Summary | ZeroBOX

46.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 May 4, 2021, 11:07 a.m. May 4, 2021, 11:19 a.m.
Size 6.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0a6569e45a3a38f7168f4c4aa0594627
SHA256 ad74f606e358fb7f6db9a5652d0a60310d069ac108934a72d0352e5fa9248b38
CRC32 510E4B74
ssdeep 96:L1YtYF8d/XFvRxR2xs9it95PtboynunSzCt4:L12jWbr5P1oynWSq
PDB Path C b
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
api.wipmania.com 212.83.168.196
IP Address Status Action
130.185.250.214 Active Moloch
131.188.40.189 Active Moloch
141.255.162.34 Active Moloch
149.56.45.200 Active Moloch
164.124.101.2 Active Moloch
173.75.39.61 Active Moloch
185.215.113.93 Active Moloch
193.11.164.243 Active Moloch
212.83.168.196 Active Moloch
23.129.64.201 Active Moloch
46.105.121.228 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 185.215.113.93:80 -> 192.168.56.101:49200 2400023 ET DROP Spamhaus DROP Listed Traffic Inbound group 24 Misc Attack
TCP 192.168.56.101:49203 -> 212.83.168.196:80 2014304 ET POLICY External IP Lookup Attempt To Wipmania Device Retrieving External IP Address Detected
TCP 23.129.64.201:80 -> 192.168.56.101:49208 2520073 ET TOR Known Tor Exit Node Traffic group 74 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49208 2522074 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 75 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49208 2500216 ET COMPROMISED Known Compromised or Hostile Host Traffic group 109 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49220 2520073 ET TOR Known Tor Exit Node Traffic group 74 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49220 2522074 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 75 Misc Attack
TCP 23.129.64.201:80 -> 192.168.56.101:49220 2500216 ET COMPROMISED Known Compromised or Hostile Host Traffic group 109 Misc Attack
TCP 192.168.56.101:49200 -> 185.215.113.93:80 2016141 ET INFO Executable Download from dotted-quad Host A Network Trojan was detected
TCP 192.168.56.101:49220 -> 23.129.64.201:80 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49220 -> 23.129.64.201:80 2028914 ET POLICY TOR Consensus Data Requested Potential Corporate Privacy Violation
TCP 23.129.64.201:80 -> 192.168.56.101:49220 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49205 -> 212.83.168.196:80 2014304 ET POLICY External IP Lookup Attempt To Wipmania Device Retrieving External IP Address Detected
TCP 149.56.45.200:9030 -> 192.168.56.101:49211 2522180 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 181 Misc Attack
TCP 131.188.40.189:443 -> 192.168.56.101:49214 2522139 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 140 Misc Attack
TCP 185.215.113.93:80 -> 192.168.56.101:49200 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 185.215.113.93:80 -> 192.168.56.101:49200 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 192.168.56.101:49211 -> 149.56.45.200:9030 2002950 ET P2P TOR 1.0 Server Key Retrieval Potential Corporate Privacy Violation
TCP 192.168.56.101:49211 -> 149.56.45.200:9030 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49211 -> 149.56.45.200:9030 2008113 ET P2P Tor Get Server Request Potential Corporate Privacy Violation
TCP 192.168.56.101:49218 -> 212.83.168.196:80 2014304 ET POLICY External IP Lookup Attempt To Wipmania Device Retrieving External IP Address Detected
TCP 149.56.45.200:9030 -> 192.168.56.101:49211 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 193.11.164.243:9030 -> 192.168.56.101:49215 2522302 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 303 Misc Attack
TCP 46.105.121.228:9100 -> 192.168.56.101:49213 2522587 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 588 Misc Attack
TCP 192.168.56.101:49215 -> 193.11.164.243:9030 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49215 -> 193.11.164.243:9030 2008113 ET P2P Tor Get Server Request Potential Corporate Privacy Violation
TCP 193.11.164.243:9030 -> 192.168.56.101:49215 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49213 -> 46.105.121.228:9100 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 46.105.121.228:9100 -> 192.168.56.101:49213 2018789 ET POLICY TLS possible TOR SSL traffic Misc activity
TCP 192.168.56.101:49208 -> 23.129.64.201:80 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 192.168.56.101:49208 -> 23.129.64.201:80 2028914 ET POLICY TOR Consensus Data Requested Potential Corporate Privacy Violation
TCP 23.129.64.201:80 -> 192.168.56.101:49208 2221001 SURICATA HTTP gzip decompression failed Generic Protocol Command Decode
TCP 173.75.39.61:9001 -> 192.168.56.101:49212 2522224 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 225 Misc Attack
TCP 192.168.56.101:49212 -> 173.75.39.61:9001 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 173.75.39.61:9001 -> 192.168.56.101:49212 2018789 ET POLICY TLS possible TOR SSL traffic Misc activity
TCP 192.168.56.101:49214 -> 131.188.40.189:443 2008113 ET P2P Tor Get Server Request Potential Corporate Privacy Violation

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49213
46.105.121.228:9100
CN=www.bwngpox3bvalfmorvip.com CN=www.rxshttafrocltee.net d2:47:05:7d:2c:eb:e7:41:65:f3:7b:03:43:39:b6:ae:51:14:d3:42
TLSv1
192.168.56.101:49212
173.75.39.61:9001
CN=www.4y5zm6ezqlkhbs2ix.com CN=www.5ul6h6l4.net dd:c6:e9:d1:7f:2e:55:3b:46:92:22:14:6d:d3:0c:85:e3:5a:8d:b6

