{"id":1517,"date":"2022-03-15T20:47:40","date_gmt":"2022-03-16T01:47:40","guid":{"rendered":"https:\/\/www.herbiez.com\/?p=1517"},"modified":"2022-03-16T00:42:08","modified_gmt":"2022-03-16T05:42:08","slug":"2022-03-14-emotet-malspam","status":"publish","type":"post","link":"https:\/\/www.herbiez.com\/?p=1517","title":{"rendered":"2022-03-14 Emotet Malspam"},"content":{"rendered":"<p>Summary<br \/>\n========<br \/>\nAs part of brushing the &#8220;rust&#8221; off and getting back into the malware analysis and blogging thing, and since I have some free time since I am on holiday, I decided to see what was in the mail filters for anything interesting or fun to play with. I did come across an email that had an encrypted zip attachment that was an Excel spreadsheet that leveraged a macro in it. For this post, I am not digging into the macro. This will be a simple analysis post. As usual, all the artifacts from this investigation can be found over in my <a href=\"https:\/\/github.com\/bloomer1016\/2022-03-14-Emotet-Malspam\" target=\"_blank\" rel=\"noopener\">Github<\/a>. The IOCs can be found at the end of the post or via this link <a href=\"#artifacts\">here<\/a>.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1535\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email-1024x499.png\" alt=\"\" width=\"900\" height=\"439\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email-1024x499.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email-300x146.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email-768x374.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email-1536x748.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email-150x73.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/email.png 1770w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><strong>****NOTE****<\/strong><br \/>\nI had some issues with a <a href=\"https:\/\/twitter.com\/HerbieZimmerman\/status\/1503590948651032577\" target=\"_blank\" rel=\"noopener\">bug<\/a> that I was running into with one of the latest versions of ProcMon last night and had to re-run things to get a better version of the ProcMon logs. For that one though, I skipped the &#8220;middle man&#8221; and just registered the malicious DLL manually to kick off the infection chain. Normally this would have executed via the macro found in the spreadsheet once the macro was enabled. I did include both ProcMon logs for reference though. Also, any references to PID 1616 is from the first ProcMon log. PID 4776 is the equivalent to PID 1616.<br \/>\n<strong>***\/NOTE****<\/strong><\/p>\n<p>Analysis<br \/>\n========<br \/>\nFrom a malware perspective this is a pretty straight forward compromise on both the network side and also the host side.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1531\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1024x197.png\" alt=\"\" width=\"900\" height=\"173\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1024x197.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-300x58.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-768x147.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1536x295.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2048x393.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-150x29.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1530\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-1024x232.png\" alt=\"\" width=\"900\" height=\"204\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-1024x232.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-300x68.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-768x174.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-1536x348.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-2048x463.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/brim-150x34.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1529\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-1024x349.png\" alt=\"\" width=\"900\" height=\"307\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-1024x349.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-300x102.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-768x262.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-1536x524.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-2048x698.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-tree-150x51.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>Once the spreadsheet is downloaded and opened Excel prompts the user to enable the malicious macro as seen below.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1534\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel-1024x535.png\" alt=\"\" width=\"900\" height=\"470\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel-1024x535.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel-300x157.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel-768x402.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel-150x78.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/excel.png 1312w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>Once the macro has been enabled, the compromise chain starts. First, the macro goes and downloads a DLL file from the site arkpp[.]com. The DLL was downloaded to the &#8220;C:\\Users\\%username%\\fbd.dll&#8221; location (notice the difference in names between the PCAP and once it lands on the host) .<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1533\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-1024x528.png\" alt=\"\" width=\"900\" height=\"464\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-1024x528.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-300x155.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-768x396.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-1536x792.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-2048x1056.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-1-150x77.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>As a side note, the malware author must like dogs as you can see various dog breeds in the stream and within the binary as well.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1532\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-1024x524.png\" alt=\"\" width=\"900\" height=\"461\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-1024x524.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-300x153.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-768x393.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-1536x786.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-2048x1047.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark-2-150x77.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>The file downloaded is called &#8220;Qbazm0Hh6NAHgHzpXWnpP.dll&#8221; in the PCAP (I renamed it to 2022-03-14-emotet.dll for the &#8220;good&#8221; ProcMon log and also from the PCAP as 9K1.bin) but is originally named &#8220;fbd.dll&#8221; and is what is leveraged using regsvr32.exe to register the malicious DLL into Windows. Once that has been registered and the initial process is running, two more child processes are then spawned off the initial one and are killed off automatically until there is only one regsvr32.exe process running with no parent process. The interesting thing about these three processes are what they are doing\/touching as it seems like each process is performing a certain function with regards to filesystem and registry &#8220;touches&#8221;.<\/p>\n<p>Using the &#8220;good&#8221; version of the ProcMon log, I looked at the three different regsvr32.exe processes filtering on the PIDs to see each process in isolation. Starting with PID 4104 (the parent) this one looks like it really is meant to get started up, then spawn the next child process (PID 5544), and then exit out as seen below.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1528\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-1024x359.png\" alt=\"\" width=\"900\" height=\"316\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-1024x359.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-300x105.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-768x270.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-1536x539.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-2048x719.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-1-150x53.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1527\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-1024x383.png\" alt=\"\" width=\"900\" height=\"337\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-1024x383.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-300x112.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-768x287.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-1536x574.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-2048x766.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/PID-4104-2-150x56.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>Jumping over to PID 5544 there is an obvious difference in what the process is doing when compared to the parent. This process looks to be querying various registry settings with a noticeable pattern that looks to be what is called COM abuse since I am seeing numerous queries for different CLSIDs and INPROCSERVER32\/LOCALSERVER32 based on some quick Google searches. I came across two good posts about this which can be found <a href=\"https:\/\/bohops.com\/2018\/06\/28\/abusing-com-registry-structure-clsid-localserver32-inprocserver32\" target=\"_blank\" rel=\"noopener\">here<\/a> and <a href=\"https:\/\/pentestlab.blog\/2020\/05\/20\/persistence-com-hijacking\" target=\"_blank\" rel=\"noopener\">here<\/a>. If this is COM abuse, this would give the malware a level of persistence. See <a href=\"https:\/\/attack.mitre.org\/techniques\/T1546\/015\" target=\"_blank\" rel=\"noopener\">Mitre&#8217;s ATT&amp;CK<\/a> for the TL;DR of COM abuse\/hijacking. Unfortunately using the PoSH commands found in both posts I was not able to replicate what they were seeing with an exposed COM object on my test VM. I went back and used ProcMon to see if there was anything modified with regards to either INPROCSERVER32\/LOCALSERVER32 registry keys and could not see anything in the log. Outside of that activity, there is a lot of fingerprinting activity that the process is doing as seen below.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1526\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-1024x437.png\" alt=\"\" width=\"900\" height=\"384\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-1024x437.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-300x128.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-768x328.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-1536x656.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-2048x875.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-1-150x64.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>It is also responsible for copying the original DLL (Qbazm0Hh6NAHgHzpXWnpP.dll\/fbd.dll) from the original location to the &#8220;C:\\Users\\%username%\\AppData\\Local\\&lt;random string&gt;\\&lt;random string&gt;.&lt;random 3 characters&gt;&#8221; and renaming it as seen below.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1525\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-2.png\" alt=\"\" width=\"617\" height=\"338\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-2.png 617w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-2-300x164.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-2-150x82.png 150w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/a><\/p>\n<p>Which it then finally closes itself out, and creates the final regsvr32.exe process (PID 4776).<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1524\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-3.png\" alt=\"\" width=\"963\" height=\"338\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-3.png 963w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-3-300x105.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-3-768x270.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-5544-3-150x53.png 150w\" sizes=\"auto, (max-width: 963px) 100vw, 963px\" \/><\/a><\/p>\n<p>The third and final regsvr32 process also continued to perform OS fingerprinting activities, but was reading various crypto registry keys, internet settings, and loading various DLL files related to web calls.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1523\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-1024x338.png\" alt=\"\" width=\"900\" height=\"297\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-1024x338.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-300x99.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-768x254.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-1536x507.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-2048x676.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-1-150x50.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1522\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-1024x340.png\" alt=\"\" width=\"900\" height=\"299\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-1024x340.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-300x100.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-768x255.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-1536x510.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-2048x680.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-2-150x50.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1521\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-1024x334.png\" alt=\"\" width=\"900\" height=\"294\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-1024x334.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-300x98.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-768x250.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-1536x501.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-2048x668.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-3-150x49.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/threads-regsvr32-pid-1616.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1539\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/threads-regsvr32-pid-1616.png\" alt=\"\" width=\"935\" height=\"617\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/threads-regsvr32-pid-1616.png 935w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/threads-regsvr32-pid-1616-300x198.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/threads-regsvr32-pid-1616-768x507.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/threads-regsvr32-pid-1616-150x99.png 150w\" sizes=\"auto, (max-width: 935px) 100vw, 935px\" \/><\/a><\/p>\n<p>It then proceeded to set the persistence mechanism in the &#8220;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\&#8221; registry location.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1520\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-4.png\" alt=\"\" width=\"902\" height=\"313\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-4.png 902w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-4-300x104.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-4-768x267.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/pid-4776-4-150x52.png 150w\" sizes=\"auto, (max-width: 902px) 100vw, 902px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1537\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence-1024x168.png\" alt=\"\" width=\"900\" height=\"148\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence-1024x168.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence-300x49.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence-768x126.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence-1536x252.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence-150x25.png 150w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/persistence.png 1875w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>Once this process was up and running, it starts beaconing back out to the C2 as seen below.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1540\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2.png\" alt=\"\" width=\"937\" height=\"769\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2.png 937w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2-300x246.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2-768x630.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2-150x123.png 150w\" sizes=\"auto, (max-width: 937px) 100vw, 937px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2a.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1538\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2a.png\" alt=\"\" width=\"662\" height=\"212\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2a.png 662w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2a-300x96.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2a-150x48.png 150w\" sizes=\"auto, (max-width: 662px) 100vw, 662px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2b.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1536\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2b.png\" alt=\"\" width=\"668\" height=\"196\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2b.png 668w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2b-300x88.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/procmon-c2b-150x44.png 150w\" sizes=\"auto, (max-width: 668px) 100vw, 668px\" \/><\/a><\/p>\n<p>I went back and took a look at the &#8220;messed up&#8221; ProcMon logs and it looks like the log is fine, it is just the newer version of ProcMon that is a little buggy. Anyways, looking at the initial download of the DLL via the Excel process, I noticed that the sizes recorded in ProcMon and in Wireshark are pretty close to each other.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1519\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-1024x428.png\" alt=\"\" width=\"900\" height=\"376\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-1024x428.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-300x125.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-768x321.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-1536x642.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-2048x856.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/wireshark3-150x63.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>I also used a tool called &#8220;<a href=\"http:\/\/split-code.com\/strings2.html\" target=\"_blank\" rel=\"noopener\">strings2<\/a>&#8221; to pull strings from the running regsvr32.exe prcoess (PID 1616 from the first ProcMon log) and piped that out to a log file. The following are some more of the interesting strings that I was able to find in this process. For example, I was able to find some more IP addresses that look to be used as possible C2s. I also found an interesting string (&lt;EXE NAME=&#8221;regsvr32.exe&#8221; ID=&#8221;{c7a85eba-c2d1-41ec-c656-ca2c9221e354}&#8221; DBID=&#8221;{11111111-1111-1111-1111-111111111111}&#8221;\/&gt;) that looks to be related to AppShimming. Some more Googling around and I came across another great <a href=\"https:\/\/redcanary.com\/blog\/detecting-application-shimming\" target=\"_blank\" rel=\"noopener\">post<\/a> from the folks at Red Canary talking about application shims. Based on some of the info in that post, I went back to the second ProcMon log and filtered for anything &#8220;SDB&#8221; in the path. Sure enough there were hits for the shim database for each process of regsvr32.exe.<\/p>\n<p><a href=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-1518\" src=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-1024x454.png\" alt=\"\" width=\"900\" height=\"399\" srcset=\"https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-1024x454.png 1024w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-300x133.png 300w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-768x341.png 768w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-1536x681.png 1536w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-2048x908.png 2048w, https:\/\/www.herbiez.com\/wp-content\/uploads\/2022\/03\/shims-150x67.png 150w\" sizes=\"auto, (max-width: 900px) 100vw, 900px\" \/><\/a><\/p>\n<p>While also just searching for keywords in the log, I did come across some bits of my system information as well as seen below.<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\nGET GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq HTTP\/1.1\r\nCookiez=SrzFvmGY1uBOVPYd1yv0gM24V9n393slc5lOHyoJ3GzjD+0impIcqACv6tBXSBSjXN4y6bkvdgVgyTi04ZGUb3EMVy5Y6KjQyGQLpCNagxegJYI+09LWyQmtaak5uJru0CHD0vKVjnI+wl1WgxiCPrsEK2L2f0KeGJzslsXmGuxoOOF8w\/85yn8gFURQcKcrxEV1Dq3XRIotzOvob9aqXgBX9QtKz6Ek3r3x7c6K3crDodv4D31dMZLNEYMHvc8rlRRPC\/YH+mKNT2O\r\nHost192.99.251.50GET \/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq HTTP\/1.1\r\nConnectionKeep-Alive\r\nCache-Controlno-cache\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq\r\nBOBSXPC_B4A6FEC6\r\n<\/pre>\n<p>And also some dead nginx sites as well.<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\nGET \/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv HTTP\/1.1\r\nCookie: AaApNexnjBNTnQ=SrzFvmGY1uBOVPYd1yv0gM24V9n393slc5lOHyoJ3GzjD+0impIcqACv6tBXSBSjXN4y6bkvdgVgyTi04ZGUb3EMVy5Y6KjQyGQLpCNagxegJYI+09LWyQmtaak5uJru0CHD0vKVjnI+wl1WgxiCPrsEK2L2f0KeGJzslsXmGuxoOOF8w\/85yn8gFURQcKcrxEV1Dq3XRIotzOvob9aqXlsEniXCixpyq6O3fQAY\/fmRl8hDyeSAa\/4Fm2pZzBzG\/Lu3Lbk5gYkHdQNGcpL+bfulIEI2spcKmLOIwPEzEIgj1uRfThDG+89PJVLsbiLKQDku4g==\r\nHost: 217.182.143.248:8080\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\nMSAFD Irda &#x5B;IrDA]\r\nMSAFD Tcpip &#x5B;UDP\/IPv6]\r\nMSAFD L2CAP &#x5B;Bluetooth]\r\n8\r\nHTTP\/1.1 502 Bad Gateway\r\nServer: nginx\r\nDate: Tue, 15 Mar 2022 02:01:31 GMT\r\nContent-Type: text\/html\r\nContent-Length: 173\r\nConnection: keep-alive\r\n<\/pre>\n<p>The following section are the other strings that I found interesting.<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\nQuery: &quot;:8080&quot;\r\n---------------\r\nLine 16962: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 16963: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 17776: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 17792: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 18469: 217.182.143.248:8080\r\nLine 18503: https:\/\/217.182.143.248:8080\/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv\r\nLine 18543: https:\/\/217.182.143.248:8080\/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv\r\nLine 18550: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 18668: Host: 217.182.143.248:8080\r\nLine 19007: https:\/\/217.182.143.248:8080\/pjUXpuZmP\r\nLine 19015: https:\/\/217.182.143.248:8080\/pjUXpuZmP\r\nLine 20396: 217.182.143.248:8080\r\nLine 20701: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20736: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20742: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20758: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20824: https:\/\/217.182.143.248:8080\/mgLhALIxcSErTBUYvIACyjUADjKVIxAnbrVFW\r\nLine 20861: https:\/\/217.182.143.248:8080\/mgLhALIxcSErTBUYvIACyjUADjKVIxAnbrVFW\r\nLine 21105: https:\/\/185.4.135.27:8080\/\r\nLine 21274: https:\/\/185.4.135.27:8080\/\r\nLine 21317: 185.4.135.27:8080\r\nLine 21374: 217.182.143.248:8080\r\nLine 21379: 217.182.143.248:8080\r\n\r\nQuery: &quot;https:&quot;\r\n----------------\r\nLine 16962: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 16963: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 17776: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 17792: https:\/\/217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR\r\nLine 18503: https:\/\/217.182.143.248:8080\/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv\r\nLine 18527: https:\/\/217.182.143.248\/\r\nLine 18538: https:\/\/217.182.143.248\/\r\nLine 18543: https:\/\/217.182.143.248:8080\/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv\r\nLine 18550: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 19007: https:\/\/217.182.143.248:8080\/pjUXpuZmP\r\nLine 19015: https:\/\/217.182.143.248:8080\/pjUXpuZmP\r\nLine 20279: https:\/\/192.99.251.50\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq\r\nLine 20289: https:\/\/192.99.251.50\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq\r\nLine 20701: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20736: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20742: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20758: https:\/\/185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh\r\nLine 20824: https:\/\/217.182.143.248:8080\/mgLhALIxcSErTBUYvIACyjUADjKVIxAnbrVFW\r\nLine 20861: https:\/\/217.182.143.248:8080\/mgLhALIxcSErTBUYvIACyjUADjKVIxAnbrVFW\r\nLine 21105: https:\/\/185.4.135.27:8080\/\r\nLine 21148: https:\/\/192.99.251.50\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq\r\nLine 21151: https:\/\/192.99.251.50\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq\r\nLine 21173: https:\/\/192.99.251.50\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq\r\nLine 21274: https:\/\/185.4.135.27:8080\/\r\nLine 21369: https:\/\/192.99.251.50\/\r\nLine 21372: https:\/\/192.99.251.50\/\r\nLine 21378: https:\/\/192.99.251.50\/\r\nLine 21380: https:\/\/192.99.251.50\/\r\nLine 21398: https:\/\/192.99.251.50\/\r\nLine 21399: https:\/\/185.4.135.27\/\r\nLine 21401: https:\/\/185.4.135.27\/\r\n\r\nQuery: &quot;regsvr32.exe&quot;\r\n----------------------\r\nLine 28: \\regsvr32.exe\r\nLine 345: REGSVR32.EXE\r\nLine 1918: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 2083: Microsoft.Windows.RegSvr32,processorArchitecture=&quot;x86&quot;,type=&quot;win32&quot;,version=&quot;5.1.0.0&quot;C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 2190: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 2259: The module &quot;%1&quot; may not compatible with the version of Windows that you're running. Check if the module is compatible with an x86 (32-bit) or x64 (64-bit) version of regsvr32.exe.\r\nLine 2283: REGSVR32.EXE.MUI\r\nLine 2431: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 13917: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 13918: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 13919: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 16665: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 16666: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 16667: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 16732: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 16737: C:\\Windows\\Temp\\AslLog_ApphelpDebug_regsvr32.exe_1616.txt\r\nLine 16742: C:\\Windows\\Temp\\AslLog_shimengstate_regsvr32.exe_1616.txt\r\nLine 16744: C:\\Windows\\Temp\\AslLog_ShimDebugLog_regsvr32.exe_1616.txt\r\nLine 16765: &amp;amp;amp;amp;amp;amp;amp;lt;EXE NAME=&quot;regsvr32.exe&quot; ID=&quot;{c7a85eba-c2d1-41ec-c656-ca2c9221e354}&quot; DBID=&quot;{11111111-1111-1111-1111-111111111111}&quot;\/&amp;amp;amp;amp;amp;amp;amp;gt;\r\nLine 16980: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 17180: regsvr32.exe\r\nLine 17188: regsvr32.exe\r\nLine 17255: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 17256: \\Device\\HarddiskVolume1\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 17327: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 19955: regsvr32.exe\r\nLine 21257: %s\\regsvr32.exe \/s &quot;%s\\%s&quot;\r\nLine 22836: regsvr32.exe:1616 Properties\r\nLine 23048: regsvr32.exe(00000650) (netsvcs) Properties\r\nLine 23166: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 36483: C:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 46610: &#x5B;zC:\\Windows\\SysWOW64\\regsvr32.exe\r\nLine 378706: regsvr32.exe\r\nLine 612840: C:\\Windows\\SysWOW64\\regsvr32.exe\r\n\r\nQuery: &quot;c7a85eba-c2d1-41ec-c656-ca2c9221e354&quot; and the lines around that \r\n---------------------------------------------------------------------------\r\n=C:=C:\\Users\\bob\\Desktop\r\nALLUSERSPROFILE=C:\\ProgramData\r\nAPPDATA=C:\\Users\\bob\\AppData\\Roaming\r\nChocolateyInstall=C:\\ProgramData\\chocolatey\r\nChocolateyLastPathUpdate=132853495844597753\r\nChocolateyToolsLocation=C:\\Tools\r\nCommonProgramFiles=C:\\Program Files (x86)\\Common Files\r\nCommonProgramFiles(x86)=C:\\Program Files (x86)\\Common Files\r\nCommonProgramW6432=C:\\Program Files\\Common Files\r\nCOMPUTERNAME=BOBS-PC\r\nComSpec=C:\\Windows\\system32\\cmd.exe\r\nDriverData=C:\\Windows\\System32\\Drivers\\DriverData\r\nFPS_BROWSER_APP_PROFILE_STRING=Internet Explorer\r\nFPS_BROWSER_USER_PROFILE_STRING=Default\r\nHOMEDRIVE=C:\r\nHOMEPATH=\\Users\\bob\r\nJAVA_HOME=C:\\Program Files\\OpenJDK\\openjdk-11.0.13_8\r\nLOCALAPPDATA=C:\\Users\\bob\\AppData\\Local\r\nLOGONSERVER=\\\\BOBS-PC\r\nNUMBER_OF_PROCESSORS=4\r\nOneDrive=C:\\Users\\bob\\OneDrive\r\nOS=Windows_NT\r\nPath=C:\\Program Files\\Microsoft Office 15\\Root\\Office15\\;C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath;C:\\Python37\\Scripts\\;C:\\Python37\\;C:\\Python27\\;C:\\Python27\\Scripts;C:\\ProgramData\\Boxstarter;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\;C:\\Windows\\System32\\OpenSSH\\;C:\\ProgramData\\chocolatey\\bin;C:\\Program Files\\Puppet Labs\\Puppet\\bin;C:\\Program Files\\OpenJDK\\openjdk-11.0.13_8\\bin;C:\\Program Files\\nodejs\\;C:\\Program Files\\Microsoft VS Code\\bin;C:\\Users\\bob\\AppData\\Local\\Microsoft\\WindowsApps;C:\\Tools\\Cmder;;C:\\ProgramData\\chocolatey\\lib\\radare2.flare\\tools\\radare2\\bin;C:\\Tools\\java-deobfuscator-gui;C:\\Tools\\Bytecode-Viewer;C:\\Program Files (x86)\\Nmap;C:\\ProgramData\\chocolatey\\lib\\rawcap\\tools\\rawcap;C:\\Tools\\pyinstxtractor;C:\\Tools\\oledump;C:\\Tools\\rtfdump;C:\\Tools\\msoffcrypto-crack;C:\\Program Files (x86)\\pdfid;C:\\Program Files (x86)\\pdfparser;C:\\pdfstreamdumper;C:\\iDefense\\SysAnalyzer;C:\\Users\\bob\\AppData\\Local\\Programs\\Fiddler;C:\\Users\\bob\\AppData\\Roaming\\npm;C:\\Program Files\\Microsoft Office 15\\root\\Client\r\nPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC;.PY;.PYW\r\nPROCESSOR_ARCHITECTURE=x86\r\nPROCESSOR_ARCHITEW6432=AMD64\r\nPROCESSOR_IDENTIFIER=Intel64 Family 6 Model 140 Stepping 1, GenuineIntel\r\nPROCESSOR_LEVEL=6\r\nPROCESSOR_REVISION=8c01\r\nProgramData=C:\\ProgramData\r\nProgramFiles=C:\\Program Files (x86)\r\nProgramFiles(x86)=C:\\Program Files (x86)\r\nProgramW6432=C:\\Program Files\r\nPROMPT=FLARE$S$d$s$t$_$p$+$g\r\nPSModulePath=C:\\Users\\bob\\Documents\\WindowsPowerShell\\Modules\r\nPUBLIC=C:\\Users\\Public\r\nRAW_TOOLS_DIR=C:\\Tools\r\nSESSIONNAME=Console\r\nSSLKEYLOGFILE=C:\\Users\\bob\\Documents\\ssl-keys.log\r\nSystemDrive=C:\r\nSystemRoot=C:\\Windows\r\nTEMP=C:\\Users\\bob\\AppData\\Local\\Temp\r\nTMP=C:\\Users\\bob\\AppData\\Local\\Temp\r\nTOOL_LIST_DIR=C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\FLARE\r\nTOOL_LIST_SHORTCUT=C:\\Users\\bob\\Desktop\\FLARE.lnk\r\nUSERDOMAIN=BOBS-PC\r\nUSERDOMAIN_ROAMINGPROFILE=BOBS-PC\r\nUSERNAME=bob\r\nUSERPROFILE=C:\\Users\\bob\r\nVM_COMMON_DIR=C:\\ProgramData\\FEVM\r\nwindir=C:\\Windows\r\n_NT_SYMBOL_PATH=symsrv*symsrv.dll*C:\\symbols*http:\/\/msdl.microsoft.com\/download\/symbols\r\nC:\\Users\\bob\\Desktop\\\r\nC:\\Windows\\SysWOW64\\regsvr32.exe\r\nC:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nC:\\Windows\\SysWOW64\\regsvr32.exe\r\nWinsta0\\Default\r\n=::=::\\\r\n=C:=C:\\Users\\bob\\Desktop\r\nALLUSERSPROFILE=C:\\ProgramData\r\nAPPDATA=C:\\Users\\bob\\AppData\\Roaming\r\nChocolateyInstall=C:\\ProgramData\\chocolatey\r\nChocolateyLastPathUpdate=132853495844597753\r\nChocolateyToolsLocation=C:\\Tools\r\nCommonProgramFiles=C:\\Program Files (x86)\\Common Files\r\nCommonProgramFiles(x86)=C:\\Program Files (x86)\\Common Files\r\nCommonProgramW6432=C:\\Program Files\\Common Files\r\nCOMPUTERNAME=BOBS-PC\r\nComSpec=C:\\Windows\\system32\\cmd.exe\r\nDriverData=C:\\Windows\\System32\\Drivers\\DriverData\r\nFPS_BROWSER_APP_PROFILE_STRING=Internet Explorer\r\nFPS_BROWSER_USER_PROFILE_STRING=Default\r\nHOMEDRIVE=C:\r\nHOMEPATH=\\Users\\bob\r\nJAVA_HOME=C:\\Program Files\\OpenJDK\\openjdk-11.0.13_8\r\nLOCALAPPDATA=C:\\Users\\bob\\AppData\\Local\r\nLOGONSERVER=\\\\BOBS-PC\r\nNUMBER_OF_PROCESSORS=4\r\nOneDrive=C:\\Users\\bob\\OneDrive\r\nOS=Windows_NT\r\nPath=C:\\Program Files\\Microsoft Office 15\\Root\\Office15\\;C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath;C:\\Python37\\Scripts\\;C:\\Python37\\;C:\\Python27\\;C:\\Python27\\Scripts;C:\\ProgramData\\Boxstarter;C:\\Windows\\system32;C:\\Windows;C:\\Windows\\System32\\Wbem;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\;C:\\Windows\\System32\\OpenSSH\\;C:\\ProgramData\\chocolatey\\bin;C:\\Program Files\\Puppet Labs\\Puppet\\bin;C:\\Program Files\\OpenJDK\\openjdk-11.0.13_8\\bin;C:\\Program Files\\nodejs\\;C:\\Program Files\\Microsoft VS Code\\bin;C:\\Users\\bob\\AppData\\Local\\Microsoft\\WindowsApps;C:\\Tools\\Cmder;;C:\\ProgramData\\chocolatey\\lib\\radare2.flare\\tools\\radare2\\bin;C:\\Tools\\java-deobfuscator-gui;C:\\Tools\\Bytecode-Viewer;C:\\Program Files (x86)\\Nmap;C:\\ProgramData\\chocolatey\\lib\\rawcap\\tools\\rawcap;C:\\Tools\\pyinstxtractor;C:\\Tools\\oledump;C:\\Tools\\rtfdump;C:\\Tools\\msoffcrypto-crack;C:\\Program Files (x86)\\pdfid;C:\\Program Files (x86)\\pdfparser;C:\\pdfstreamdumper;C:\\iDefense\\SysAnalyzer;C:\\Users\\bob\\AppData\\Local\\Programs\\Fiddler;C:\\Users\\bob\\AppData\\Roaming\\npm;C:\\Program Files\\Microsoft Office 15\\root\\Client\r\nPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC;.PY;.PYW\r\nPROCESSOR_ARCHITECTURE=x86\r\nPROCESSOR_ARCHITEW6432=AMD64\r\nPROCESSOR_IDENTIFIER=Intel64 Family 6 Model 140 Stepping 1, GenuineIntel\r\nPROCESSOR_LEVEL=6\r\nPROCESSOR_REVISION=8c01\r\nProgramData=C:\\ProgramData\r\nProgramFiles=C:\\Program Files (x86)\r\nProgramFiles(x86)=C:\\Program Files (x86)\r\nProgramW6432=C:\\Program Files\r\nPROMPT=FLARE$S$d$s$t$_$p$+$g\r\nPSModulePath=C:\\Users\\bob\\Documents\\WindowsPowerShell\\Modules\r\nPUBLIC=C:\\Users\\Public\r\nRAW_TOOLS_DIR=C:\\Tools\r\nSESSIONNAME=Console\r\nSSLKEYLOGFILE=C:\\Users\\bob\\Documents\\ssl-keys.log\r\nSystemDrive=C:\r\nSystemRoot=C:\\Windows\r\nTEMP=C:\\Users\\bob\\AppData\\Local\\Temp\r\nTMP=C:\\Users\\bob\\AppData\\Local\\Temp\r\nTOOL_LIST_DIR=C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\FLARE\r\nTOOL_LIST_SHORTCUT=C:\\Users\\bob\\Desktop\\FLARE.lnk\r\nUSERDOMAIN=BOBS-PC\r\nUSERDOMAIN_ROAMINGPROFILE=BOBS-PC\r\nUSERNAME=bob\r\nUSERPROFILE=C:\\Users\\bob\r\nVM_COMMON_DIR=C:\\ProgramData\\FEVM\r\nwindir=C:\\Windows\r\n_NT_SYMBOL_PATH=symsrv*symsrv.dll*C:\\symbols*http:\/\/msdl.microsoft.com\/download\/symbols\r\nC:\\Windows\\SYSTEM32\\ntdll.dll\r\nC:\\Windows\\System32\r\nC:\\Windows\\SYSTEM32;C:\\Windows\\system;C:\\Windows;\r\nvI}m\r\nC:\\Users\\bob\\Desktop\\\r\nC:\\Windows\\SYSTEM32\\apphelp.dll\r\nvaoC\r\nC:\\Windows\\System32\\KERNEL32.DLL\r\n\\l#mW\r\nC:\\Windows\\System32\\KERNELBASE.dll\r\nC:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\n2\r\nRC\r\nTLt0\r\nApphelpDebug\r\nC:\\Windows\\Temp\\AslLog_ApphelpDebug_regsvr32.exe_1616.txt\r\n. }$\r\nTLtX\r\nApphelp\r\nshimengstate\r\nC:\\Windows\\Temp\\AslLog_shimengstate_regsvr32.exe_1616.txt\r\nShimDebugLog\r\nC:\\Windows\\Temp\\AslLog_ShimDebugLog_regsvr32.exe_1616.txt\r\nSHA1\r\nMicrosoft Primitive Provider\r\nbcryptprimitives.dll\r\nC:\\Windows\\SYSTEM32\\AcLayers.dll\r\n_NT_SYMBOL_PATH=symsrv*symsrv.dll*C:\\symbols*http:\/\/msdl.microsoft.com\/download\/symbols\r\nC:\\Windows\\System32\\msvcrt.dll\r\nJAVA_HOME=C:\\Program Files\\OpenJDK\\openjdk-11.0.13_8\r\nTOOL_LIST_DIR=C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\FLARE\r\nUSER32.dll\r\nC:\\Windows\\System32\\USER32.dll\r\nenforcesigninglevelfordependentmodules\r\nSSLKEYLOGFILE=C:\\Users\\bob\\Documents\\ssl-keys.log\r\nTOOL_LIST_SHORTCUT=C:\\Users\\bob\\Desktop\\FLARE.lnk\r\nC:\\Windows\\System32\\win32u.dll\r\nonlyallowcontrolflowguardenabledbinaries\r\nGDI32.dll\r\n&amp;amp;amp;amp;amp;amp;amp;lt;?xml version=&quot;1.0&quot; encoding=&quot;utf-8&quot;?&amp;amp;amp;amp;amp;amp;amp;gt;\r\n\r\n&amp;amp;amp;amp;amp;amp;amp;lt;MATCHED_ENTRIES&amp;amp;amp;amp;amp;amp;amp;gt;\r\n\r\n&amp;amp;amp;amp;amp;amp;amp;lt;EXE NAME=&quot;regsvr32.exe&quot; ID=&quot;{c7a85eba-c2d1-41ec-c656-ca2c9221e354}&quot; DBID=&quot;{11111111-1111-1111-1111-111111111111}&quot;\/&amp;amp;amp;amp;amp;amp;amp;gt;\r\n\r\n&amp;amp;amp;amp;amp;amp;amp;lt;\/MATCHED_ENTRIES&amp;amp;amp;amp;amp;amp;amp;gt;\r\n\r\nQuery: &quot;outnpny&quot;\r\n-----------------\r\nLine 1918: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 2296: C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb\r\nLine 2432: C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb\r\nLine 13918: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 16666: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 16732: C:\\Windows\\SysWOW64\\regsvr32.exe \/s &quot;C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb&quot;\r\nLine 16900: C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb\r\nLine 17676: Emehnrnpmefb\\outnpny.kzb\r\nLine 18454: outnpny.kzb\r\nLine 23167: C:\\Users\\bob\\AppData\\Local\\Emehnrnpmefb\\outnpny.kzb\r\nLine 23831: outnpny.kzb\r\n\r\nQuery: &quot;S-1-5-21-3461203602-4096304019-2269080069&quot; - My system SID\r\n--------------------------------------------------------------------\r\nLine 1861: \\REGISTRY\\USER\\S-1-5-21-3461203602-4096304019-2269080069-1003\\SOFTWARE\\Microsoft\\Windows\\Current\r\nLine 1873: \\REGISTRY\\USER\\S-1-5-21-3461203602-4096304019-2269080069-1003\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunBags3Z\\\r\nLine 13942: \\REGISTRY\\USER\\S-1-5-21-3461203602-4096304019-2269080069-1003\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\r\nLine 13957: Y\\USER\\S-1-5-21-3461203602-4096304019-2269080069-1003\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\r\nLine 17613: webcache_{031b98cf-4a69-4c31-ab42-fd9b3c199407}_S-1-5-21-3461203602-4096304019-2269080069-1003\r\nLine 17618: webcache_{031b98cf-4a69-4c31-ab42-fd9b3c199407}_S-1-5-21-3461203602-4096304019-2269080069-1003\r\nLine 17839: webcache_{031b98cf-4a69-4c31-ab42-fd9b3c199407}_S-1-5-21-3461203602-4096304019-2269080069-1003\r\n\r\nQuery: &quot;nginx&quot;\r\n----------------\r\nGET \/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv HTTP\/1.1\r\nCookie: AaApNexnjBNTnQ=SrzFvmGY1uBOVPYd1yv0gM24V9n393slc5lOHyoJ3GzjD+0impIcqACv6tBXSBSjXN4y6bkvdgVgyTi04ZGUb3EMVy5Y6KjQyGQLpCNagxegJYI+09LWyQmtaak5uJru0CHD0vKVjnI+wl1WgxiCPrsEK2L2f0KeGJzslsXmGuxoOOF8w\/85yn8gFURQcKcrxEV1Dq3XRIotzOvob9aqXlsEniXCixpyq6O3fQAY\/fmRl8hDyeSAa\/4Fm2pZzBzG\/Lu3Lbk5gYkHdQNGcpL+bfulIEI2spcKmLOIwPEzEIgj1uRfThDG+89PJVLsbiLKQDku4g==\r\nHost: 217.182.143.248:8080\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\nMSAFD Irda &#x5B;IrDA]\r\nMSAFD Tcpip &#x5B;UDP\/IPv6]\r\nMSAFD L2CAP &#x5B;Bluetooth]\r\n8\r\nHTTP\/1.1 502 Bad Gateway\r\nServer: nginx\r\nDate: Tue, 15 Mar 2022 02:01:31 GMT\r\nContent-Type: text\/html\r\nContent-Length: 173\r\nConnection: keep-alive\r\n\r\nQuery: &quot;GET \/&quot;\r\n-------------------\r\nLine 17700: Host192.99.251.50 GET \/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq HTTP\/1.1\r\nLine 18664: GET \/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv HTTP\/1.1\r\n<\/pre>\n<p id=\"artifacts\">Artifacts<br \/>\n==========<\/p>\n<p>OSINT<br \/>\n&#8212;&#8212;&#8212;-<br \/>\n<a href=\"https:\/\/tria.ge\/220314-y191labhh9\" target=\"_blank\" rel=\"noopener\">https:\/\/tria.ge\/220314-y191labhh9<\/a><br \/>\n<a href=\"https:\/\/tria.ge\/220315-aj5gsaebg4\" target=\"_blank\" rel=\"noopener\">https:\/\/tria.ge\/220315-aj5gsaebg4<\/a><br \/>\n<a href=\"https:\/\/tria.ge\/220315-qe56hsbec2\" target=\"_blank\" rel=\"noopener\">https:\/\/tria.ge\/220315-qe56hsbec2<\/a><br \/>\n<a href=\"https:\/\/app.any.run\/tasks\/7000b947-2ab9-4e3b-bbcd-eba0c459af96\" target=\"_blank\" rel=\"noopener\">https:\/\/app.any.run\/tasks\/7000b947-2ab9-4e3b-bbcd-eba0c459af96<\/a><br \/>\n<a href=\"https:\/\/urlhaus.abuse.ch\/browse.php?search=www.arkpp.com\" target=\"_blank\" rel=\"noopener\">https:\/\/urlhaus.abuse.ch\/browse.php?search=www.arkpp.com<\/a><\/p>\n<p>IOCs<br \/>\n&#8212;&#8212;&#8211;<br \/>\nwww[.]arkpp[.]com<br \/>\n146[.]59[.]226[.]45<br \/>\n61[.]61[.]127[.]68<br \/>\n185[.]4[.]135[.]27:8080<br \/>\n192[.]99[.]251[.]50<br \/>\n217[.]182[.]143[.]248:8080<\/p>\n<p>URIs<br \/>\n&#8212;&#8212;&#8211;<br \/>\n185.4.135.27:8080\/VmiDTRawFeKRBbtXXJDwGXXHUKVtYgGFZuSvIXnSOsTIPh<br \/>\n192.99.251.50\/GIkOEmWvEuWNRKAxYXzFlZFjifQrTylGFDgmHwq<br \/>\n217.182.143.248:8080\/mXZnXrixsLeAyUDItYgZngTrcancmWprjPFEqOQZZsWqTkEGzldUVsGpKLDukv<br \/>\n217.182.143.248:8080\/mgLhALIxcSErTBUYvIACyjUADjKVIxAnbrVFW<br \/>\n217.182.143.248:8080\/pjUXpuZmP<br \/>\n217.182.143.248:8080\/snPqOycogkeznKykYjmXLpWfvXHqEdVwsyIyysXhCrXrtzOJckvdR<\/p>\n<p>File hashes<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;<br \/>\n2022-03-14_1551.xlsm &#8211; 8e586a928eecac9fa5b4dd6980915389f0092c6ec968ffe90dc4ccf3504ae578<br \/>\nfbd.dll &#8211; a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22<br \/>\nEmehnrnpmefb\/outnpny.kzb &#8211; a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22<\/p>\n<p>Munin results<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br \/>\n[ ] Processing \/outnpny.kzb &#8230;<br \/>\n[ ] Processing \/2022-03-14_1551.xlsm &#8230;<br \/>\n[ ] Processing \/fbd.dll &#8230;<br \/>\n[+] Processing 3 lines &#8230;<\/p>\n<p>1 \/ 3 &gt; Suspicious<br \/>\nHASH: a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22 COMMENT: outnpny.kzb<br \/>\nVIRUS: Microsoft: Trojan:Win32\/Sabsik.FL.B!ml \/ Kaspersky: VHO:Trojan-Banker.Win32.Convagent.gen<br \/>\nTYPE: Win32 DLL SIZE: 997.0 KB FILENAMES: XHtmlTreeTest.exe, emotet_exe_e4_a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22_2022-03-15__011320._exe<br \/>\nFIRST: 2022-03-15 01:13:22 LAST: 2022-03-15 01:13:22 SUBMISSIONS: 1 REPUTATION: 0<br \/>\nCOMMENTS: 0 USERS: &#8211; TAGS: PEDLL<br \/>\nRESULT: 4 \/ 65<\/p>\n<p>2 \/ 3 &gt; Unknown<br \/>\nHASH: 8e586a928eecac9fa5b4dd6980915389f0092c6ec968ffe90dc4ccf3504ae578 COMMENT: 2022-03-14_1551.xlsm<br \/>\nRESULT: &#8211; \/ &#8211;<\/p>\n<p>3 \/ 3 &gt; Unknown<br \/>\nHASH: a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22 COMMENT: fbd.dll RULE: &#8211;<br \/>\nTYPE: &#8211; SIZE: 0 FILENAMES: &#8211;<br \/>\nFIRST: &#8211; LAST: &#8211; SUBMISSIONS: 0 REPUTATION: 0<br \/>\nCOMMENTS: 0 USERS: &#8211; TAGS:<br \/>\nRESULT: 0 \/ 65<br \/>\n[!] Sample on ANY.RUN URL: <a href=\"https:\/\/any.run\/report\/a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22\" target=\"_blank\" rel=\"noopener\">https:\/\/any.run\/report\/a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22<\/a><\/p>\n<p>Machinae results<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n********************************************************************************<br \/>\n* Information for arkpp.com<br \/>\n* Observable type: fqdn (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[-] No URLVoid Results<br \/>\n[-] No URL Unshorten Results<br \/>\n[-] No Malc0de Results<br \/>\n[+] Fortinet Category Results<br \/>\n[-] Fortinet URL Category: Malicious Websites<br \/>\n[+] VirusTotal pDNS Results<br \/>\n[-] pDNS data from VirusTotal: (&#8216;2020-11-13&#8242;, &#8217;61[.]61.127.68&#8217;)<br \/>\n[-] pDNS data from VirusTotal: (&#8216;2019-11-06&#8242;, &#8217;61[.]63.62.68&#8217;)<br \/>\n[-] pDNS data from VirusTotal: (&#8216;2021-12-25&#8242;, &#8217;91[.]195.240.87&#8217;)<br \/>\n[-] No McAfee Threat Results<\/p>\n<p>********************************************************************************<br \/>\n* Information for 146.59.226.45<br \/>\n* Observable type: ipv4 (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[+] IP Whois Results<br \/>\n[-] ASN Information: (&#8216;16276&#8217;, &#8216;146[.]59.0.0\/16&#8217;, &#8216;1994-03-08&#8217;, &#8216;ripencc&#8217;, &#8216;FR&#8217;)<br \/>\n[-] Network Information: (&#8216;146[.]59.226.0\/23&#8217;, &#8216;VPS-GRA8&#8217;, &#8216;146[.]59.226.0 &#8211; 146[.]59.227.255&#8217;)<br \/>\n[-] Registration Info: (&#8216;2020-10-22&#8217;, &#8216;2020-10-22&#8217;)<br \/>\n[-] Registration Locality: FR<br \/>\n[-] Abuse Email: abuse@ovh[.]net<br \/>\n[+] IPVoid Results<br \/>\n[-] Number of detections: 4<br \/>\n[-] IP Void Detection Rate: 4%<br \/>\n[-] Engines: (&#8216;Feodo Tracker&#8217;, &#8216;(hXXps):\/\/feodotracker[.]abuse[.]ch\/&#8217;)<br \/>\n[-] Engines: (&#8216;IPsum&#8217;, &#8216;hXXps:\/\/github[.]com\/stamparm\/ipsum&#8217;)<br \/>\n[-] Engines: (&#8216;Redstout Threat IP list&#8217;, &#8216;(hXXps):\/\/www[.]redstout[.]com\/index[.]html&#8217;)<br \/>\n[-] Engines: (&#8216;Snapt NovaSense&#8217;, &#8216;hXXps:\/\/novasense-threats[.]com\/&#8217;)<br \/>\n[-] No Malc0de Results<br \/>\n[+] AbuseIPDB Results<br \/>\n[-] AbuseIPDB reports: 2<br \/>\n[!] Error from RansomwareTracker: 503 Server Error: Backend unavailable, connection timeout for url: https:\/\/ransomwaretracker.abuse.ch\/host\/146.59.226.45<br \/>\n[-] No SANS Results<br \/>\n[!] Error from freegeoip.io: 403 Client Error: Forbidden for url: https:\/\/freegeoip.io\/json\/146.59.226.45<br \/>\n[+] Fortinet Category Results<br \/>\n[-] Fortinet URL Category: Malicious Websites<br \/>\n[+] VirusTotal pDNS Results<br \/>\n[-] pDNS data from VirusTotal: (&#8216;2022-03-11&#8217;, &#8216;vps-05aa197a.vps[.]ovh[.]net&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXp:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-14&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-09&#8217;, &#8216;hXXps:\/\/146[.]59.226.45\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-08&#8217;, &#8216;hXXp:\/\/146[.]59.226.45:443\/&#8217;)<br \/>\n[-] No McAfee Threat Results<br \/>\n[-] No ThreatCrowd IP Report Results<br \/>\n[-] No GreyNoise Results<\/p>\n<p>********************************************************************************<br \/>\n* Information for 185.4.135.27<br \/>\n* Observable type: ipv4 (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[+] IP Whois Results<br \/>\n[-] ASN Information: (&#8216;199246&#8217;, &#8216;185[.]4.132.0\/22&#8217;, &#8216;2012-09-26&#8217;, &#8216;ripencc&#8217;, &#8216;GR&#8217;)<br \/>\n[-] Network Information: (&#8216;185[.]4.132.0\/22&#8217;, &#8216;GR-PAPAKI-20120926&#8217;, &#8216;185[.]4.132.0 &#8211; 185[.]4.135.255&#8217;)<br \/>\n[-] Registration Info: (&#8216;2012-09-26&#8217;, &#8216;2020-07-20&#8217;)<br \/>\n[-] Registration Locality: GR<br \/>\n[-] Abuse Email: abuse@papaki[.]gr<br \/>\n[+] IPVoid Results<br \/>\n[-] Number of detections: 4<br \/>\n[-] IP Void Detection Rate: 4%<br \/>\n[-] Engines: (&#8216;IPsum&#8217;, &#8216;hXXps:\/\/github[.]com\/stamparm\/ipsum&#8217;)<br \/>\n[-] Engines: (&#8216;Redstout Threat IP list&#8217;, &#8216;(hXXps):\/\/www[.]redstout[.]com\/index[.]html&#8217;)<br \/>\n[-] Engines: (&#8216;S5hbl&#8217;, &#8216;(hXXp):\/\/www.usenix[.]org[.]uk\/content\/rbl[.]html&#8217;)<br \/>\n[-] Engines: (&#8216;Snapt NovaSense&#8217;, &#8216;hXXps:\/\/novasense-threats[.]com\/&#8217;)<br \/>\n[-] No Malc0de Results<br \/>\n[-] No AbuseIPDB Results<br \/>\n[-] No SANS Results<br \/>\n[+] Fortinet Category Results<br \/>\n[-] Fortinet URL Category: Malicious Websites<br \/>\n[+] VirusTotal pDNS Results<br \/>\n[-] pDNS data from VirusTotal: (&#8216;2022-03-08&#8217;, &#8216;webmail[.]lybe[.]gr&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXp:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXp:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXp:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-14&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-14&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-14&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-14&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-14&#8217;, &#8216;hXXps:\/\/185[.]4.135.27\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-09&#8217;, &#8216;hXXps:\/\/185[.]4.135.27:8080\/&#8217;)<br \/>\n[-] No McAfee Threat Results<br \/>\n[-] No ThreatCrowd IP Report Results<br \/>\n[-] No GreyNoise Results<\/p>\n<p>********************************************************************************<br \/>\n* Information for 192.99.251.50<br \/>\n* Observable type: ipv4 (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[+] IP Whois Results<br \/>\n[-] ASN Information: (&#8216;16276&#8217;, &#8216;192[.]99.0.0\/16&#8217;, &#8216;2013-06-17&#8217;, &#8216;arin&#8217;, &#8216;CA&#8217;)<br \/>\n[-] Network Information: (&#8216;192[.]99.0.0\/16&#8217;, &#8216;NET-192-99-0-0-1&#8217;, &#8216;OVH-ARIN-7&#8217;, &#8216;192[.]99.0.0 &#8211; 192[.]99.255.255&#8217;)<br \/>\n[-] Network Information: (&#8216;192[.]99.251.48\/29&#8217;, &#8216;NET-192-99-251-48-1&#8217;, &#8216;OVH-CUST-7087977&#8217;, &#8216;192[.]99.251.48 &#8211; 192[.]99.251.55&#8217;)<br \/>\n[-] Registration Info: (&#8216;OVH Hosting, Inc.&#8217;, &#8216;2013-06-17&#8217;, &#8216;2013-06-17&#8217;)<br \/>\n[-] Registration Info: (&#8216;Private Customer&#8217;, &#8216;2018-04-22&#8217;, &#8216;2018-04-22&#8217;)<br \/>\n[-] Registration Locality: (&#8216;Montreal&#8217;, &#8216;QC&#8217;, &#8216;H3A 2N4&#8217;, &#8216;CA&#8217;)<br \/>\n[-] Registration Locality: (&#8216;BENTONG&#8217;, &#8216;28700&#8217;, &#8216;MY&#8217;)<br \/>\n[-] Abuse Email: abuse@ovh[.]ca<br \/>\n[-] Tech Email: noc@ovh[.]net<br \/>\n[+] IPVoid Results<br \/>\n[-] Number of detections: 6<br \/>\n[-] IP Void Detection Rate: 7%<br \/>\n[-] Engines: (&#8216;Barracuda_Reputation_BL&#8217;, &#8216;(hXXp):\/\/www[.]barracudanetworks[.]com\/&#8217;)<br \/>\n[-] Engines: (&#8216;Feodo Tracker&#8217;, &#8216;(hXXps):\/\/feodotracker[.]abuse[.]ch\/&#8217;)<br \/>\n[-] Engines: (&#8216;IPsum&#8217;, &#8216;hXXps:\/\/github[.]com\/stamparm\/ipsum&#8217;)<br \/>\n[-] Engines: (&#8216;Redstout Threat IP list&#8217;, &#8216;(hXXps):\/\/www[.]redstout[.]com\/index[.]html&#8217;)<br \/>\n[-] Engines: (&#8216;S5hbl&#8217;, &#8216;(hXXp):\/\/www.usenix[.]org[.]uk\/content\/rbl[.]html&#8217;)<br \/>\n[-] Engines: (&#8216;Snapt NovaSense&#8217;, &#8216;hXXps:\/\/novasense-threats[.]com\/&#8217;)<br \/>\n[-] No Malc0de Results<br \/>\n[-] No AbuseIPDB Results<br \/>\n[-] No SANS Results<br \/>\n[+] Fortinet Category Results<br \/>\n[-] Fortinet URL Category: Malicious Websites<br \/>\n[+] VirusTotal pDNS Results<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-16&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/192[.]99.251.50\/&#8217;)<br \/>\n[-] No McAfee Threat Results<br \/>\n[-] No ThreatCrowd IP Report Results<br \/>\n[-] No GreyNoise Results<\/p>\n<p>********************************************************************************<br \/>\n* Information for 217.182.143.248<br \/>\n* Observable type: ipv4 (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[+] IP Whois Results<br \/>\n[-] ASN Information: (&#8216;16276&#8217;, &#8216;217[.]182.0.0\/16&#8217;, &#8216;2001-03-02&#8217;, &#8216;ripencc&#8217;, &#8216;FR&#8217;)<br \/>\n[-] Network Information: (&#8216;217[.]182.0.0\/16&#8217;, &#8216;FR-OVH-20010302&#8217;, &#8216;217[.]182.0.0 &#8211; 217[.]182.255.255&#8217;)<br \/>\n[-] Registration Info: (&#8216;2017-02-20&#8217;, &#8216;2017-02-20&#8217;)<br \/>\n[-] Registration Locality: FR<br \/>\n[-] Abuse Email: abuse@ovh[.]net<br \/>\n[+] IPVoid Results<br \/>\n[-] Number of detections: 3<br \/>\n[-] IP Void Detection Rate: 3%<br \/>\n[-] Engines: (&#8216;IPsum&#8217;, &#8216;hXXps:\/\/github[.]com\/stamparm\/ipsum&#8217;)<br \/>\n[-] Engines: (&#8216;Redstout Threat IP list&#8217;, &#8216;(hXXps):\/\/www[.]redstout[.]com\/index[.]html&#8217;)<br \/>\n[-] Engines: (&#8216;Snapt NovaSense&#8217;, &#8216;hXXps:\/\/novasense-threats[.]com\/&#8217;)<br \/>\n[-] No Malc0de Results<br \/>\n[+] AbuseIPDB Results<br \/>\n[-] AbuseIPDB reports: 7<br \/>\n[-] No SANS Results<br \/>\n[+] Fortinet Category Results<br \/>\n[-] Fortinet URL Category: Malicious Websites<br \/>\n[+] VirusTotal pDNS Results<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXp:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXp:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248:8080\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] pDNS malicious URLs from VirusTotal: (&#8216;2022-03-15&#8217;, &#8216;hXXps:\/\/217[.]182.143.248\/&#8217;)<br \/>\n[-] No McAfee Threat Results<br \/>\n[-] No ThreatCrowd IP Report Results<br \/>\n[-] No GreyNoise Results<\/p>\n<p>********************************************************************************<br \/>\n* Information for 8e586a928eecac9fa5b4dd6980915389f0092c6ec968ffe90dc4ccf3504ae578<br \/>\n* Observable type: hash.sha256 (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[+] VirusTotal File Report Results<br \/>\n[-] Date submitted: 2022-03-15 16:55:14<br \/>\n[-] Detected engines: 30<br \/>\n[-] Total engines: 60<br \/>\n[-] Scans: (&#8216;DrWeb&#8217;, &#8216;X97M[.]DownLoader.929&#8217;)<br \/>\n[-] Scans: (&#8216;MicroWorld-eScan&#8217;, &#8216;Trojan[.]Vita.6&#8217;)<br \/>\n[-] Scans: (&#8216;FireEye&#8217;, &#8216;Trojan[.]Vita.6&#8217;)<br \/>\n[-] Scans: (&#8216;CAT-QuickHeal&#8217;, &#8216;DOC[.]Emotet.45887&#8217;)<br \/>\n[-] Scans: (&#8216;Sangfor&#8217;, &#8216;Malware.Generic-XLM[.]Save[.]ma35&#8217;)<br \/>\n[-] Scans: (&#8216;Alibaba&#8217;, &#8216;TrojanDownloader:VBA\/MalDoc[.]ali1000101&#8217;)<br \/>\n[-] Scans: (&#8216;K7GW&#8217;, &#8216;Trojan ( 0058ce181 )&#8217;)<br \/>\n[-] Scans: (&#8216;K7AntiVirus&#8217;, &#8216;Trojan ( 0058ce181 )&#8217;)<br \/>\n[-] Scans: (&#8216;Arcabit&#8217;, &#8216;Trojan[.]Vita.6&#8217;)<br \/>\n[-] Scans: (&#8216;Cyren&#8217;, &#8216;XLSM\/Downldr.A[.]aggr!Camelot&#8217;)<br \/>\n[-] Scans: (&#8216;ESET-NOD32&#8217;, &#8216;multiple detections&#8217;)<br \/>\n[-] Scans: (&#8216;TrendMicro-HouseCall&#8217;, &#8216;TROJ_FRS[.]VSNTCE22&#8217;)<br \/>\n[-] Scans: (&#8216;Avast&#8217;, &#8216;VBS:Malware-gen&#8217;)<br \/>\n[-] Scans: (&#8216;Kaspersky&#8217;, &#8216;HEUR:Trojan.MSOffice[.]Emotet[.]gen&#8217;)<br \/>\n[-] Scans: (&#8216;BitDefender&#8217;, &#8216;Trojan[.]Vita.6&#8217;)<br \/>\n[-] Scans: (&#8216;Emsisoft&#8217;, &#8216;Trojan[.]Vita.6 (B)&#8217;)<br \/>\n[-] Scans: (&#8216;TrendMicro&#8217;, &#8216;TROJ_FRS[.]VSNTCE22&#8217;)<br \/>\n[-] Scans: (&#8216;McAfee-GW-Edition&#8217;, &#8216;X97M\/Downloader[.]kj&#8217;)<br \/>\n[-] Scans: (&#8216;Sophos&#8217;, &#8216;Troj\/DocDl-AFRE&#8217;)<br \/>\n[-] Scans: (&#8216;GData&#8217;, &#8216;Macro.Trojan-Downloader[.]Agent[.]BDH&#8217;)<br \/>\n[-] Scans: (&#8216;Antiy-AVL&#8217;, &#8216;Trojan\/Generic[.]ASMalwRG.167&#8217;)<br \/>\n[-] Scans: (&#8216;Microsoft&#8217;, &#8216;TrojanDownloader:O97M\/Emotet[.]PKCL!MTB&#8217;)<br \/>\n[-] Scans: (&#8216;ZoneAlarm&#8217;, &#8216;HEUR:Trojan.MSOffice[.]Emotet[.]gen&#8217;)<br \/>\n[-] Scans: (&#8216;AhnLab-V3&#8217;, &#8216;Downloader\/XML[.]XlmMacro.S1774&#8217;)<br \/>\n[-] Scans: (&#8216;McAfee&#8217;, &#8216;Downloader-FCHG!CAB6670DF74A&#8217;)<br \/>\n[-] Scans: (&#8216;MAX&#8217;, &#8216;malware (ai score=85)&#8217;)<br \/>\n[-] Scans: (&#8216;Zoner&#8217;, &#8216;Probably Heur.W97ShellN&#8217;)<br \/>\n[-] Scans: (&#8216;Rising&#8217;, &#8216;Downloader[.]Agent\/XLM!1.DC56 (CLASSIC)&#8217;)<br \/>\n[-] Scans: (&#8216;Fortinet&#8217;, &#8216;MSExcel\/Agent[.]DVP!tr&#8217;)<br \/>\n[-] Scans: (&#8216;AVG&#8217;, &#8216;VBS:Malware-gen&#8217;)<br \/>\n[+] MetaDefender File Report Results<br \/>\n[-] Date submitted: 2022-03-15T17:04:08.882Z<br \/>\n[-] Detected engines: 6<br \/>\n[-] Total engines: 35<br \/>\n[-] Scans: (&#8216;Cyren&#8217;, &#8216;XLSM\/Downldr.A[.]aggr!Camelot&#8217;)<br \/>\n[-] Scans: (&#8216;IKARUS&#8217;, &#8216;Trojan-Downloader[.]XLM[.]Agent&#8217;)<br \/>\n[-] Scans: (&#8216;Kaspersky&#8217;, &#8216;HEUR:Trojan.MSOffice[.]Emotet[.]gen&#8217;)<br \/>\n[-] Scans: (&#8216;McAfee&#8217;, &#8216;X97M\/Downloader[.]kj&#8217;)<br \/>\n[-] Scans: (&#8216;RocketCyber&#8217;, &#8221;)<br \/>\n[-] Scans: (&#8216;Sophos&#8217;, &#8216;Troj\/DocDl-AFRE&#8217;)<br \/>\n[-] Scans: (&#8216;Webroot SMD&#8217;, &#8221;)<br \/>\n[-] Scans: (&#8216;Jiangmin&#8217;, &#8216;Unavailable (production)&#8217;)<br \/>\n[-] Scans: (&#8216;Scrutiny&#8217;, &#8221;)<br \/>\n[-] Scans: (&#8216;Vir[.]IT eXplorer&#8217;, &#8216;X97M[.]Emotet[.]DGN&#8217;)<\/p>\n<p>********************************************************************************<br \/>\n* Information for a6565a3bf494f2aa107e07fdd345bed1f31205da76492a6cdceffdb1d7cf5c22<br \/>\n* Observable type: hash.sha256 (Auto-detected: True)<br \/>\n********************************************************************************<br \/>\nNot seeing what you expect? Likely not a valid site. Try running with &#8211;list-sites<\/p>\n<p>[+] VirusTotal File Report Results<br \/>\n[-] Date submitted: 2022-03-15 01:13:22<br \/>\n[-] Detected engines: 4<br \/>\n[-] Total engines: 65<br \/>\n[-] Scans: (&#8216;Kaspersky&#8217;, &#8216;VHO:Trojan-Banker.Win32[.]Convagent[.]gen&#8217;)<br \/>\n[-] Scans: (&#8216;Antiy-AVL&#8217;, &#8216;Trojan\/Generic[.]ASCommon.21F&#8217;)<br \/>\n[-] Scans: (&#8216;Microsoft&#8217;, &#8216;Trojan:Win32\/Sabsik[.]FL.B!ml&#8217;)<br \/>\n[-] Scans: (&#8216;Rising&#8217;, &#8216;Trojan[.]Kryptik!8.8 (C64:YzY0Oh\/jx0YklSUX)&#8217;)<br \/>\n[+] MetaDefender File Report Results<br \/>\n[-] Detected engines: 1<br \/>\n[-] Total engines: 1<br \/>\n[-] Scans: (&#8216;Avira&#8217;, &#8216;TR\/AD[.]Nekark.a6565a&#8217;)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Summary ======== As part of brushing the &#8220;rust&#8221; off and getting back into the malware analysis and blogging thing, and since I have some free time since I am on holiday, I decided to see what was in the mail filters for anything interesting or fun to play with. I did come across an email that had an encrypted zip attachment that was an Excel spreadsheet that leveraged a macro in it. For this post, I am not digging into the macro. This will be a simple analysis post. As usual, all the artifacts from this investigation can be found&#8230;<\/p>\n<p> <a class=\"continue-reading-link\" href=\"https:\/\/www.herbiez.com\/?p=1517\"><span>Continue reading<\/span><i class=\"crycon-right-dir\"><\/i><\/a> <\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[12],"class_list":["post-1517","post","type-post","status-publish","format-standard","hentry","category-packet-analysis","tag-emotet"],"_links":{"self":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1517"}],"version-history":[{"count":13,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1517\/revisions"}],"predecessor-version":[{"id":1553,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1517\/revisions\/1553"}],"wp:attachment":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}