Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 5, 2024, 9:26 a.m. | Aug. 5, 2024, 9:29 a.m. |
-
-
TeamViewer.exe "C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer.exe"
2688
-
Name | Response | Post-Analysis Lookup |
---|---|---|
ping3.dyngate.com | ||
master16.teamviewer.com | 185.188.32.26 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49177 -> 185.188.32.26:80 | 2009475 | ET POLICY TeamViewer Dyngate User-Agent | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
request | GET http://master16.teamviewer.com/din.aspx?s=00000000&id=0&client=DynGate&rnd=142693444&p=10000001 |
request | GET http://master16.teamviewer.com/dout.aspx?s=59766239&p=10000001&client=DynGate&data=FyQSkwCjHqkys5MkoZ6bHJmbmxubnJMkoh6YEyY3s7O0tzOemJMmoKGemDwcmjIymRucMZmZG5ovmLGwmBoZmLMyHDCxGLIxr5kYHBsbG5qbGRyTJqSiHpg8HJoyMpkbnDGZmRuaL5ixsJgaGZizMhwwsRiyMa+ZGBwbGxuamxkckyepnqu0txuTKx6bFxgXHJyaG5AoqaE= |
request | GET http://master16.teamviewer.com/din.aspx?s=59766239&id=0&client=DynGate&p=10000002 |
file | C:\Users\test22\AppData\Roaming\Opera\Opera\operaprefs.ini |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_es.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_sv.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_pt.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\tv_x64.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_it.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\tv_w32.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\tv_x64.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ar.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_tr.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Desktop.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_da.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\tv_w32.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\TvGetVersion.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_fr.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_de.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\System.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ko.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_cs.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\nsis7z.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_en.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ru.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Service.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_fi.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_pl.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ja.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\ReadCustomerData.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_no.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_zh.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_nl.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer.exe |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\nsis7z.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ko.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ar.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_nl.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_pl.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_zh.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\System.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_fi.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_fr.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_tr.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\ReadCustomerData.dll |
file | C:\Users\test22\AppData\Local\Temp\nsxEF63.tmp\TvGetVersion.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ru.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_de.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_sv.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_cs.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_da.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_en.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\tv_w32.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Desktop.exe |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_ja.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_it.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_no.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_pt.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\tv_w32.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Resource_es.dll |
file | C:\Users\test22\AppData\Local\Temp\TeamViewer\Version6\TeamViewer_Service.exe |
section | {u'size_of_data': u'0x00004600', u'virtual_address': u'0x00031000', u'entropy': 7.838627115962658, u'name': u'UPX1', u'virtual_size': u'0x00005000'} | entropy | 7.83862711596 | description | A section with a high entropy has been found | |||||||||
entropy | 0.421686746988 | description | Overall entropy of this PE file is high |
section | UPX0 | description | Section name indicates UPX | ||||||
section | UPX1 | description | Section name indicates UPX |
mutex | TeamViewer_Win32_Instance_Mutex |
regkey | HKEY_LOCAL_MACHINE\Software\TeamViewer\Version6\DefaultSettings\ |
regkey | HKEY_LOCAL_MACHINE\SOFTWARE\TeamViewer3 |