Report - DNSBench.exe

UPX PE File PE32
ScreenShot
Created 2024.08.17 23:00 Machine s1_win7_x6401
Filename DNSBench.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed
AI Score
11
Behavior Score
3.6
ZERO API file : clean
VT API (file) 4 detected (Malicious, score, Static AI, Suspicious PE, Zbot, fpyl)
md5 04177f89fa23b9d6fec146d9be737566
sha256 a1375a7ecbacf70efd3d54c7ec3c1ceae7166ad1c723b390ac78d7a3e1b19f92
ssdeep 3072:5Sww+ICvU0Qv8Z9yzvSh3gzaDKzHDa4cn2qTWM9gbYfOheIB2:5SwwPC08CzvSh3geOzm4cn2AWM9gbi
imphash 09d0478591d4f788cb3e5ea416c25237
impfuzzy 3:swBJAEPwS9KTXzhAXwEBJJ67EGVn:dBJAEHGDymVn
  Network IP location

Signature (10cnts)

Level Description
watch Performs a TXT record DNS lookup potentially for command and control or covert channel
notice A process attempted to delay the analysis task.
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice File has been identified by 4 AntiVirus engines on VirusTotal as malicious
notice Performs some HTTP requests
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks if process is being debugged by a debugger
info One or more processes crashed
info The executable uses a known packer

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (592cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.grc.com/x/ne.dll?aaaaaaednxaptz5yqth3s3zvqtvtnkk30s52dlvtv42q01221x322qjlrb US LEVEL3 4.79.142.202 clean
https://www.grc.com/x/ne.dll?aaaaaaednxaptz5yqth3s3zvqtvtnkk30s52dlvtv42q01221x322qjlrb US LEVEL3 4.79.142.202 clean
wglhn4qxaszflva4flruzoirwh.com Unknown clean
www.dq0ehd0tgeuaklnd3trkwmnbof.com Unknown clean
kv33ntmrha1ra4whqbsupdwdwe.Youtube.com Unknown clean
fh43jy5tr4buuf50gjqky00yne.com Unknown clean
v3tajp3tuvkvvcv2gcskqi0hvf.com Unknown clean
nfv4yqnqwaciuniknctiqggdyh.com Unknown clean
isc.org US FASTLY 151.101.2.217 clean
ciwlhowxtrqu3cfaxdsaj5pk5g.Youtube.com Unknown clean
www.wj0tjhvswhj3mcxfbgra2gsgyh.com Unknown clean
25.16.6.68.test.senderbase.org Unknown clean
30.16.100.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
jt5yc2yrcyhjuzl51lqsi3ic5b.Yahoo.com Unknown clean
b1lpxcbstkb4d2h1omqanlqfog.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
25.16.4.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
2.87.93.66.origin.asn.cymru.com Unknown 127.0.0.2 clean
as7922.asn.cymru.com Unknown clean
y3njz1lu05amhmtvnasoq4nqrb.Google.com Unknown clean
uksz2nvtjy0llumtecqiypfdug.com Unknown clean
sol2tc2qrih14k30hss4qzipsg.Yahoo.com Unknown clean
www.n0t3ifgxgdtqoksq3ascvijv3g.com Unknown clean
w0mer1urosq0bsrhjytgnsnnve.com Unknown clean
1tdu3d2ud11efzeyqkra15p5af.com Unknown clean
170.68.87.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
22.71.154.156.test.senderbase.org Unknown clean
ud4z2kss1v5ghdqbvrs0ogfjie.Youtube.com Unknown clean
lgilom1v0mer0xytsqrwq5ho0c.com Unknown clean
i5xxupdtpeahxjaan1qyqaozyb.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
cbsh3upwdledr32w3pqyojbwwb.Google.com Unknown clean
4qmo30fq3hryctxncyqiakqrdb.com Unknown clean
1fnspaju2dxx0csdmssuu1fbkd.Youtube.com Unknown clean
ufdzt5wtls2crtrxzbs0d5p4ke.com Unknown clean
qshberjqbhcyac2nc4ro11iklg.com Unknown clean
www.qgyt1wksdaqmu3cgjbr43rquac.com Unknown clean
2r1p0fksxdbydh5snprqovgiwf.Google.com Unknown clean
0vftpz3x240xa0oedor23fn0bc.com Unknown clean
db0zcnzuuspdq1nsy0sep1b0ef.Yahoo.com Unknown clean
eq4a1tdutcylcr44raqcx220vb.com Unknown clean
tfhhxn0xnq2x3josvhsaw2yywd.com Unknown clean
1.194.153.198.test.senderbase.org Unknown clean
gj1weg4xzob3ntdcqjqig5jg3a.Yahoo.com Unknown clean
0kh1cccrf3uhzlupl2rklwfpoh.com Unknown clean
30.16.12.68.test.senderbase.org Unknown clean
www.Yahoo.com Unknown 180.222.119.248 clean
www.Youtube.com US GOOGLE 142.250.207.110 mailcious
qxwgvpqtr3llinpfijrgskbcra.com Unknown clean
dyrtw5yxwxa0fwgqugruohi3jg.Google.com Unknown clean
tsgb1fdutzd5oacfsbqyzmdo5a.com Unknown clean
www.n04pvi3w10oknbamnvrcs2e5sd.com Unknown clean
vj44lfaxcqmbosfi0lti0y4sya.com Unknown clean
29.32.113.24.origin.asn.cymru.com Unknown 127.0.0.2 clean
