

0 403 Not Foundįound strings which match to known social media urls HTTP traffic detected: HTTP/1.1 4 03 Forbidd enConnecti on: closeX -Powered-B y: PHP/7.4. Tries to download or post to a non-existing HTTP route (HTTP/1.1 404 Not Found / 503 Service Unavailable / 403 Forbidden) Network traffic detected: HTTP traff ic on port 443 -> 49 733 Network traffic detected: HTTP traff ic on port 49733 -> 443

JA3 SSL client fingerprint seen in connection with other malware Source: C:\Windows \SysWOW64\ msiexec.ex e

Source: C:\Windows \System32\ msiexec.ex e drĬhecks for available system drives (often done to infect USB drives) drīinary string: C:\OpenSSL \Temp\open ssl-1.0.2h -x32\out32 dll\libeay 32.pdb sou rce: libea 圓2.dll.2. 7:49733 v ersion: TL S 1.2īinary string: C:\Branch\ win\Releas e\custact\ x86\AICust Act.pdb so urce: SlNX e5bAfS.msiīinary string: C:\dvs\p4\ build\sw\r el\gpu_drv \r384\r384 _00\driver s\ui\NvSma rtMax\NvSm artMaxapp\ bin\releas e\NvSmartM axApp.pdb6 ,kx source : Fzpiv.ex e, 0000001 9.00000000. Uses secure TLS version for HTTPS connections