Time & API Arguments Status Return Repeated

CryptExportKey

buffer: ªDH1ÂÄC.^ïW;)ͬ=ds}ËpJD;¶b$yZ0E‰û,¹rü_àw(Š §=,_‘ÒÍ®½h\i1§‰ÕA8¤Àèt#ÝÊä¢/1Õ²Ðуù¬"ã ýˆ8Xƒ d’¶J¹÷C®qÒ|‰·™ëøºK'Tü
crypto_handle: 0x004429c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1 ,û{´[ÈØóÌÑVÈTl'Zap ! ƒHäÉ;CÖ“Ïæ.Ÿc{´˜–æŲÐaüŠH=·Á2–·[v·?rìèc€ï¶Ô¡{À÷ª%¯þ_€ÔôP°éP[Uªèt¿T8H½ÌäŽl_-@¸‰P™:Ʊ_÷Ä4
crypto_handle: 0x004429c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1iƒ•þõÔBúîµwrxùb,×|ˆ×ˆrƒ7¡K<P % ~V†ØCÿ~ǛñŠ¡dåÁ›hK~ѵ[Ƕ³ff¸Fy"@zÝÂ7\lðžó1 -ÜBñëùÅ̕àr”<d:„ʓ­ôAM%"a> ‰pò¹f]Þi€N
crypto_handle: 0x00442ac0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1ªM`pf¡B&NC;Iðy|CÅã,º;œâf¬ ’{ÑÞQªWXÏ,ð9ã2]1îKlûTúîF$¬5‹WnÃI›×4ëâmð0܆؁Nï9³'Ä 4Y¶‹2áÂß¡:^g5äSuµï*¨{ÎÏwV#'´‹µ…±²Û
crypto_handle: 0x00442ac0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1‰Ú&‰V$‹/óÖ¶ ñ‰ÖÚù˜ßÍòGæ}ÃA³l×&‹Ž´^öŽÅî·P4Ýùp‚Š.T1ÅNø̅WBlÖ¯)Á •$ÄDîN˜_u‘5ÔÖ§L&E${¡®øËéˆwìæò $5u*¶¦ö¤îìD»Ü©ØTü("y
crypto_handle: 0x00442bc0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH18ëøÇ"åðÛÉÓ-]ºÜuó„ï[âNv]èöx. )Ý5±#¤Uc‚ÃùU$´ùxO‚‡ŠIÁ‡r… Šô=£ä4ÔåNëù!,ëNyÔ¢‰è« ³ >Œ Þ ç²!’•öçé£ñ ù×è”ê˜3­‚›ÏQå€)žVW‰†”
crypto_handle: 0x00442bc0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1¶?U“ø¢½FIz8ˆòˆ4”Ïl5*‘Ü‘wIk/§Ž¿G¯ùB¡ûÒ´Å¡Æ5ê2OùpDŸªÚ)’¤Ë‰þG'YŽ§(x*R-ɂ`±½aøá¥æ¯—[Öð[:ÒUgˆê΋š,›|PG×Z®’‹gð\ã@ž …;
crypto_handle: 0x00442c00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1íÛâäÜüº|f‹ðÒiØ%‘Q݄Öã Ê7ºÜ¨‡`…:<}¦4ˆÁo¬ÚGü·¹þ³Ywé˜RŒÚš¸kdP›§ŽCÃÎ眫Aæý ®>û®ÛÚAÈÃ?1Põc:ü¦õòîØ:¾®¥>ýsy^û~áùL÷ù+±é4€0ä{
crypto_handle: 0x00442c00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1&÷â®€0¢Îal<=˜Ââ‡?> ëุø¡Å1é—îžuîŶ¡¹̋óŽ¤ÍÑòshæÑ~²¿Mdå2ýÿb5{û]P…þW.¯9È,€Ón‹_ѷˎ2Ém{«.Ìöªm—á¦:)^-{<$»[d{Êi^ì8
crypto_handle: 0x00442b00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1â„Ç¥·E¹ªã(Ú»ëçÉð€+þ*ȟf£G¥Zý˜ÿ[‘P ’°XÿÆt¦SšÂ¯z>b¶ ¾ªdRµ’ ËØ•w|¬näÁö›"Òöïß\>XᇲœÔìî³iuX¾[©°Í|+£)Ï!U ¹Ñ‚ë¿“K;( 
crypto_handle: 0x00442b00
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1oóDLf5’yç›_lcáT4ôFªE°ëîl™éçîy4Ú!àɇƒ5­…×NŽ‘Â^odFAýíïš\Ƨ<·jZëž eWx_3QÅ]ÃL­k•±™»CívS•d^²VçV[ûDà*"GVæpցì㈻æQ͊
crypto_handle: 0x00442ac0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1Áϼ¹ä„­çÎRYú<™÷&(±‹_Ŋ¤kb}%ë^©lÄlp;¿@D˜ë˜MŒÿG*kZÊÂÙÚàÝÙ(U’¨X £“çŽ),Y4ÁÕÑV~k¦â€ÃȎ*æa^D³¿ÂŒŸyà×Ì/&cÌ1h6ð?4 .R
crypto_handle: 0x00442ac0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1ÁNPVÔøZ‹a€Ö5dŠÔ—:$z…ñ¤¹nñtÁ"\•V•î·¬K]“£÷Óþº0Zæݽûaœä }3´PÄ-ւ„äVŠx]^%‹l\Ð#¶¦Éÿ—ó—â”û÷¥Y• Þäæ:&Z$g¼»Ä<¼856¡zzHâü
crypto_handle: 0x00442bc0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: ªDH1ّ·œhÒ»­ Ç ¸Ù±m§FªëòÕDcvÔe—=¦Xi¬5ׯPOδ/Ò÷Ì ¬¸4ƒ[Êé,‰°wG2%Pà>¦tÚI ‰r)x¾º]¶Y˜&Œ¢å-¯â¹Fp·çÔ±H·a ]éóZ`|ÛNè£%ƒÍkY÷ÖqÐ
crypto_handle: 0x00442bc0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
pdb_path C b
packer Armadillo v1.71
suspicious_features Connection to IP address suspicious_request GET http://185.215.113.93/pepwn.exe
suspicious_features GET method with no useragent header, Connection to IP address suspicious_request GET http://23.129.64.201/tor/status-vote/current/consensus.z
suspicious_features Connection to IP address suspicious_request GET http://185.215.113.93/cc11
suspicious_features Connection to IP address suspicious_request GET http://185.215.113.93/cc22
request GET http://185.215.113.93/pepwn.exe
request GET http://api.wipmania.com/
request GET http://23.129.64.201/tor/status-vote/current/consensus.z
request GET http://185.215.113.93/cc11
request GET http://185.215.113.93/cc22
description lsass.exe tried to sleep 226 seconds, actually delayed analysis time by 226 seconds
file C:\Users\test22\AppData\Local\Temp\2478016950.exe
file C:\Users\test22\AppData\Local\Temp\19667.exe
file C:\Users\test22\AppData\Local\Temp\2478016950.exe
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Time & API Arguments Status Return Repeated

