The sample contacted only unknown URLs. |
Host | Country | City | Protocols | Reputation Status |
---|---|---|---|---|
doc2th.com (192.232.251.15) | United States | Houston | HTTP, DNS, TCP |
Unknown
|
URL | Connection Successful | Reputation Status |
---|---|---|
doc2th.com/tin/off.exe |
Unknown
|
Operation | Additional Information | Success | Count | Logfile |
---|---|---|---|---|
Resolve Name | host = doc2th.com, address_out = 192.232.251.15 | 1 |
Fn
|
Information | Value |
---|---|
Total Data Sent | 0.07 KB (71 bytes) |
Total Data Received | 232.23 KB (237802 bytes) |
Contacted Host Count | 1 |
Contacted Hosts | doc2th.com |
Information | Value |
---|---|
Server Name | doc2th.com |
Server Port | 80 |
Data Sent | 0.07 KB (71 bytes) |
Data Received | 232.23 KB (237802 bytes) |
Operation | Additional Information | Success | Count | Logfile |
---|---|---|---|---|
Open Session | access_type = WINHTTP_ACCESS_TYPE_NO_PROXY, proxy_name = WINHTTP_NO_PROXY_NAME, proxy_bypass = WINHTTP_NO_PROXY_BYPASS | 1 |
Fn
|
|
Open Connection | protocol = http, server_name = doc2th.com, server_port = 80 | 1 |
Fn
|
|
Open HTTP Request | http_verb = GET, http_version = HTTP/1.1, target_resource = /tin/off.exe | 1 |
Fn
|
|
Send HTTP Request | headers = host: doc2th.com, connection: Keep-Alive, url = doc2th.com/tin/off.exe | 1 |
Fn
Data
|
|
Read Response | size = 4096, size_out = 4096 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 8972 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 3752 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 3508 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 23232 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 7260 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 1452 | 2 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 2904 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 1452 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 4356 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 1452 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 20328 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 5808 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 1452 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 4356 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 17424 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 4356 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 30492 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 4356 | 1 |
Fn
Data
|
|
Read Response | size = 65536, size_out = 30492 | 1 |
Fn
Data
|
|
Read Response | size = 54850, size_out = 15972 | 1 |
Fn
Data
|
|
Read Response | size = 38878, size_out = 2904 | 1 |
Fn
Data
|
|
Read Response | size = 35974, size_out = 24684 | 1 |
Fn
Data
|
|
Read Response | size = 11290, size_out = 11290 | 1 |
Fn
Data
|
|
Close Session | - | 1 |
Fn
|
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".