w4fhrlav5zfp44pwurqyolaolh.Youtube.com Unknown clean
6.2.2.4.test.senderbase.org Unknown clean
wasahngxefbkpq1wftrsylruxh.com Unknown clean
mhf1ptyts51xwuxq0pryfbddgd.com Unknown clean
co52fllvtb1hdkokcqsa4l21xg.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
zpvidqauzbdpmbsthkqw4ejgva.Yahoo.com Unknown clean
222.220.67.208.origin.asn.cymru.com Unknown 127.0.0.2 clean
tzjdtbbua55jehml4ns0wshqsc.Google.com Unknown clean
qoi4ofrq4pibiptxujtyi1tmbd.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
net127.rebindtest.com Unknown 127.0.0.1 clean
ameazjzwgxdnmfdnvwt4wuwloc.Youtube.com Unknown clean
1.1.1.1.origin.asn.cymru.com Unknown 127.0.0.2 clean
u3liem4xfbuwuyhmw2smsnorqg.com Unknown clean
pcbgukzvqvcugc2lhgs4mtxkvd.com Unknown clean
30.16.6.68.test.senderbase.org Unknown clean
22.70.154.156.test.senderbase.org Unknown clean
ytdrtrksp5ik15kvnsqkcjwvtd.Google.com Unknown clean
www.pahwdmlvqkqupywfdtsax1avje.com Unknown clean
oykhnjjqs1s1g0tl51q4xpyvrd.com Unknown clean
ebwv3zws4bmvyqchwcqy2dexzg.com Unknown clean
25.18.1.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
2.111.81.64.test.senderbase.org Unknown clean
1.212.118.74.origin.asn.cymru.com Unknown clean
bw3gij1rd0ll1rx4tst2dfdhvc.com Unknown clean
220.1.55.209.test.senderbase.org Unknown clean
1n4rs1fvwdewy5dpk3skcrux5b.Yahoo.com Unknown clean
net172.rebindtest.com Unknown 172.16.0.1 clean
www.yjbmz2juxg3oqjedcftiumyrle.com Unknown clean
251.35.250.129.test.senderbase.org Unknown clean
2.45.81.64.test.senderbase.org Unknown clean
g5hn2zhssjwpg5qpjltyplltxd.com Unknown clean
tep3teqqktfdfxbylasuvnmstd.com Unknown clean
loiumtsriroseascwoswg3fnua.Youtube.com Unknown clean
www.iexf5mgq01qhs2zxqrsyyobaeh.com Unknown clean
jfjwltxqjanq4repl1sa2bhwud.com Unknown clean
o42xu0zx1j0ui0qm0frixwc12e.com Unknown clean
10.252.2.199.origin.asn.cymru.com Unknown 127.0.0.2 clean
roc3ohet1k3nqhebmcrkx5rcpf.Yahoo.com Unknown clean
jkl2jbmr4ifcxddbrzsqc4lgag.com Unknown clean
as11696.asn.cymru.com Unknown clean
m0dn2kkuoh5idlhr3cr4n3b0hd.Yahoo.com Unknown clean
8.8.8.8.test.senderbase.org Unknown clean
9.9.9.9.origin.asn.cymru.com Unknown 127.0.0.2 clean
iv2pwvbuv1mag0mdkxqa4cbbnf.com Unknown clean
www.cnazauutqjrkhmgrjsq00xtrlb.com Unknown clean
fucfr01tvzh1i1211cs2m1zcma.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
2.41.231.216.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.16.2.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
dbb113qwped2l1sx4gtszg31gd.Youtube.com Unknown clean
25.16.100.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
vnhhecsqf1lnj5jubvqmmn035c.Yahoo.com Unknown clean
29.32.113.24.test.senderbase.org Unknown clean
2.95.254.216.origin.asn.cymru.com Unknown 127.0.0.2 clean
3.2.2.4.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.16.13.68.test.senderbase.org Unknown clean
dwzdq3ostta42ludigqqxtu2na.com Unknown clean
sjvdontww3wpo2unfwtwydq4nh.com Unknown clean
pbtahbotymikjoecdmsszrouyf.com Unknown clean
25.70.154.156.origin.asn.cymru.com Unknown 127.0.0.2 clean
30.16.11.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
mchjxsgql1lkkfvcelr2omtmxh.Yahoo.com Unknown clean
200.234.194.204.origin.asn.cymru.com Unknown 127.0.0.2 clean
2.212.118.74.test.senderbase.org Unknown clean
5iyj5lrr3pmfkx30nztglkuv0a.Yahoo.com Unknown clean
30.16.4.68.test.senderbase.org Unknown clean
gi35idhtqykw03xhmyt2qyrw3d.com Unknown clean
vlrm02lxlw5crkujlbsqpgxf0b.Yahoo.com Unknown clean
25.16.100.68.test.senderbase.org Unknown clean
woxxb1oxwa0rgfp03zryyuu02a.Youtube.com Unknown clean
vurzrcivogzjr1dyxqqanjzutf.Google.com Unknown clean
2.224.92.66.origin.asn.cymru.com Unknown 127.0.0.2 clean
10.214.117.204.origin.asn.cymru.com Unknown 127.0.0.2 clean
30.16.111.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
as17184.asn.cymru.com Unknown clean
owv0wz1sa2pfe0icdssgw0ctrg.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
s12ptbnvoq5ekoggictahecs3b.com Unknown clean
www.b4rqgfqqavm5xielymrclhguhb.com Unknown clean
5caj4crw0fe4w32cantate540d.com Unknown clean
r1mkgxrso0bc43e1i2ryhx2o4g.Google.com Unknown clean
g34454zqeux11ima1fqmiv2yvh.com Unknown clean
f5nkwbyx0nirh4iksbtygrj05f.Google.com Unknown clean
mwg1lborpaic53kl4hre1gfiqb.com Unknown clean
uczmwdjxexbtp0p3ibq4fnadbd.Yahoo.com Unknown clean
qlxsfxfq0lhyudu4asrkqlys3g.com Unknown clean
30.16.12.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
1.71.154.156.origin.asn.cymru.com Unknown 127.0.0.2 clean
1emqivmr5j2gisvgd5skl1gprc.com Unknown clean
i1nrwejskdestv4pddryd5oewf.com Unknown clean
bg33utouolpfzzuhj2sufeinnc.com Unknown clean
10.212.97.204.origin.asn.cymru.com Unknown 127.0.0.2 clean
30.16.100.68.test.senderbase.org Unknown clean
f0mz1gjxpf5jlrageiruamrfua.com Unknown clean
4l2nv2au21icsu5q5xs450xllh.Yahoo.com Unknown clean
n5czl5lwtookojwmuxqgqsp24a.com Unknown clean
x4x0qzbqbd4addt5p3suhnso4d.Yahoo.com Unknown clean
cgsos4wuvv3nfsvr3oqcckuk4e.com Unknown clean
dw1m54htxi320ak5vyssrsr55c.Youtube.com Unknown clean
m0gcqllxv55u0febxtquckbxpe.com Unknown clean
3.2.2.4.test.senderbase.org Unknown clean
2.159.81.64.origin.asn.cymru.com Unknown 127.0.0.2 clean
uxfkilhtotiprhdmwassabm0vh.com Unknown clean
30.16.9.68.test.senderbase.org Unknown clean
4x341neujlm4cvv54zqw4yzpcg.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
zdrd2brxdfirytdlqtq4immyda.com Unknown clean
xuj4fanuknnvgvanloq2q0ejca.com Unknown clean
www.ciwdeybtdslirk50ycqit4iupc.com Unknown clean
123.220.67.208.origin.asn.cymru.com Unknown 127.0.0.2 clean
1gyljw5s5u1k4jehcitsfoyode.Google.com Unknown clean
www.ay5xgkeqhow4mel10eqqf3szeg.com Unknown clean
x5sxhovwczk0lc2iyrqq2ec4he.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
tzmef3ywrv2gjdygjbt2gp5e2e.Youtube.com Unknown clean
2.159.92.66.test.senderbase.org Unknown clean
bt3ghecv0uku3iyqtprmkgkxnf.com Unknown clean
25.16.11.68.test.senderbase.org Unknown clean
1gquyuasadgfqzo3ndrcxeixcd.Google.com Unknown clean
yb3ranrxmooeus2ue5rydjpgtd.com Unknown clean
30.16.6.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
8.8.8.8.origin.asn.cymru.com Unknown 127.0.0.2 clean
www.e4hxuc1s2jgkx3dls3tiwekuzb.com Unknown clean
wjx3t2lv55qjdyqjnrt2olnwbb.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
0sqi0trtnl1m25ve1yroftu25c.com Unknown clean
cf5r3jfsxb11oarpyor2unldyd.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
caypoiurkjmums2unwt2x1h04h.com Unknown clean
chdnhn5qygievdd0epqapbttja.com Unknown clean
www.vziulxkvn4feeaqt3aqwhasxmg.com Unknown clean
30.16.4.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.16.10.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
net10.rebindtest.com Unknown 10.0.0.1 clean
41y1utvtb5zxlin0gmroficjoc.com Unknown clean
glblwa4xyzlvol30v3sayyzhyc.Google.com Unknown clean
vuvaf0uvikwg242ykfsqukmt2h.Google.com Unknown clean
4seuowgvunn5v1vmnvqq15zuog.com Unknown clean
9.9.9.9.test.senderbase.org Unknown clean
www.tniiqmdve5k5hdhmttr4uspvfb.com Unknown clean
as10397.asn.cymru.com Unknown clean
as397213.asn.cymru.com Unknown clean
pywi1l1qm2s5dlgpdds2sggb5f.com Unknown clean
www.grc.com US LEVEL3 4.79.142.202 clean
www.wisr0t0wm3kdv0voznsg5cpx0b.com Unknown clean
www.napdruiutipgyhypsjsue1ap4d.com Unknown clean
200.232.194.204.origin.asn.cymru.com Unknown 127.0.0.2 clean
22.71.154.156.origin.asn.cymru.com Unknown 127.0.0.2 clean
bens5d2xmqjflu2nczsa4oymjg.Yahoo.com Unknown clean
220.222.67.208.origin.asn.cymru.com Unknown 127.0.0.2 clean
1.71.154.156.test.senderbase.org Unknown clean
vkyl1qeu3r5iy4vi4iqojcjycf.com Unknown clean
squghqhs4dkp1c5vg1s40jtrkd.com Unknown clean
4.4.8.8.test.senderbase.org Unknown clean
h0xagt1wakbqgz2grpqsxn2r5b.Youtube.com Unknown clean
1.192.153.198.origin.asn.cymru.com Unknown 127.0.0.2 clean
ic02pafsf1s5ikdfcjrmlxkd2h.Youtube.com Unknown clean
4ceyccxsfgomhl5u0pq4bdwpmg.Youtube.com Unknown clean
c5lp4ddt0u3wjluma4t052seff.com Unknown clean
5.2.2.4.origin.asn.cymru.com Unknown 127.0.0.2 clean
n1b5pwyxml3hgvvwjgqmmwei5f.com Unknown clean