InternetReadFile

buffer: MZÿÿ¸@𺴠Í!¸LÍ!This program cannot be run in DOS mode. $ö·¤D—Ù÷D—Ù÷D—Ù÷cQ´÷G—Ù÷cQ¢÷V—Ù÷D—Ø÷ý—Ù÷+ˆÝ÷G—Ù÷Nj×÷F—Ù÷+ˆÓ÷O—Ù÷ZÅ]÷E—Ù÷ZÅH÷E—Ù÷RichD—Ù÷PELQëŽ`à  4Z*BP@àŽ@|vÜ°´ÀtSP.textÈ34
request_handle: 0x00cc000c
1 1 0
buffer Buffer with sha1: 2fd868d94c6dc063ca49c767c873505fbc87dcd9
host 130.185.250.214
host 131.188.40.189
host 141.255.162.34
host 149.56.45.200
host 173.75.39.61
host 185.215.113.93
host 193.11.164.243
host 23.129.64.201
host 46.105.121.228
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Host Process for Windows Services reg_value C:\2472355972237\lsass.exe
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Host Process for Windows Services reg_value C:\2472355972237\lsass.exe
registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
Time & API Arguments Status Return Repeated

connect

ip_address: 46.105.121.228
socket: 1812
port: 9001
1 0 0

send

buffer: ZV`®ëä½@WÜ$†’FN‚³,ÏÏZ„ÊRÓQ#9Å ù/5 ÀÀÀ À 28ÿ  
socket: 1812
sent: 95
1 95 0

connect

ip_address: 46.105.121.228
socket: 1804
port: 9100
1 0 0

send

buffer: ZV`®ëÛY7į@ЊGsl‰Œ;X õ3Ë«J™S/5 ÀÀÀ À 28ÿ  
socket: 1804
sent: 95
1 95 0

send

buffer: FBA9•“}åx¤ìSˆÊ SŒöx/6¸Á‚Ü£ 」Âqõª-KN¨‰Fm¡ÞDôÉù1—¡WȤ¯?֛0sqç¼ô[ËîÓ!Våæú]¿s €Ë-*…ÆÁ·´„ê“þR’óáh„ˆì<±8
socket: 1812
sent: 134
1 134 0

send

buffer: FBAú¾ï5µí|ÚÀ{»Wßè5I[ÒâŠ,ëë53Î,ÒßOBüqÓ=æc.l¿À=PÐྯsçL2^EÅë l܊0ïôG*z²…oÞB¥x»¶Kù“ϱ;XÏ÷ße‰5n]ÝÍ_0n¡&‘@„D‡ @
socket: 1804
sent: 134
1 134 0

send

buffer:  µ}3Ï(¤›…c"IuSO ¶˜ØÀ6›|²`‚끎
socket: 1812
sent: 37
1 37 0

send

buffer:  ˜8OîÈ+¡Ü°Ñl­êS˜¢ÿNƒ¥,Á4[m$_ZKZáÑ])îÜa7+M×c‘Ánlõ>|ΈgXz6˜BÛÓÑ^Ëaìü]H¸ O~R‰òÒéZ\œFÿó—Ù°7¥V& QÓ³0òrûúÐtvµ2ƒƒ¨Õàä£o-ŽS‘ׯ‘?M£t5ÅêvžE¿¾.ßy³” !ù“¹ž\msóp×RϱC¾}‚pºðɍ:U|Í bl žÐ$iÑ@øDÂ_ü?¬^ËO¸(Jcàs ÜÚ÷†axÖMïËGó˜Qu¶øÐó[ôvßÙ)i?“ºÄŞdÊL^5\^h)@_à Õí"﨡ü <ÝŸ}¢Oý¯û#øô²Ú·;ã%m® ²Òì4£š‘µH¤HýÛgöoº‡%P£á.Cý4Ä\Ê|‹‰ÉfLg™ ÒW'˜ènÌk6){áó_ëϛÇFt19‹ò쏚³ö r¦ý“Ž‚¦c­º÷`PÃ\÷_’eâˆ$®S7ºÏô§™ž%®âü·0LC™r:s5T/ªåúñåŽaƒ†j_²I¬xЫLAõH.§‘èb؇lq?[¢KñOÚÀQ?žtš«4g_,ê糖á’i¥ÒÚøk´/&~Íø|˜z– š~—½Z§ÌÙãú–{|Œ
socket: 1812
sent: 549
1 549 0

