss7849.tmp\nsExec.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\uninstall.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\pythonw.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\python37.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\vcruntime140.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\ucrtbase.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\python3.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\sqlite3.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\libssl-1_1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\python.exe |
cmdline | cmd /c schtasks /create /f /tn "mysidex2" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmppyei1ysf" |
cmdline | schtasks /create /f /tn "mysidex" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmpnow_cesc" |
cmdline | cmd /c schtasks /create /f /tn "mysidex" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmpnow_cesc" |
cmdline | schtasks /create /f /tn "mysidex2" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmppyei1ysf" |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_distutils_findvs.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_ssl.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_msi.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_socket.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\python.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\pyexpat.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_lzma.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\uninstall.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\python3.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_elementtree.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\sqlite3.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\ucrtbase.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\libssl-1_1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_decimal.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_hashlib.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\unicodedata.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_ctypes.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_asyncio.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_sqlite3.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_multiprocessing.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\python37.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\pythonw.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_bz2.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\_queue.pyd |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\api-ms-win-core-processthreads-l1-1-1.dll |
cmdline | cmd /c schtasks /create /f /tn "mysidex2" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmppyei1ysf" |
cmdline | schtasks /create /f /tn "mysidex" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmpnow_cesc" |
cmdline | cmd /c schtasks /create /f /tn "mysidex" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmpnow_cesc" |
cmdline | schtasks /create /f /tn "mysidex2" /xml "C:\Users\ADMINI~1.OSK\AppData\Local\Temp\tmppyei1ysf" |
host | 172.217.24.14 |
reg_key | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\mysidex | reg_value | "C:\Users\Administrator.Oskar-PC\AppData\Roaming\mysidex\python\pythonw.exe" "load.pyc" ml2 |
No hosts contacted.
Name | Response | Post-Analysis Lookup |
---|---|---|
www.google-analytics.com |
A 203.208.40.33
CNAME www-google-analytics.l.google.com |
203.208.40.33 |
dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
teredo.ipv6.microsoft.com |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49187 | 203.208.40.33 www.google-analytics.com | 80 |
192.168.56.101 | 49192 | 203.208.40.33 www.google-analytics.com | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49713 | 114.114.114.114 | 53 |
192.168.56.101 | 50002 | 114.114.114.114 | 53 |
192.168.56.101 | 53657 | 114.114.114.114 | 53 |
192.168.56.101 | 60384 | 114.114.114.114 | 53 |
192.168.56.101 | 62318 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
192.168.56.101 | 50534 | 224.0.0.252 | 5355 |
192.168.56.101 | 51808 | 224.0.0.252 | 5355 |
192.168.56.101 | 51963 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 57756 | 224.0.0.252 | 5355 |
192.168.56.101 | 57874 | 224.0.0.252 | 5355 |
192.168.56.101 | 61680 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 63429 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
192.168.56.101 | 49714 | 239.255.255.250 | 3702 |
192.168.56.101 | 50537 | 239.255.255.250 | 1900 |
URI | Data |
---|---|
http://www.google-analytics.com/collect?v=1&t=pageview&tid=&z=413705617&cid=2409ecdf-da11-4ad7-9f60-73a0f1e4c856&ua=Mozilla%2F5.0+%28Windows+NT+6.1%3B+Win64%3B+x64%3B+rv%3A47.0%29+Gecko%2F20100101+Firefox%2F47.0&sr=800x600&de=cp936&ul=zh_CN&dl=%2Fgen%2Ftrack%2Flaunch&cd1=Win6.1%28x64%29&cd4= | GET /collect?v=1&t=pageview&tid=&z=413705617&cid=2409ecdf-da11-4ad7-9f60-73a0f1e4c856&ua=Mozilla%2F5.0+%28Windows+NT+6.1%3B+Win64%3B+x64%3B+rv%3A47.0%29+Gecko%2F20100101+Firefox%2F47.0&sr=800x600&de=cp936&ul=zh_CN&dl=%2Fgen%2Ftrack%2Flaunch&cd1=Win6.1%28x64%29&cd4= HTTP/1.1 Accept-Encoding: identity Host: www.google-analytics.com User-Agent: Python-urllib/3.7 Connection: close |
http://www.google-analytics.com/collect?v=1&t=pageview&tid=&z=835147829&cid=2409ecdf-da11-4ad7-9f60-73a0f1e4c856&ua=Mozilla%2F5.0+%28Windows+NT+6.1%3B+Win64%3B+x64%3B+rv%3A47.0%29+Gecko%2F20100101+Firefox%2F47.0&sr=800x600&de=cp936&ul=zh_CN&dl=%2Finstaller%2FinstallSuccess&cd1=Win6.1%28x64%29&cd4= | GET /collect?v=1&t=pageview&tid=&z=835147829&cid=2409ecdf-da11-4ad7-9f60-73a0f1e4c856&ua=Mozilla%2F5.0+%28Windows+NT+6.1%3B+Win64%3B+x64%3B+rv%3A47.0%29+Gecko%2F20100101+Firefox%2F47.0&sr=800x600&de=cp936&ul=zh_CN&dl=%2Finstaller%2FinstallSuccess&cd1=Win6.1%28x64%29&cd4= HTTP/1.1 Accept-Encoding: identity Host: www.google-analytics.com User-Agent: Python-urllib/3.7 Connection: close |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts