| Yara Pattern Name | Description |
|---|---|
| Str_Win32_Wininet_Library | Match Windows Inet API library declaration |
| spyeye | SpyEye X.Y memory |
| IsPE32 | No Description Available |
| HasOverlay | Overlay Check |
| HasDigitalSignature | DigitalSignature Check |
| HasDebugData | DebugData Check |
| HasRichSignature | Rich Signature Check |
| anti_dbg | Checks if being debugged |
| disable_dep | Bypass DEP |
| escalate_priv | Escalade priviledges |
| screenshot | Take screenshot |
| win_registry | Affect system registries |
| win_token | Affect system token |
| win_files_operation | Affect private profile |
| Advapi_Hash_API | Looks for advapi API functions |
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| .text | 0x00001000 | 0x00050938 | 0x00050a00 | 6.37310729568 |
| .data | 0x00052000 | 0x00004564 | 0x00002000 | 3.7782392076 |
| .idata | 0x00057000 | 0x00001528 | 0x00001600 | 5.4112995152 |
| .rsrc | 0x00059000 | 0x0000a3a8 | 0x0000a400 | 3.97025169423 |
| .reloc | 0x00064000 | 0x00006604 | 0x00006800 | 4.33795978342 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_ICON | 0x0005f530 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_DIALOG | 0x0005fbdc | 0x000001a4 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_DIALOG | 0x0005fbdc | 0x000001a4 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_DIALOG | 0x0005fbdc | 0x000001a4 | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_GROUP_ICON | 0x0005fddc | 0x0000005a | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_GROUP_ICON | 0x0005fddc | 0x0000005a | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_VERSION | 0x0005fe38 | 0x000002dc | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| RT_MANIFEST | 0x00060114 | 0x0000044a | LANG_ENGLISH | SUBLANG_ENGLISH_US | None |
| None | 0x000605ac | 0x0000003c | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x000605ac | 0x0000003c | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x000605ac | 0x0000003c | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x000605e8 | 0x000001b2 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x0006318c | 0x00000006 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x00063194 | 0x00000004 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x000631a4 | 0x00000202 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| None | 0x000631a4 | 0x00000202 | LANG_NEUTRAL | SUBLANG_NEUTRAL | None |
| Ordinal | Address | Name |
|---|---|---|
| 1 | 0x41c9b1 | _DecodePointerInternal@4 |
| 2 | 0x41c9cc | _EncodePointerInternal@4 |
| Domain | IP Address | Destination Location |
|---|---|---|
| downloadcbm.tsspltd.com | 52.4.96.36 | US |
| www.bing.com | 13.107.21.200 | US |
| go.microsoft.com | 23.10.88.237 | US |
| www.bing.com | 204.79.197.200 | US |
| dns.msftncsi.com | 131.107.255.255 | US |
GET /CBMCalculator.application HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: downloadcbm.tsspltd.com Connection: Keep-Alive
GET /favicon.ico HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.bing.com Connection: Keep-Alive
GET /CBMCalculator.application HTTP/1.1 Accept: */* Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Range: bytes=3173- Unless-Modified-Since: Wed, 05 Sep 2018 06:35:52 GMT If-Range: "019dbb0e244d41:0" Host: downloadcbm.tsspltd.com Connection: Keep-Alive
GET /CBMCalculator.application HTTP/1.1 Accept: */* Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate If-Modified-Since: Wed, 05 Sep 2018 06:35:52 GMT If-None-Match: "019dbb0e244d41:0" Host: downloadcbm.tsspltd.com Connection: Keep-Alive
GET /CBMCalculator.application HTTP/1.1 Accept: */* Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate If-Modified-Since: Wed, 05 Sep 2018 06:35:52 GMT If-None-Match: "019dbb0e244d41:0" Host: downloadcbm.tsspltd.com Connection: Keep-Alive
GET /CBMCalculator.application HTTP/1.1 Accept: */* Accept-Language: en-us User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Range: bytes=3219- Unless-Modified-Since: Wed, 05 Sep 2018 06:35:52 GMT If-Range: "019dbb0e244d41:0" Host: downloadcbm.tsspltd.com Connection: Keep-Alive
GET /CBMCalculator.application HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: downloadcbm.tsspltd.com Connection: Keep-Alive
GET /CBMCalculator.application HTTP/1.1 Host: downloadcbm.tsspltd.com Accept-Encoding: gzip Connection: Keep-Alive
GET /Application%20Files/CBMCalculator_2_0_0_52/CBMCalculator.exe.manifest HTTP/1.1 Host: downloadcbm.tsspltd.com Accept-Encoding: gzip
| IP Address | Country of Origin |
|---|---|
| 52.4.96.36 | US |
| 216.58.206.14 | US |
| 204.79.197.200 | US |
| Process Name | PID | Parent PID |