send

buffer:  o¹u='—wӞ£=Ü4ŸµŠ\N-!ŠÕ)ÎK–‰â4
socket: 1804
sent: 37
1 37 0

send

buffer:  JIÀ*dÜÕ*áò(,þ¹¼Éx u¿2ۘ”HÈHliô:ºˆp]ÁÖ"cë@·°Eøâù μȊKò«vƚ—!RŠC£óÉ7l7íBÇ%qÒá°¦ZN‰Må{'>Ÿà¿%VÆÎ0QʬŒ¸!*l%-ãœ1j±OdÁq?V¨ˆ*µQ¸xMS!á?H:C§$"üwÍEoCŸ!  $·À›mF Î%×& òrÝÆú(ÆÅH͊»È& Þ 7B˜@ŽL<@WüüH‘ÃJÚ1S„´Uî¤ÀT¸ZCÊ0v"5°e`Õ÷û¦s.Ä%@­D¡­Mìݹ`õÿ/\;³Áž„«­].n¡`ºó¿Z¦3Eú´ZDîœä€Ã‹Óü ™v? GäÄ·D ¢Ý0ZT¶ûÌÿ:(7pr8“S>tÃZÊ³¦ÞÙëîÙ0µMö’½ÈøîÏ1¾~ÇHN¯šSp¦õhü&Mò§é</Q‘œ[ŸâïÅ#kP-™þ¾þ~Ãr¹`úÒ׫¿¢Ê9gß6pæÀ„œä¹~L@ëÀº ! ¯5Š·Ö­3¼ÝÍ3<¶¸Ê醱à z¿_ ÙÝ,T¯»é—5/¨T±G'Š¯öÈ,”µîÁ`~LRøáª^Å>‹êT/8«2î–[-»¿¦tê'ë-ÿ„šV<¾`ú¿£rL•ö\=ñ·¤³J‘W
socket: 1804
sent: 549
1 549 0

send

buffer:  gd€+ª\™Eùj56Û'x”‡ã6§T†C÷ƒÃ¢áÇ8YbÐkÒÙF¹âÖ°n+T«üÆ6—«í?¢–Ûþ[3H‰(ìºÔ²¢tÄ/zÜÞàòœeÂJIm^bvš0˜ºcÚùk©tDç"x©ïȧ7—(v9´µi¨k0àD¹GÈؖ°ˆt¹‡ê­­‹À^z©ê£;“Œÿï/›ž€ö-4«#g&]%sïfoî!<<u(ý—4yËFáb_ºP$K4‡YäÛ¯é‰ÍC%¾öáGxÓµÒ_ 4Kh0Ф)D ÅÄ5O\©WꈚŽD‡ã‡­s2=ÂÑF8bA÷…I©ù9 7ӔG7Haw w€£TÅ}M…ò"°Ä¬`h£ ˆŒר† ®TO\€ô'³*ÙåÇ==è´[pðøêédMÂí“Àš?êÁþ%ÕU˜;{ØïØh¹büYQ!7rªgK) `¶Ož›µxÓpvó‹hI¦Ð «9u#(â*|ù?ô'Àì7nv5ó„ä‚]…±Ö¦ïý¦S#<,®«LÆÿ…Á*úa77îy»q{t¸^U˶DîDNò± <ˆU¼nd„U˜]$ëØÝ¥hªr'O åE՟‘i)_í´„k‚Ô7œ`qdpCÐH&ٝrÜ#HL¬À<›8 Ôù:í“ħ>pê51`Èݗ
socket: 1804
sent: 549
1 549 0

send

buffer:  ¹Ñv*ŒbÏFóŠÖš~ÎÆGl9›p¡Ëy& _î}Tˆôˆœ^©™égzšÞ£L£Ü˱=`° Kø¯Üpg‡·$°×hB¤ò Kl·#;z°„†#[ئŸËä´V‰ÖDžQ ¢Àº¯þ³Ö·§ ÈÐ9î'ôÆÄíÒJÂ{TÓÅ>ªg¯íˆÝ™Ä7†Š·4C|IdJó5žãü=Åc4¢v<“Ä„ÿ‡èJrqF2§æÏ:±åŸ;ÓR“½©ˆÉ«¹Ç`æ=µðåVãSœ<טiŒ”Xq kM*Š|t÷†J™}‘˜gœÿÞ±Ù:<“Ä‹¹»ò*°C×C`¼Ù:|ø裸Ë¢þ:•†­»0;ïç½íx8IÀ ÿ7ȟnláÞâÂë{¿ ¿;Йæù»èƒÎôóy“z3ÑaîÒý.kon“²*roquçêÍDá3ÞʺQ˜"º§ÇpõTlïBrfšÆþ~eô–¹ŸŽL‡ °á»«‘[@æ“AÁYv9_º"£îlÎq@¢×´ €4{çÍåÕ , ‘ðéqI{ØçظR¥óÔߤYåà›ý枑÷èú7K€€H!¶ü±ÜHãÒ#Çm©„x©-ù:•î’@ ½ü[R=®ï L7ÙÙPg›PÀöNý•–{uTÜ¥æËç\€Îô¥ù_@–”Œ?3­Pl%]6
socket: 1812
sent: 549
1 549 0

send

buffer:  «¶wøñnĎ I#˜¾BßqQºN9÷w‚|:O_òz†. •¬L¸7„.IñDbIw0ºk³MÃkˆ`‹Vs æ잾¢YXˆ{á'%2g_êóŠŒbk5d ¾ ¯’Fû)Çg4q¨1F\°‚M6]¿ÇÐý99‡é;}.qÑÚXd!:‚ANWÔcµ„TTÔP’mÚS¸"Òñ·¦0?[dÐËRÚ4÷"°¼c ÐÞX¤zˆZx * `+‚)ÄV‡.€?Á¨Q¡;pƒ±]Ý AàqLŠ©wq7ðõ…ܘ±þD? ¦~ªÅ¸ìQÜ»^fyD´¡'“q¶Û áÐÎò¦£»[‡¢ëSò joØU>À8D́ӟcÏ-ò#Z¹]¿HYñò_kDýÔ ¾´#&ŽH ý_SL’Ìía8Te:p_ë uU]Uû¬Š+…ú§'‘ D¼«]«ºwƒ`œ ¶ZDw"#µµæjºšwÆd.ø™<­ \Œ®û>óèÏuŽu0"£u>õf7â©gRðeÁ…ûã ¥x€ ]`²Ùu¸áYQ*'äí/à×üýY¬¦J¤×DÎ÷ <…K*©µ ¤<üP™î.Ùу¬#¾üˆxï֘:Á‹[]Ù!6œYKáȳ¥í£hòð ²ïuRg‰"³v¸=¼X'u~
socket: 1812
sent: 549
1 549 0

send

buffer:  äuU©¯ªã#Ù·‘†ZtÇ»†÷Ï×Å©lŒóÕ˜J¤ë”(SȧR 8U? .Ï1õvøÒ&ŒUctáw£CI³ Þ®‡#×Ús«"¬ìÚWœê2ùT•yÿžšäqäîô*¦éµÇòì·¦y¶F¶w­UÇø¶AᵘG^è¥ðå¾3Ȗr¥xäeZ_¶Êó-ôšÞóªX>T݄ú Ã-ÝèŒÄ—F 3/¾K¨ÔŠÅLJÚ°,«ۅ ³.ˆ-ù ”)Ò¢ÎÐÅTn§$.±3ÍÙÑN 1ù—ò^{ô.«1IRG$½JšF§SùVlÙH%˜)÷ÛW^§.ôÕ{É»b3ûú‹øp$§›ìÏ9ÚËì}¬¨ßõG¦½\þ¢“ÿò“Ä]s>ǯûÜã…Ó³‚㮧g<Bo ãß╠a:Æa,#‡u7F>€I,˜cgš¿‰ÕPäx5µf Š®>e¦£þW†3^‚Ëa ¹\Æ.·.9#5^í½¤ݎIü¢,ž»Å瘤­ì^†v©Îr¤P¿½n¦P^J=×.tÓ=ýBýøªuŒ)®Ðtbˆ~/I@Ï£¯Ù°ÑQªÄúÎQBwµnŒÀºía캭ÌAƒ…À9ö™ï ´Õ aÅt©É¶Ql-®ý…ÕÑËGL Ãçtœšo#Æq
socket: 1812
sent: 549
1 549 0

send

buffer:  C1¾3µ€ºÝM&Nyv ƒ“mQô£/ã&¨üw"DW1<}Ϻ…äÃP€«mŽ>kåœ<¹2CjP›€Èœƒ€ Ý µrHå‰wurÍÿýXKE's_ðâ´Õ22#|.yT…Õd&&škgX=ˆ²Í¼š´3f#`èå»Ñ»œ„O71“¢ù¾¶y ¿„ÎǁhƒÔ<ŒB]>–„oÆ 2ÎÏÉËX²ÁÍBT8"sš¯?e΀04åÞOì“]”¤¾¿îfÄh:‡ßÀy‹íI 6F¸s”Ü^µ¤Mœ,Œô„ííµz5иäxÍã ðМ&?z[‘"g¦ŠülsÇËj9W ?èšä&RƒØ5ÅDô¿¸6m¦.¬&Fï˜Fu„Ä5cÕgöŽùÿiifQÖ¨ ±™ t¶µÛ®íc#ôІØdy_9zªXª¿Oh ž:òœ¯ÊùÓB†ÙeðŠÀp!Ì/IÕÌø©š‰ ê^>GÉ(3† šf˜Œ[ŽòD}Ù¢ú?JxG†ëñ=`ÏØÕ$¬²MëԖ …‘‘Ô¾Â"$k¹jBŒŠFc÷}Â9U»‘íMÔYÂÁK³â€ lœ¼¾öbBmWU¬]èð{*|FÃ¥±½þ¶K{ÇjõlUd æÁy¦[‘fF„C< 0ÖwÍ-Ú÷4pã주¦A$Ëtª]§!€ª
socket: 1812
sent: 549
1 549 0

send

buffer:  óm {vµýý‰ž  åŠ¾s²Å:4yê~X  ¥Žù Æ©(kCu‰ǺþÁ¤Ó?êå'i¯„ú»Îáz@Š$#Mq8)>ÌȈ ¥b_ג^.¿”".8ž!͆€Ìïå§~ÒUʔ"3ªÙ³§™Ãî⃊oùíó ÏV«¢¾Ë¬;RêúÛù|2K^î›?«¯7Nv_\¶ï1‚¢R]:&Åa€KtB±7ÌÓû8/§T¡ôm± ý;éWy‚ÆPe¹ð¬½¹ßû<¿ràú„ZÉlÞ  Ñe¤.›Ñ^'W“ÿ5Ñ#ÎDٜë;•¢4··´Š§ÊÞ(ûî,Î,ѲTdýÀ<~9î¿€¶Ã0©0û~ύ÷kÑù‡œD­´D¹ô½‡Lô.oHÄ{þ¾Mt9qcÍ:KâKY3ØFֈÉS»¼0èÀ P©ÍçOdû)¦Z;4þ«¡íÛÓòA…è¤Ý<¸‰óê¥]Eä%õØ FZ'} NŽEmØé;3˜J)o‘’ÓåCAET# ‹ñÈ?€#˜ž.:~ðe#Òü^ ï²Ïºæˆmb›(åÁÒ¬#y}-^S¾Mœ¢}¬gY5Š#ÿnáL÷° z‘;íRU *e~aW3çXÈܗb,êŒÛ²ydM%1uöëáS8Îâ¶è±ëöJÛv>ªrÓã|­º?#YùrÃ+à
socket: 1812
sent: 549
1 549 0

send

buffer:  Iá«}^ÉÐö&ßbhÞì¹ÔõÃs;ÞKûŸàz ,Ӄ?ÞôIîÄ7ñŸÓ:çõÚz3<ªU-70š:KÌ[]­2šô=Ì0¯Èi3­ËH¢Qy u㺄ƒgòªµ¦Ž{- ÂCš|€†8꫗\ÑH’Ï};³w‹òË*ú%Q,ƒ+¬Dë~Ã>•©Ñ÷˜ý¹3ª’¹O=­iâ­1œ¿¶ Ìëœêƍ¥Yà %âI/"‰Ì¤†ç!ԉ0•–Vµ%:ñ0'•œØkô¶–Çl¯‚~]”Ý Ž2¹B|ÉUI[3è ¥Õu}¬¸¤j:¯`y[,Rx^u …+ <Ž«\ŸhԚÐm4–þuÈD¨ ϊµM 6…–~–‰ŠXÏ2pœ~PÀÏð•àEmpYU2¬DØ'lq fbªZÔãFQi‘pûþÁñNí7–š+4`kgº,šÈ°vF’z®9ê—:’ËGåx'G„‚’Ÿ ¼ûîÆ.êhö”¥b±GªñÉð^uþ‘ÞQfTøؼFõŠ,¾­W©|ȍò\šK§}ܽ“êv:±™ § 3¼íüû»eˆÞ@…tЉ”wÛ ×±§ÔïãØdciGNwΗSŸ½„Ïõç–ãL¯¡=Z®*p¥£õ¯§ÜZ!‘6}'QOoÓíÝ3fç@"8sHdW—ý»è§˜Éd%s õ3ÎçáèÐý
socket: 1812
sent: 549
1 549 0

send

buffer:  Ó V4ʆ€î¿bLG¢^93å|quØòi5„±w£½’UÏbÆïø5eŠHÄ?¾ÂŠš™Ç߁„«f3Z N¼r›†6vÿþÖÔdå¤äȓÿ W(¥DD¼n†à1â‹ðÙՎ%jnŽF‡žVJaºœib™GþH¹;{ W^EÐ!0O}ƒCþ/áý²@€Ârš';?úö™J*ëðÐàönªÝ­sºŠžUR=ÎzÄÒkj΢·•5~Eqw¬¯¤£•W$؃tªw`¿ßÚ:%ÚG‹7OjR?º8‚JZ$€ ؾ œŒÔï)|=½½óüJrÈ¥¬‰|Êm»Il#¦~õû§Ƭ¢Ëw«jôŸjàop fü¹;¯CòßÚd8¹`  „bD'lr@kATVªGMî[*[O³ÔJ¯©;q¤±•sà°ô³ñ{t`Nûž£%Eˏ͜!˜½Ÿ»q JؾÖ×n¥hJ‡» . Š„ó•ùŒk>jó7¬7 ]!í  ñ6qÝ#2Q£;R+¦ß¼/³MÈ£‘VqïŸ5°Ç* èk‚]D© [èW£®D‘ %Ä3õ,„_ƒõCíͼh©Ëe,)mחJ]–¾q·”.˜µ—cÌØ¿yFèƒ=©áR^#&x€:YHíɎvß݉Ó2â¸$~7JÇM¢Ògôöá(80
socket: 1812
sent: 549
1 549 0

send

buffer:  ¸½'2ÆÎ5ðlRžQJ;ÿËQ̝r‡—H#×ImiÄõ-{àŸCƗÚbã¨ÓØüMTÙ¢hETãQûº¨t{ɱO¤S§'¼ª`YóòœM¹Æ¦Ôs@þÂå‰ÑväU³³h¯¢Ÿ[è6m¸+ˆu~Á#,@ÂFޜíþ3€êµ}‰Ml<]tN¡§×bH$/§<©¡ÛÃyµ^>Ýq§‰P3DÒø®CHV<]y8Ì}$uÔCzräeððõ€™·R‹%:aï@¡þ4gH à¬Ôêð¢Xê1¸ËÆêMܾ¿H›Ùèٟ.e¿ÕF,Æ¿ Œf½´H²žµ_ ^ŠíÔôFšì„¿^ 0[|<¿žÞ±vL Ý –0PÍOb®šß),#èÊèú邺4ë7 %£r Í-w›ï4mQk^UBŧèã^ªKf`­"ӒÔyèçy [‡wZUá #k”Ù˜à\껢YþÉçYìO”Œ¨"B¨ðSD¿–aQrµûzþþƒ¶‰ KÝ¥gÎGµ<-HÙß½Êؘ\ý‰º©„T!¨[)N±5·2Éðxì‡ö<Ö@+Gâ.¥¶¡GM’ÞfÉF®\$H¨•o->9*'sÎöýd»ko{;Õ·¶6à÷ßIeýá½ÕAX×ãTåÒ#NÐUZ 1HiÍÉ-RÔßSMlYÜ%}Ͷ‹´
socket: 1812
sent: 549
1 549 0

send

buffer:  ]׈¯½èJ[„þ z…“Ý#’9˗ôÑÐÚÙ颎åLù× ¥˜L ãÌ}i|.ûD¸AÝ/xzêta¶Îíè} è+lØ8\PöÇè=:î<q‘Òué+kíQ„K’Úú4חNŒƒÆ¶X=w" ¨ÞLVÀ¼Á4Wak_4HÅ·à—ô©-Ӂ^ø1­˜Åo×füMۚ"\bÕQè5ðÞèhûvý+®w̎68HƳoõú‰4Œ8é†ùå…¿T£ ë^~ ‹P0‚ªª[¼°ÚÂõv›“< J·mÛ>,™NcM_‡pÇo÷<ïn%ØlŸ»qºÁ•ô¦òݛFс'•UE Ñú®4[·•ÿá6®Ä[ª?^매'pÂYx/QÒcƒj£ ÁÅè^“D¥éJQãøÀípŒ°øôã*éU>“¹ìøeLçÌ*%\~ßÙO<åÛôu¬ä€Ù‚Jÿ_àAÎ9£c8Åè‚RÕpXN Wöê´á}G›v<Û<e˜ø°ÒÿÝRŠýˏ Û B÷¤y³éâÑŊˆ—ý$ÈƘ·¼s dòÿ¨J¤/ÆRÑ(GÓµ<j>ÙÊP±ÕH‡&ºßÐÜ-U„ÒݝØe·§$jNWÛ¶Ú%2Ý`Ø@ô†|`“Xò‰@v †D(ÃÂ4•È3¨{¦ÏðÓm*ÎòLŒwX;%wªKp9 1
socket: 1812
sent: 549
1 549 0

send

buffer:  a§`‘‹ÑyâG¤ü­Û”gØnoIûs`wÙä,ìZ|Ø ‰š}—ÜSv%ÒG*H ê|ƒÍ‡’¢qTeg4êˆõz?˜¹KĖ)ëWs–Ä_?ë¢mŠs9{ï èþ øOÉþÚýƒ|¼zŽu\e•FíI µ( p—z–À9ì‰Í¬ ތîI5îñÇ–a²oÿ¼ívDܔv¥ ª¢¸×ÕÙVã'Oš©ÀaTæÑt+¾< õ)R’“¦í+÷,$tg»aòÁºý¶ÄËcÞ¬뤖ãœ=C_ŸFµR||Òößk¢¬]‰2õI‡öÔ€à™…Øøo͚J®~×E䉇ób—Uô¦Ð>ªEx²'¡9¬© ç @9–âøÅÛ •bö¤?R1ýöícÕ§ªÄîãéÙïï—e—–˜‚¦nF€Îî ‘é ÿ*i ïÄ¿³x¸ðܗڿblRìG!¥dbÖþ»öô+‹¹SÔx2×ÂÁ¨ú?²ÌŸ)hL©:Õ3‹™Èå°úžÁÁÇ6ô¸o2ÚC¥”Áœm„ŸȦ“(ÊÓ°¾ÝOKˆ ·ŽÒ,“‘F¨'>¸p'jm#`’tRjØU˜È(UA£;¹m£™îÇÉ"Ð꼫À~*òÞ0C㌥ Dœà1ŠÎeÁFT»!å3¥ÏÉ+;ÖRD6¼hïMMòs?õÊ$H>a¢ù“
socket: 1812
sent: 549
1 549 0

send

buffer:  WvjÙ:…?y[²j+9@߯5¦+ ^ËÙëU)÷22ÚA^âtçCnm¤Ú’8s©+£øP†[*nýՔê=XmššÐ¸èN„›YÂ~§æ5#ãHtœ':_üݗùÕu„‡Þ|«Ï{5Æ)ûí-XI6dl<iәñÈó¨²×í¦Mª ÏÖñ±“¦ÚC!օ”œq´>{ôŽš›’¾üPŖ¸ì|ϳ‰ù„ÜÃé3O)³ªájnûœÿFÂGé~9#NŸŠ1„GÈ Ýy6c@$è£8'’~ÍТvtYn5±ÛòŸœ ¸ÆA©ô.G¸5ƒ=09—@š)š¼\¹¯ÑáT‘žš¢…`z!…NÜZLYu¾íÍ ú/#¼ª‰wˆÅ`³¥*ŽÒgVöãzÍP   =ƒ§³rø±& r<NQÈ%X}-cAîëŸëpñº¥ž.Õð…—ÐsäžWQÂlH:©|‰æ¯PO+Ó£!1ÇÇH—ã´ôîZ—PhXŞKÛ[ÜD·ÀYë&—”ûד-AŸÉæÙô”îõŽ: yæ8¨Ó€ýHF 8.…]BÏøðUv܃Ûö ]ú/|`Ùw#½BeKi¬`{8Óô<EC¼m†ˆÙ‡GŸ˜ÕÚS€÷ó‚]izb…tžgLK DÙjÞÕß¹Ëx5œ»ð¢¾ÓjßÒB`C€Ðèíè1>Ÿ
socket: 1812
sent: 549
1 549 0

send

buffer:  }ëé_+Yy×,ØQHlõMdåC½?ŠÓ>•(œ‰Ž„lEőÐUPÏr(ö5‹4RN;Z`fOzßØ@µ>VaXïúM¼) ôƒÉ¡Zh_’OJùVû/OŠøñ¸‰4Eò‰>ÿÐ}UÏçًf·q¬ø5ºíʗ…o¬œí¬ZÃuF-ïˆÅ¶V| ÜpI¦[ê>kŠÕeø GCbm}Ày VéÂó_øO]´(ÌSTöÐμþLµ¤:D%ñAzz Nj3—Þ5MÆ²üÊw m?¯øߔšB.ë¬}h1‚£eŸHîýC¸>ôï8:¨aŸš«ó²u»+F4|r¾îÝkú)ïTPèvÛ ;JÂÏ3kÜÑ6UDäÑük©Š Üòûç:GЂ³cÚ¡gð×7KHrˆUýr.y?¼Û©œX.:hª5é#Û{å$<Uˆ„û.UØ+½š÷c"`àQfÃF"à ñsáw¸P»r“ä&ƒáøŒ!Ü ¥‰(£ÿAô)ujÆQ¨ÙÇ9ð&ØAÎ'Di:ƒt«\k02>;o°Œ¾•D Ö¦ˆFGB‚1õ¢YÓ.žgØi¶kŸÞ¶0ø}÷¸+GÏ2§<mo»Õñ{ö[™.§øCùøJ1¿ú¦Rœ=`ş¢è B}`náÃÍX’3ìЖHKñ0 §ç(4ãòÈb
socket: 1812
sent: 549
1 549 0

send

buffer:  +4Az3¼¡}~„]".ì$·V>²­‡t×8‚E}ã­<ü}Š€›PÂwk88pÍнcW`­¥ŽÌ^ž¨©1–RDí˜Oôú‡­þ '%a¡}ó©‚ÂyÂ^w^ÞñfŸ2n>Ú¹´K¾8`öæÞ6ô¢Ø3(¤ÿø•«æià ÊÁXCêùúÈ´ötÒ»]’âý÷Låßx&/ ӏt>¬u PùÜ&žÁ‡] Â_©¿YØ!~÷ìý˜åîÞ¨ì-¢íUKlWBÀs®¼0áó î~—¦e½U7u4AËÒضŽEJ/d/üá4Z Zϊ‹(ÙëõÿÖnzÑøÇ=Ó5õ"E9Aey:³ћ¶ØÚ×5š+•Ô¦ÞMÿß?‰Þ¥'ž¼–„1‡Y‚اm¨6îb­ N‰\8jÕ dœ²Ç¼îz³8¶Ä„^æ*qJ|˜(wÁû*Ÿ­ƒ«îÔ9ª¿UW¿X´ûÚ­Š^B†ˆTGjUájn—Ýb݌dï ™ ÷׸…êxEôŽÔV¬Ê6ÝýóôJ¾½W{äîši+3þX7½•ˆ³Ù‹‹Úgèþø;¦³Q×Ȭ66½Ë](⊀Dô—Û¢]„ãÓs¬>¥¸7½¯X³ëɨôöe7ÔíaHÍÿYÜçSđ\nùRbÆX€S+x/?ÕÝQ£X,c
socket: 1812
sent: 549
1 549 0

send

buffer:  ;òþ/™¦ðJ«EìA«#Þ´nè¤ËxÒÒ3óÂŽš8yU]1»Ò½ôƘA=ƒ“[KO¿ï°1ÜÇqnéEqGÃtIŠák„¼|…¢k§à2Ê~}w’€ï)sâ+ñӄ‡#¾{+c|öD¬MI„ž¯2éíŐ¸WžR̊9a=Jk¥¦÷¢“+I®t±)¢wFBˆ+™4ªÎûkÀ­âa@×Xlícî·j'a[¸Äv+]8ä`EÒÐyÌVš`½)\ ¸Ü?lóû¬m׿Ìy%VB$…9”è›:nëRk¢ÚÇiÜ>Ä_h@ïú.}fÃRâð£í™»F¬úÚß ©ûÕUõ¯œåÞÕ"8pÄ|¥ô%Ø:´­¶Ùkü‰ho‰B(H@¨Ø~$çoŠ;’.ñ—Ó› °$¹$ð„‡+Q°z.“õy“Ï%ðÌ&>O¶Mã {åõté-÷ÿÎæ¼Î€?ƲúÏs²WÓ.»Í†îÄ`>rlrfåÞærÀ3UI43[n³/Û>Ú#€Õ‰ ¥ˆnÖÆobÒéH^®¹ai!P¾i» ùÓh@|’#&®¦DæŕE£¹òûÎÝRæ ëò€û)åT•ΚȊÉÊÊ|abÙ&†Zæ Mü*ؾ*2¦%3&qPPAÓÇ-(Ñ þ Ë¾0Å)*KÃg– ;œ ± 5˜^a
socket: 1812
sent: 549
1 549 0

send

buffer:  –Ï©•è+æ/DjÛMÝ?O!¥øˆ_}p+fHÙ⢂Œ÷€!-꧗ÙÑÒȽ&ŒƒÏU¢ö‰‡ÂsÕ6~m22„-ÍoŸo4î÷KXӃú)ÙòUCÃHz`T¤˜Õ¯¡•ªàä¡Ywúñ?)‘†­®2¹ðgå±7ƒ5ÒPåø ðîšë„ð¤Êɉ½+ÉÇ£õ˜©ÁB²‰€z•ž.SM ±¿ÿ1ۇ›{üó7–Ó²‰…‚Ï6õVÑ¡V=¥¥qցShEoÕˆÚSù=é¡3g¾o€“Fv'Àe–ŽR.zÉ¡ C›q6Ÿǭ0U‚Y÷ užŸÕ®Ír ³y £Å{‚§å  }>¢Vï¤ÃSeĄ’!âŪCՐ³âï·­eæQ?òí@'C ¤ŒnV þƒóÑ3W½ôšwƒ%HëJNµ÷ž ›†#鯍­ê¯<—•'1¾²NIãЃSÖô­m'ǽ„$•G: *šÅâ€íŸ¯:ˆ@UrnàK®óî4WUvßMQ`âÎCØX¸0†=æ?Ú ˆ>H×÷8êQ2ø17LqÙ2Š²­¨0%ž.Q»,»dÙ;)›ÎÆFpGL4öצÝʪÖ&ƒ»Oì;–®»{^2G ¬£Gø[›ЗǍwøÞ´ãäy' õ „ÝÝ@Uoç/ë÷³µçBÿ¼‡×}
socket: 1812
sent: 549
1 549 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesOverride
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiSpywareOverride
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesDisableNotify
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusOverride
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallDisableNotify
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusDisableNotify
registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallOverride
process 46.exe useragent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
process 19667.exe useragent Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
process lsass.exe useragent
file C:\Users\test22\AppData\Local\Temp\19667.exe:Zone.Identifier
file C:\Users\test22\AppData\Local\Temp\2478016950.exe:Zone.Identifier
file C:\2472355972237\lsass.exe:Zone.Identifier
description attempts to disable antivirus notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusOverride
description attempts to disable antivirus notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusDisableNotify
description attempts to disable firewall notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallDisableNotify
description attempts to disable firewall notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallOverride
description attempts to disable windows update notifications registry HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesDisableNotify
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Heur.Mint.Zard.11
FireEye Generic.mg.0a6569e45a3a38f7
ALYac Gen:Heur.Mint.Zard.11
Cylance Unsafe
K7AntiVirus Trojan ( 0056d4f21 )
K7GW Trojan ( 0056d4f21 )
Cybereason malicious.45a3a3
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Phorpiex.AG
APEX Malicious
Avast Win32:CoinminerX-gen [Trj]
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Heur.Mint.Zard.11
Paloalto generic.ml
Ad-Aware Gen:Heur.Mint.Zard.11
Sophos Mal/Generic-S
Comodo TrojWare.Win32.TrojanDownloader.Agent.EQE@80vxxy
McAfee-GW-Edition BehavesLike.Win32.Generic.xt
Emsisoft Gen:Heur.Mint.Zard.11 (B)
SentinelOne Static AI - Malicious PE
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=89)
Microsoft Trojan:Win32/Caynamer.A!ml
GData Gen:Heur.Mint.Zard.11
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.Dlder.C3467007
Acronis suspicious
McAfee RDN/Generic.hbg
VBA32 BScope.Trojan.Caynamer
Malwarebytes Worm.Phorpiex.Generic
Rising Worm.Phorpiex!8.48D (TFE:dGZlOgUN9lLDNPuMzg)
Ikarus Win32.Outbreak
eGambit Unsafe.AI_Score_97%
Fortinet W32/Phorpiex.AH!worm
BitDefenderTheta Gen:NN.ZexaF.34686.auW@a0A3T4li
AVG Win32:CoinminerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
dead_host 130.185.250.214:80
dead_host 141.255.162.34:8080