2.159.81.64.test.senderbase.org Unknown clean
fcwivmnrwrtck0ifymskk2ewhh.com Unknown clean
55bqbzksyr32rl5fitsgzzeg0a.com Unknown clean
womt5qbxx0luc3kpl5t04bkzlg.com Unknown clean
btm1v1ntuwpi4sbst4rqzedi3f.com Unknown clean
dideb0ewbubdju32tzqe4rnxxg.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
30.16.2.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
btpfifms3xhwodffq0rynda1ob.Google.com Unknown clean
rvwkoyiudyhxup5b00tsat5qte.com Unknown clean
2.79.81.64.test.senderbase.org Unknown clean
fteim2mrp10j31bnlbq2jkqlbe.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
0fmenalwoozlhcf0dks2vtbkfa.com Unknown clean
kfixupivvlv1mhe0eeruxdzuoh.Yahoo.com Unknown clean
flr1oyjuxaipunaxaftmomaive.Youtube.com Unknown clean
naysfajwutyf4euopctwmz2uqe.com Unknown clean
b4fkktysfueqy2nq1atebvnioh.com Unknown clean
25.16.12.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
njq2viruwx4h5syjtorgj4h15c.Yahoo.com Unknown clean
170.68.87.68.test.senderbase.org Unknown clean
2ynq1otxuzgncnvvhkqwp5fpnf.Youtube.com Unknown clean
www.fstbrmwwo05n2tzldktgmercdc.com Unknown clean
1.194.153.198.origin.asn.cymru.com Unknown 127.0.0.2 clean
hgafhvmvtrekm0wuu3r2ulutee.com Unknown clean
as11404.asn.cymru.com Unknown clean
mzq31qavcdgchxyiliscicv0qg.com Unknown clean
kovlekuxi3vj2sqflnqy2yh3wf.Google.com Unknown clean
quekctdt4azflnlvzkru1bqukd.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
zzjhotbx0gmrbttapotc5ut03b.com Unknown clean
250.35.250.129.test.senderbase.org Unknown clean
www.po0fxghul54k0ojfcfsqgapo2c.com Unknown clean
2.224.92.66.test.senderbase.org Unknown clean
uwzxdf1vaeulds40gvtst0xjxc.com Unknown clean
xjsrbgwwb2oszqw2oequgusfyc.Youtube.com Unknown clean
www.1yooal4rwpjhvehawvt4vc1hsh.com Unknown clean
tedhlccuwqmzya2ic3qqbdkzra.com Unknown clean
25.70.154.156.test.senderbase.org Unknown clean
2pv5bqgr0ylxtxmh3jtgjss1bc.Yahoo.com Unknown clean
oljqnbuuwytw433bw5tuwplvud.Google.com Unknown clean
10.252.2.199.test.senderbase.org Unknown clean
uiqdjb3sxvdyxadlt0seqichkh.com Unknown clean
jlj0fcaui35x244lkvqiluqqxb.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
cikl5mzuph1dy4heprraztma5h.com Unknown clean
y3xr4eyxchb3y3vhpgti5zfvpc.Yahoo.com Unknown clean
10.214.117.204.test.senderbase.org Unknown clean
rij0vlyweng3niyaeftqr4k2te.com Unknown clean
eb0bynstzrihlvm1aqrk3iuyzd.com Unknown clean
b1ebpcmsvknu4r1l0gtg0urdeb.Youtube.com Unknown clean
wztr54hrjy1ejqrolrrowxyhbb.com Unknown clean
sy5b5nkxai5pmfkxvnssgia4le.Google.com Unknown clean
vvdfeuhruo2ev13hmusqbmrjpg.Yahoo.com Unknown clean
www.owxvwqmw0rt3lylfvmq455kzmh.com Unknown clean
fij3hhnup1235yoybxsy025z5h.com Unknown clean
edizsv2sj4ahmx50ciswnvyhja.com Unknown clean
uhlmljst30to4fbng1survt5ye.com Unknown clean
www.oku2zzuqekg0eetv1hre3ti5eb.com Unknown clean
duzidthxgjbgkos5goso1ffmpb.Youtube.com Unknown clean
2.41.231.216.test.senderbase.org Unknown clean
www.adgoeodrw4g1o5hwzkrugc5g1g.com Unknown clean
4.4.8.8.origin.asn.cymru.com Unknown 127.0.0.2 clean
knowkdkv3ihsmudzywt44pqdsg.com Unknown clean
110.0.55.209.test.senderbase.org Unknown clean
kzluo4gslwnvnm255lrelc1bze.com Unknown clean
eppmijetkpmvg35le4turqzg3a.com Unknown clean
akndwpgsn3tyvidou1toqarjnf.com Unknown clean
as2914.asn.cymru.com Unknown clean
m33l3imqeds3qf531vtu5rqate.com Unknown clean
as22773.asn.cymru.com Unknown clean
1.2.2.4.origin.asn.cymru.com Unknown 127.0.0.2 clean
whwiftptab3zos2bussunpmdza.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
ci2ftqxxmemnpb5m2htygznmzg.Google.com Unknown clean
gad5g1iru3qlmcddnaqef0v5wa.com Unknown clean
rhzduq4rrhpdebo1xdsqzhwguc.com Unknown clean
bt234l2vmnwrdt1gddq00su2wg.com Unknown clean
www.q4a5dcoqyviyzu0pqhrybzheyh.com Unknown clean
www.zazj40vr2zvufjpngjqamiikhd.com Unknown clean
vwpomk0udtuqfu4neqs4myzibd.com Unknown clean
pgriu11uvey3si3wu2qelw1ctc.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
phkp0pot5x0ny0u5lotqtjv3pd.com Unknown clean
lrs2e1aumuoqdlljc1sqz44bof.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
30.16.2.68.test.senderbase.org Unknown clean
ioatctkqakyb1eg4uxr0synh3f.Youtube.com Unknown clean
xjkr3ivsmzrwx3fd3ytsmwqb0e.com Unknown clean
gtrr0stwkwni1fv5rdrmxmlyce.com Unknown clean
bp4kxb4xls2gbxju2ut2y4bk3g.com Unknown clean
2.111.81.64.origin.asn.cymru.com Unknown 127.0.0.2 clean
www.3gsdllexmwfna0u1r5tkwy0sng.com Unknown clean
ksyxhgduyo4febutkltqqpdj2g.com Unknown clean
bljck35q2cfxz1ajiotwpnysea.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
30.16.10.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
ycdfbhuwbib41k2tq5rgegqhwb.com Unknown clean
www.Google.com US GOOGLE 142.250.206.228 clean
2.101.124.164.test.senderbase.org Unknown clean
ezpe4ssvhrhehaqpvcsqx2iagh.com Unknown clean
2.64.92.66.test.senderbase.org Unknown clean
mavbalnr3omqvktzfbrcipd1ud.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
5z2z1brw5w2zxadmnzs03af0ph.com Unknown clean
30.16.13.68.test.senderbase.org Unknown clean
fa3zrzpvgl2qf0ofmcr0bdyckb.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
u3x1op0wumfb4j0xqaqmihjbfc.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
1.70.154.156.origin.asn.cymru.com Unknown 127.0.0.2 clean
www.iimu0azunxhmi2pkqjq4aqyhrd.com Unknown clean
as3257.asn.cymru.com Unknown clean
hmwdm3rwx0g22ukgieqkvowbbh.Google.com Unknown clean
vea2kalt5qawvbetkvrcgpwtad.Yahoo.com Unknown clean
2.2.2.4.test.senderbase.org Unknown clean
txaebhoxau3cbjekmvte3cqrae.com Unknown clean
xmotufgql4jqc1hinztik4imeb.com Unknown clean
o3hxow1sm0dlkb0qg2sgnxusve.com Unknown clean
25.16.9.68.test.senderbase.org Unknown clean
zcjkjplvswutchpslksajgnocc.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
c5vsehzuywnkbihhx5q4h2vkpd.Yahoo.com Unknown clean
gq4vs2jvvu3lwms04rr03tpevf.Youtube.com Unknown clean
heemyqas2mimd4nxgct0vcrese.com Unknown clean
cwehoqww0fzwfti54osoh3ij1e.Google.com Unknown clean
tdtdhtxwifomqfov2irym53qib.Youtube.com Unknown clean
123.222.67.208.test.senderbase.org Unknown clean
lb44xgjvnycvd0s33dqidrk1lb.com Unknown clean
2.79.81.64.origin.asn.cymru.com Unknown 127.0.0.2 clean
dlxdtphviktdhdztbxrqioz1de.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
as36692.asn.cymru.com Unknown clean
nmulocnuihbgwqbsxlse1nzbcb.com Unknown clean
2.2.2.4.origin.asn.cymru.com Unknown 127.0.0.2 clean
l1azpipv2aygf00mhqrav04f2c.com Unknown clean
carforfs1fl4vp31coqsyxgmrf.Google.com Unknown clean
tqc2asvr4gag5fhfv3qc4iskhb.com Unknown clean
22.70.154.156.origin.asn.cymru.com Unknown 127.0.0.2 clean
ukcj0rlv5mw0dgddwftgljfaqg.com Unknown clean
2mr2k5asf4jcuscuzrq0n5n3gd.Youtube.com Unknown clean
0pqh2qxrsvvzcr5qaxteycqvke.isc.org Unknown clean
as3356.asn.cymru.com Unknown clean
zuxkngvuqcggdfj5xrrkzq0k1c.com Unknown clean
www.4f3rrjerllmezvwcrjrc5ebdgf.com Unknown clean
2cr2wfsrqzfdsygm12qsyfsgvf.com Unknown clean
1.1.1.1.test.senderbase.org Unknown clean
unu4i0xqxu2xopjop3tyix4lwb.Yahoo.com Unknown clean
220.220.67.208.origin.asn.cymru.com Unknown 127.0.0.2 clean
2.127.81.64.test.senderbase.org Unknown clean
2.101.124.164.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.71.154.156.test.senderbase.org Unknown clean
dncs4vltkhgv0bqweorcxacy0b.com Unknown clean
fsrmei4vdpw23qmgklq0qscemd.Google.com Unknown clean
kmugvfovgdnpfjsp52rqngo50d.com Unknown clean
as15169.asn.cymru.com Unknown clean
rotwufprkhpindexfhsqxphlsb.com Unknown clean
154.64.87.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.16.10.68.test.senderbase.org Unknown clean
220.220.67.208.test.senderbase.org Unknown clean
1.0.0.1.origin.asn.cymru.com Unknown 127.0.0.2 clean
cnp0idkrq1zvtua2rnty1u1x1c.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
uf4auert4bb1ghtuxequc02clg.com Unknown clean
l2f5ntowjf4jmwqr4fsoifrlsd.com Unknown clean
jgwdq3iqlakti4dda1saxb5k0h.Google.com Unknown clean
1.212.118.74.test.senderbase.org Unknown clean
www.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
45hncyxxljrz5fbpquto33lb2a.Youtube.com Unknown clean
6.2.2.4.origin.asn.cymru.com Unknown 127.0.0.2 clean
bgbo0fqqk0er4nc3ipq0x3xf0a.com Unknown clean
2.87.93.66.test.senderbase.org Unknown clean
1.192.153.198.test.senderbase.org Unknown clean
2.159.92.66.origin.asn.cymru.com Unknown 127.0.0.2 clean
usfstpet0tsun0b3kkq2hwjywg.Youtube.com Unknown clean
m1wdujev3mfx34zv5xsck0zqae.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
25.16.4.68.test.senderbase.org Unknown clean
222.222.67.208.test.senderbase.org Unknown clean
25.16.11.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
lqx4k5fufbl1wwgvnhq2kjcrjb.com Unknown clean
3vgpbpus50w2ibve1vsgtpiqye.com Unknown clean
gyvistzrkosp3imvfzq2sxvzpb.Google.com Unknown clean
dqwmkr5rpohbdixg22se400iog.com Unknown clean
net192.rebindtest.com Unknown 192.168.0.1 clean
he04l2fsolxqbtyzbqqqojehvg.com Unknown clean
k45c13bwviwmltjt25ra0r04pb.com Unknown clean
25.16.2.68.test.senderbase.org Unknown clean
25.71.154.156.origin.asn.cymru.com Unknown 127.0.0.2 clean
5tkc0cyrsfx4walt43rieimbnc.Yahoo.com Unknown clean
154.69.87.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
220.222.67.208.test.senderbase.org Unknown clean
rehhdq3qt0tumfqsikrewlhggf.com Unknown clean
024xhenq2nvkpqvzn0t4txmvte.com Unknown clean
o4mwbfctrnxpyxmk0ntq1i3oaa.Google.com Unknown clean
222.220.67.208.test.senderbase.org Unknown clean
bnatngnsmzrnzcqsmnqqwhwltd.Google.com Unknown clean
www.k2vmzohx5fynrdfgl3qktnszbe.com Unknown clean
dyjzhgytugw4gqwkefrcflh2ca.com Unknown clean
qstjnxeupi53fltczzt0kbpv5e.com Unknown clean
4.2.2.4.origin.asn.cymru.com Unknown 127.0.0.2 clean
200.234.194.204.test.senderbase.org Unknown clean
25.18.1.68.test.senderbase.org Unknown clean
30.18.1.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
bv0khonwiheup0guiqqcv0ky2h.Youtube.com Unknown clean
2.45.81.64.origin.asn.cymru.com Unknown 127.0.0.2 clean
30.16.10.68.test.senderbase.org Unknown clean
30.32.113.24.origin.asn.cymru.com Unknown 127.0.0.2 clean
30.16.13.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
200.232.194.204.test.senderbase.org Unknown clean
00b4isyufr2b4xsmqdqowsi0le.com Unknown clean
prusjvnxv3xc2vt4s0sq4zwjlg.com Unknown clean
aobisrvvshvcxfskd3rwaqvfig.Youtube.com Unknown clean
123.222.67.208.origin.asn.cymru.com Unknown 127.0.0.2 clean
tpmmktdqjjj5lujxb2q2god45h.Google.com Unknown clean
qldqinrrho5rl4sulaqyzu30uh.Yahoo.com Unknown clean
154.69.87.68.test.senderbase.org Unknown clean
ktnpxdtxdekurlmvvpridrb1zc.com Unknown clean
as1239.asn.cymru.com Unknown clean
10.212.97.204.test.senderbase.org Unknown clean
as397215.asn.cymru.com Unknown clean
dn501p0ujeovrxl5apte035wbh.Google.com Unknown clean
ok1bfk5s5urkbnzalzrqklmoch.com Unknown clean
kge1le5rgre2t3gisss0nrxt1a.Youtube.com Unknown clean
5rex1h0ub4vtqrpwodqmdcabed.Yahoo.com Unknown clean
net4.rebindtest.com US LEVEL3 4.4.4.4 clean
220.1.55.209.origin.asn.cymru.com Unknown 127.0.0.2 clean
gcx5b3eubs2aybjnzyq0f0ghug.com Unknown clean
3juqowwsucmco3vo5ttsdlzn2c.com Unknown clean
222.222.67.208.origin.asn.cymru.com Unknown 127.0.0.2 clean
30.16.11.68.test.senderbase.org Unknown clean
2.64.92.66.origin.asn.cymru.com Unknown 127.0.0.2 clean
3ladwgxvuwxt201fa0tu3otpoc.com Unknown clean
tprsxe1uf0z2wegcoltg0i0zef.com Unknown clean
hhgzimfv5e5fqpujverooji03a.com Unknown clean
vmz1yigx1chdigyvdersn55gie.com Unknown clean
5u1xjrnvdm0iyvon41t0jzp5kc.com Unknown clean
5.2.2.4.test.senderbase.org Unknown clean
xbac4yis25yymhjktgrqnyvdxh.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
ddxbjies0m1jktjcvvsqeffxua.com Unknown clean
2x0d4xnxzd4qlggxhktex2atke.com Unknown clean
uixfxznqkgs2q0bq0ktggqk35e.com Unknown clean
yb3ywgosd4uigqc244sirodzsf.com Unknown clean
n033mfyxrnzjnkfpborkqmf1mb.com Unknown clean
rsbwtp4rhclm4hzf3vsm4mczia.Yahoo.com Unknown clean
hznlmnfwy35trntvjssegq2dre.Yahoo.com Unknown clean
dukhhkcrp5jkrxgp1bsm33h3ec.com Unknown clean
123.220.67.208.test.senderbase.org Unknown clean
ujrfsnuq1fklycopgxqehzdfca.com Unknown clean
qrkc24ptbyzcm25jyjrcacoszb.com Unknown clean
pcemkf4voeeebdwqhotix345ze.Yahoo.com Unknown clean
w5abunztb2kkeabt33rar05fsa.com Unknown clean
hnkka4au1u40pu4m44rspk0e5c.com Unknown clean
msti0qcwnhzy3ayqpitu522qge.com Unknown clean
30.18.1.68.test.senderbase.org Unknown clean
athu1huvxeiqaxizvstkqdtilh.com Unknown clean
ifvekmhx1gf4yb0sdnreqraxof.Youtube.com Unknown clean
4h1d5w2wnenrehy04criyyu04e.com Unknown clean
2lwntxbvyk5qxmsvkst0wiz5nf.Google.com Unknown clean
vswaiyhqylxyciun5ptopebjqd.com Unknown clean
sjqirogtxghkz21zamsi0zuiha.Google.com Unknown clean
xdvzes2v0pefivqk1ys005em5e.com Unknown clean
bdrfpryrsn533loggusg0odqid.Youtube.com Unknown clean
25.16.6.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
k4z330ixsdw1q4jopuquxvv5jd.com Unknown clean
www.yews3zxtj2ddrhhevtqovzjwrf.com Unknown clean
25.16.9.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.16.111.68.test.senderbase.org Unknown clean
ausjhnztw21c33emrwtwhwqjnf.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
www.nlujakhur3a1xiixmiqg1sshmb.com Unknown clean
d41bavisvcsulhtkoet41nkxsf.Google.com Unknown clean
4.2.2.4.test.senderbase.org Unknown clean
zjvohh4vh2fpdomdl1qq4b0i4f.com Unknown clean
250.35.250.129.origin.asn.cymru.com Unknown 127.0.0.2 clean
mtscmy1txon1n0sly0ronstx4b.Google.com Unknown clean
e4hryrwv0f43oj1hpbrmjsp43c.Yahoo.com Unknown clean
nulfd4jwz1xjq1flfntcbhl53c.com Unknown clean
0frju1zskkrejdbz4oq2ewzyvh.com Unknown clean
ir2ndyxt0bj55tei3grc0g4xnc.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
g1zyj10u3u0ybkgzf1t0i0fbwg.Yahoo.com Unknown clean
as3786.asn.cymru.com Unknown clean
0xqo5glrtkhiquoxwyqyrbrjoa.Yahoo.com Unknown clean
25.16.111.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
y2zaz53qerl153mi0fs2fghinc.Yahoo.com Unknown clean
2.127.81.64.origin.asn.cymru.com Unknown 127.0.0.2 clean
as13335.asn.cymru.com Unknown clean
vldqziuvv1khmqmfxrr2ve5kse.com Unknown clean
doya1k0x5qob12ev4bqk51h5xg.com Unknown clean
s3xpvahwjmhdbx4fs3qaaihngh.com Unknown clean
251.35.250.129.origin.asn.cymru.com Unknown 127.0.0.2 clean
110.0.55.209.origin.asn.cymru.com Unknown 127.0.0.2 clean
25.16.13.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
tsyoqmqsc0dpjc3nfvtms5nlvg.Youtube.com Unknown clean
qxwgh5qx42w34czz31s0n5ykpf.com Unknown clean
2.95.254.216.test.senderbase.org Unknown clean
1.70.154.156.test.senderbase.org Unknown clean
25.16.12.68.test.senderbase.org Unknown clean
wwakaqnse51ljjkvb3qud0xr0h.com Unknown clean
coxrn2auhawe43oq1iqubcdfne.Google.com Unknown clean
birxptxtiu3pgrnr4kq2lnnx2c.Youtube.com Unknown clean
crqypzwt2k111fiwkfqq3r5mhb.com Unknown clean
fkeiwcav42jobwiliiruz4hdxf.com Unknown clean
zgizxgyr4bnhufyn3fs0ejn4xh.Yahoo.com Unknown clean
2.175.27.216.origin.asn.cymru.com Unknown 127.0.0.2 clean
as19281.asn.cymru.com Unknown clean
pypvapnx1ql0cxm0hgtstpyhuh.Live.com US MICROSOFT-CORP-MSN-AS-BLOCK 204.79.197.212 clean
www.c5smjgyvhfi1mzwkghsoju00fb.com Unknown clean
xvzcbq5s1a0uf54ksargrz55nc.com Unknown clean
www.rodj53xsomwgpx2rfsscfrpn5f.com Unknown clean
30.16.9.68.origin.asn.cymru.com Unknown 127.0.0.2 clean
v5igpqtuvqnl3nvhiutua45vwf.com Unknown clean
30.32.113.24.test.senderbase.org Unknown clean
www.3rhy21xwaupnpk4dwoq4xgqsmf.com Unknown clean
jnyoehzsvpu0xemdksqcnns3xc.Google.com Unknown clean
2.212.118.74.origin.asn.cymru.com Unknown clean
5qwc3jlujdcv0q45q3rik5td5b.com Unknown clean
1.0.0.1.test.senderbase.org Unknown clean
svrn44ptag1tlvaw42qujo4mfh.Youtube.com Unknown clean
qnfe2enuwtky3d13rwtkweti3c.Youtube.com Unknown clean
2.175.27.216.test.senderbase.org Unknown clean
30.16.111.68.test.senderbase.org Unknown clean
3gnhcjmv4muf3jvzaftaggsg1f.Google.com Unknown clean
154.64.87.68.test.senderbase.org Unknown clean
www.smwseaevoaqk4q1kayso0g0zqa.com Unknown clean
f4koqwascalcvxrmrkt2xouqbf.com Unknown clean
1.2.2.4.test.senderbase.org Unknown clean
129.250.35.250 US NTT-COMMUNICATIONS-2914 129.250.35.250 clean
129.250.35.251 US NTT-COMMUNICATIONS-2914 129.250.35.251 clean
64.81.45.2 US ATL-CBEYOND 64.81.45.2 clean
68.11.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.11.16.25 clean
68.9.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.9.16.25 clean
66.93.87.2 US ATL-CBEYOND 66.93.87.2 clean
156.154.70.22 US ULTRADNS 156.154.70.22 clean
199.2.252.10 US SPRINTLINK 199.2.252.10 clean
216.254.95.2 US ATL-CBEYOND 216.254.95.2 clean
156.154.70.25 US ULTRADNS 156.154.70.25 clean
198.41.0.4 US CLT-NIC 198.41.0.4 clean
209.55.1.220 US MOMENTUM 209.55.1.220 clean
68.1.18.30 US ASN-CXA-ALL-CCI-22773-RDC 68.1.18.30 clean
204.194.234.200 US 302-DIRECT-MEDIA-ASN 204.194.234.200 clean
204.97.212.10 US SPRINTLINK 204.97.212.10 clean
68.6.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.6.16.25 clean
208.67.220.222 US OPENDNS 208.67.220.222 clean
68.87.68.170 US COMCAST-7922 68.87.68.170 clean
208.67.220.220 US OPENDNS 208.67.220.220 clean
208.67.222.123 US OPENDNS 208.67.222.123 clean
68.111.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.111.16.25 clean
68.100.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.100.16.25 clean
68.11.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.11.16.30 clean
156.154.71.1 US ULTRADNS 156.154.71.1 clean
156.154.70.1 US ULTRADNS 156.154.70.1 clean
216.27.175.2 US NBS11696 216.27.175.2 clean
68.87.69.154 US COMCAST-7922 68.87.69.154 clean
68.2.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.2.16.30 clean
1.0.0.1 AU CLOUDFLARENET 1.0.0.1 clean
204.194.232.200 US 302-DIRECT-MEDIA-ASN 204.194.232.200 clean
68.12.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.12.16.30 clean
24.113.32.30 US AS-WAVE-1 24.113.32.30 clean
68.4.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.4.16.25 clean
74.118.212.1 US THREATTRACK-SECURITY-INC 74.118.212.1 clean
204.117.214.10 US SPRINTLINK 204.117.214.10 clean
4.79.142.202 US LEVEL3 4.79.142.202 clean
156.154.71.22 US ULTRADNS 156.154.71.22 clean
66.92.224.2 US ATL-CBEYOND 66.92.224.2 clean
64.81.159.2 US ATL-CBEYOND 64.81.159.2 clean
156.154.71.25 US ULTRADNS 156.154.71.25 clean
68.13.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.13.16.30 clean
208.67.222.220 US OPENDNS 208.67.222.220 clean
208.67.222.222 US OPENDNS 208.67.222.222 clean
68.10.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.10.16.30 clean
68.13.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.13.16.25 clean
4.2.2.2 US LEVEL3 4.2.2.2 clean
68.87.64.154 US COMCAST-7922 68.87.64.154 clean
216.231.41.2 US ATL-CBEYOND 216.231.41.2 clean
208.67.220.123 US OPENDNS 208.67.220.123 clean
64.81.127.2 US ATL-CBEYOND 64.81.127.2 clean
64.81.79.2 US ATL-CBEYOND 64.81.79.2 clean
74.118.212.2 US THREATTRACK-SECURITY-INC 74.118.212.2 clean
68.9.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.9.16.30 clean
68.6.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.6.16.30 clean
66.92.159.2 US NBS11696 66.92.159.2 clean
4.2.2.1 US LEVEL3 4.2.2.1 clean
4.2.2.3 US LEVEL3 4.2.2.3 clean
209.55.0.110 US MOMENTUM 209.55.0.110 clean
4.2.2.5 US LEVEL3 4.2.2.5 clean
4.2.2.4 US LEVEL3 4.2.2.4 clean
4.2.2.6 US LEVEL3 4.2.2.6 clean
68.4.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.4.16.30 clean
198.153.194.1 US ULTRADNS 198.153.194.1 clean
68.1.18.25 US ASN-CXA-ALL-CCI-22773-RDC 68.1.18.25 clean
68.100.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.100.16.30 clean
68.10.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.10.16.25 clean
68.12.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.12.16.25 clean
24.113.32.29 US AS-WAVE-1 24.113.32.29 clean
68.2.16.25 US ASN-CXA-ALL-CCI-22773-RDC 68.2.16.25 clean
68.111.16.30 US ASN-CXA-ALL-CCI-22773-RDC 68.111.16.30 clean
66.92.64.2 US ATL-CBEYOND 66.92.64.2 clean
64.81.111.2 US MEGAPATH5 64.81.111.2 clean
198.153.192.1 US ULTRADNS 198.153.192.1 clean
9.9.9.9 FR QUAD9-AS-1 9.9.9.9 clean

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x4a86b0 LoadLibraryA
 0x4a86b4 GetProcAddress
 0x4a86b8 VirtualAlloc
 0x4a86bc VirtualFree

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure