ComfyUI_LayerStyle
Yara Scan Results
Generated on 2024-07-14 08:45:50
Passed Tests
Failed Tests
Issues
FILE README_CN.MD
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 58936 | 0 | b'https://drive.google.com' | ||
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 90483 | 0 | b'https://drive.google.com' | ||
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 103486 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 58936 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 90483 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 103486 | 0 | b'https://drive.google.com' |
FILE lut/BlueArchitecture.cube
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $virtualbox_mac_1c | False | () | b'080027' | 6 | 94190 | 0 | b'080027' | ||
anti_sandboxing | VBox_Detection | $virtualbox_mac_1c | False | () | b'080027' | 6 | 94190 | 0 | b'080027' | ||
anti_sandboxing | vmdetect | $virtualbox_mac_1c | False | nex () | b'080027' | 6 | 94190 | 0 | b'080027' |
FILE py/local_groundingdino/util/slconfig.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 8892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 8942 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9031 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9065 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9113 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9265 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 8892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 8942 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9031 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9065 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9113 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9265 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 8892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 8942 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9031 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9065 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9113 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9265 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 8892 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 8942 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9031 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9065 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9113 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 9265 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 8892 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 8942 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9031 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9065 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9113 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 9265 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 8892 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 8942 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9031 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9065 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9113 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 9265 | 0 | b'identifier' |
FILE py/data_nodes.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'99999999999999999999' | 20 | 277 | 0 | b'99999999999999999999' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'99999999999999999999' | 20 | 9405 | 0 | b'99999999999999999999' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'99999999999999999999' | 20 | 9434 | 0 | b'99999999999999999999' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'99999999999999999999' | 20 | 9916 | 0 | b'99999999999999999999' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'99999999999999999999' | 20 | 9945 | 0 | b'99999999999999999999' |
FILE py/iopaint/plugins/restoreformer.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'eaeeff6c4a1caa1673977cb374e6f699' | 32 | 525 | 0 | b'eaeeff6c4a1caa1673977cb374e6f699' |
FILE py/iopaint/plugins/anime_seg.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'5f25479076b73074730ab8de9e8f2051' | 32 | 12045 | 0 | b'5f25479076b73074730ab8de9e8f2051' |
FILE py/iopaint/plugins/gfpgan_plugin.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'94d735072630ab734561130a47bc44f8' | 32 | 508 | 0 | b'94d735072630ab734561130a47bc44f8' |
FILE py/iopaint/plugins/realesrgan.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'91a7644643c884ee00737db24e478156' | 32 | 1247 | 0 | b'91a7644643c884ee00737db24e478156' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'99ec365d4afad750833258a1a24f44ca' | 32 | 1776 | 0 | b'99ec365d4afad750833258a1a24f44ca' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'd58ce384064ec1591c2ea7b79dbf47ba' | 32 | 2324 | 0 | b'd58ce384064ec1591c2ea7b79dbf47ba' |
FILE py/iopaint/plugins/interactive_seg.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'01ec64d29a2fca3f0661936605ae66f8' | 32 | 549 | 0 | b'01ec64d29a2fca3f0661936605ae66f8' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'0b3195507c641ddb6910d2bb5adee89c' | 32 | 709 | 0 | b'0b3195507c641ddb6910d2bb5adee89c' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'4b8939a88964f0f4ff5f5b2642c598a6' | 32 | 869 | 0 | b'4b8939a88964f0f4ff5f5b2642c598a6' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'f3c0d8cda613564d499310dab6c812cd' | 32 | 1041 | 0 | b'f3c0d8cda613564d499310dab6c812cd' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'c6b8953247bcfdc8bb8ef91e36a6cacc' | 32 | 1205 | 0 | b'c6b8953247bcfdc8bb8ef91e36a6cacc' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'08947267966e4264fb39523eccc33f86' | 32 | 1369 | 0 | b'08947267966e4264fb39523eccc33f86' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'3560f6b6a5a6edacd814a1325c39640a' | 32 | 1533 | 0 | b'3560f6b6a5a6edacd814a1325c39640a' |
FILE py/iopaint/web_app/assets/index-_6nUWG_P.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 702711 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235773 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235878 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236784 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236889 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237472 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237577 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238109 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238214 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238745 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238850 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239382 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240224 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240329 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240672 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240777 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241400 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242061 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242166 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242700 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242805 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315158 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444780 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444830 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445247 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445297 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445711 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445761 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 599659 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 599829 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200375 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200407 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222111 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222128 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349080 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349141 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 653962 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 702248 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 712321 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 712821 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200027 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200427 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200486 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202105 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222362 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530158 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530184 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530279 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530299 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533506 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565789 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566405 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707789 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711052 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711178 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712358 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712465 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712569 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 714429 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714445 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715223 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719723 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 721651 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 723784 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 730894 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 733331 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 739633 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 739925 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 702711 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-c6LmMFap.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 702629 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26439 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26474 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26681 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26958 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27055 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27087 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235768 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235873 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236779 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236884 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237467 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237572 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238104 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238209 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238740 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238845 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239377 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239482 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240219 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240324 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240667 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240772 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241395 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241500 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242056 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242161 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242695 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242800 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274678 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315135 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315482 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444897 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444947 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445364 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445414 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445828 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445878 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 599692 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 599862 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200011 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200370 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200402 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202032 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222106 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222123 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349057 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349118 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 653888 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 702166 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 712239 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 712739 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30641 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30689 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148890 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153907 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154479 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160074 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160161 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166561 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168037 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168058 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173603 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174219 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176765 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176897 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177692 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177707 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200022 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200422 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200481 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202100 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222357 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530228 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530254 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530349 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530369 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533576 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565859 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566475 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707707 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710970 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711096 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712276 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712383 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712487 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 714347 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714363 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715141 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719641 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 721569 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 723702 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 730812 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 733249 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 739551 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 739843 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 702629 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26787 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26835 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-qFliSBYV.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698683 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235770 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235875 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236886 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237469 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237574 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238106 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238211 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238742 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238847 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239379 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240221 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240326 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240669 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240774 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241397 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241502 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242058 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242163 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242802 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 314980 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315327 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444602 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444652 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445069 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445119 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445533 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445583 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595723 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595893 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200375 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200407 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222111 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222128 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 348902 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 348963 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 649925 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 698220 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708293 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708793 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200027 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200427 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200486 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202105 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222362 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 529980 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530006 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530101 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530121 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533328 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565611 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566227 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 703761 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707024 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707150 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708330 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708437 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708541 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 710401 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710417 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711195 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715693 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 717621 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719754 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 726864 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 729301 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735603 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735895 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698683 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-8BlaS7ws.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698590 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235749 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235854 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236760 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236865 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237448 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237553 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238085 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238190 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238721 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238826 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239358 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239463 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240200 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240305 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240648 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240753 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241376 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241481 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242037 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242142 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242676 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 314959 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315306 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444725 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444775 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445192 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445242 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445656 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445706 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595846 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 596016 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 199995 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200354 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200386 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222090 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222107 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349025 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349086 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 650048 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 698127 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708200 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708700 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200006 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200406 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200465 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202084 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222341 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530103 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530129 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530224 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530244 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533451 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565734 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566350 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 703668 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 706931 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707057 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708237 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708344 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708448 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 710308 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710324 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711102 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715602 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 717530 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719663 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 726773 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 729210 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735512 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735804 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698590 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-kS3ik1bw.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 702702 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26439 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26474 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26681 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26958 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27055 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27087 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235768 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235873 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236779 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236884 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237467 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237572 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238104 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238209 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238740 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238845 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239377 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239482 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240219 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240324 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240667 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240772 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241395 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241500 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242056 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242161 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242695 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242800 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274678 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315135 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315482 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444897 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444947 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445364 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445414 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445828 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445878 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 599692 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 599862 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200011 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200370 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200402 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202032 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222106 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222123 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349057 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349118 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 653961 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 702239 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 712312 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 712812 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30641 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30689 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148890 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153907 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154479 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160074 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160161 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166561 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168037 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168058 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173603 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174219 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176765 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176897 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177692 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177707 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200022 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200422 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200481 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202100 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222357 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530228 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530254 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530349 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530369 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533576 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565859 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566475 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707780 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711043 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711169 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712349 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712456 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712560 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 714420 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714436 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715214 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719714 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 721642 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 723775 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 730885 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 733322 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 739624 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 739916 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 702702 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26787 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26835 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85090 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136699 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142204 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142236 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142949 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142981 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-NQyCh9rO.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698674 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235770 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235875 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236886 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237469 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237574 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238106 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238211 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238742 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238847 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239379 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240221 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240326 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240669 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240774 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241397 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241502 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242058 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242163 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242802 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 314980 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315327 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444602 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444652 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445069 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445119 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445533 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445583 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595723 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595893 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200375 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200407 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222111 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222128 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 348902 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 348963 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 649925 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 698211 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708284 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708784 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200027 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200427 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200486 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202105 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222362 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 529980 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530006 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530101 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530121 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533328 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565611 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566227 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 703752 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707015 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707141 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708321 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708428 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708532 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 710392 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710408 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711186 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715684 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 717612 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719745 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 726855 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 729292 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735594 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735886 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698674 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-QuEBEP4v.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 704443 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235773 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235878 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236784 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236889 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237472 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237577 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238109 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238214 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238745 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238850 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239382 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240224 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240329 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240672 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240777 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241400 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242061 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242166 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242700 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242805 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315184 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315531 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445677 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445727 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446144 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446194 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446608 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446658 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 600556 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 600726 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 682902 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 683039 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200375 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200407 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222111 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222128 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349106 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349167 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 654858 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 703980 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 714053 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 714553 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200027 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200427 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200486 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202105 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222362 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 531055 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 531081 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 531176 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 531196 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 534403 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566686 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 567302 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 709521 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712784 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712910 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714090 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714197 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714301 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 716161 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 716177 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 716955 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 721455 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 723383 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 725516 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 732626 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735063 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 741365 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 741657 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 704443 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-CXO-mkQB.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698634 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235770 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235875 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236886 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237469 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237574 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238106 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238211 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238742 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238847 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239379 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240221 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240326 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240669 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240774 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241397 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241502 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242058 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242163 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242802 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 314980 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315327 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444746 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444796 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445213 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445263 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445677 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445727 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595867 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 596037 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200375 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200407 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222111 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222128 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349046 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349107 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 650069 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 698171 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708244 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708744 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200027 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200427 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200486 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202105 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222362 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530124 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530150 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530245 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530265 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533472 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565755 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566371 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 703712 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 706975 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707101 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708281 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708388 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708492 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 710352 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710368 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711146 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715648 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 717576 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719709 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 726819 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 729256 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735558 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735850 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698634 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-Tqq3L7kY.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698590 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235749 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235854 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236760 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236865 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237448 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237553 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238085 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238190 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238721 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238826 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239358 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239463 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240200 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240305 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240648 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240753 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241376 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241481 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242037 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242142 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242676 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 314959 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315306 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444725 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444775 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445192 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445242 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445656 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445706 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595846 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 596016 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 199995 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200354 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200386 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222090 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222107 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349025 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349086 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 650048 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 698127 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708200 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708700 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200006 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200406 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200465 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202084 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222341 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530103 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530129 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530224 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530244 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533451 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565734 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566350 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 703668 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 706931 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707057 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708237 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708344 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708448 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 710308 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710324 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711102 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715602 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 717530 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719663 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 726773 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 729210 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735512 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735804 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698590 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-hrusMZZs.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698611 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235770 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235875 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236886 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237469 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237574 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238106 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238211 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238742 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238847 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239379 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240221 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240326 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240669 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240774 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241397 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241502 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242058 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242163 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242802 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 314980 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315327 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444746 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 444796 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445213 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445263 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445677 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445727 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 595867 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 596037 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 199995 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200354 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200386 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222090 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222107 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349046 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349107 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 650069 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 698148 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708221 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 708721 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200006 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200406 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200465 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202084 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222341 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530124 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530150 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530245 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530265 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 533472 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 565755 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566371 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 703689 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 706952 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 707078 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708258 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708365 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 708469 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 710329 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 710345 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 711123 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 715623 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 717551 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 719684 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 726794 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 729231 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735533 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 735825 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 698611 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/web_app/assets/index-TI-UMrGI.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 704335 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26441 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26476 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26683 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 26960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235773 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 235878 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236784 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 236889 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237472 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 237577 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238109 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238214 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238745 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 238850 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239382 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 239487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240224 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240329 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240672 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 240777 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241400 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 241505 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242061 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242166 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242700 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 242805 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 274697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315184 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 315531 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445551 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 445601 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446018 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446068 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446482 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 446532 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 600430 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 600600 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 682793 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 682930 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200016 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200375 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 200407 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 202037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222111 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 222128 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349106 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 349167 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 654732 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 703872 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 713945 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 714445 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30643 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 30691 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 148892 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 153909 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 154481 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160076 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 160163 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 166563 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168039 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 168060 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 173605 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 174221 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176767 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 176899 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177694 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'OnError' | 7 | 177709 | 0 | b'OnError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200027 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200427 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 200486 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 202105 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 222362 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530929 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 530955 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 531050 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 531070 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 534277 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 566560 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 567176 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 709413 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712676 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 712802 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 713982 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714089 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 714193 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 716053 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 716069 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 716847 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 721347 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 723275 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 725408 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 732518 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 734955 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 741257 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 741549 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 704335 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26789 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 26837 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 85092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 136701 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142206 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142951 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 142983 | 0 | b'identifier' |
FILE py/iopaint/model/fcf.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'3323152bc01bf1c56fd8aba74435a211' | 32 | 53421 | 0 | b'3323152bc01bf1c56fd8aba74435a211' |
FILE py/iopaint/model/manga.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'7d8b269c4613b6b3768af714610da86c' | 32 | 505 | 0 | b'7d8b269c4613b6b3768af714610da86c' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'0c926d5a4af8450b0d00bc5b9a095644' | 32 | 754 | 0 | b'0c926d5a4af8450b0d00bc5b9a095644' |
FILE py/iopaint/model/mat.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'8ca927835fa3f5e21d65ffcb165377ed' | 32 | 60452 | 0 | b'8ca927835fa3f5e21d65ffcb165377ed' |
FILE py/iopaint/model/mi_gan.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'76eb3b1a71c400ee3290524f7a11b89c' | 32 | 457 | 0 | b'76eb3b1a71c400ee3290524f7a11b89c' |
FILE py/iopaint/model/zits.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'9978cc7157dc29699e42308d675b2154' | 32 | 489 | 0 | b'9978cc7157dc29699e42308d675b2154' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'55e31af21ba96bbf0c80603c76ea8c5f' | 32 | 770 | 0 | b'55e31af21ba96bbf0c80603c76ea8c5f' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'3d88a07211bd41b2ec8cc0d999f29927' | 32 | 1096 | 0 | b'3d88a07211bd41b2ec8cc0d999f29927' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'a9727c63a8b48b65c905d351b21ce46b' | 32 | 1381 | 0 | b'a9727c63a8b48b65c905d351b21ce46b' |
FILE py/iopaint/model/lama.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'e3aa4aaa15225a33ec84f9f4bc47e500' | 32 | 433 | 0 | b'e3aa4aaa15225a33ec84f9f4bc47e500' |
FILE py/iopaint/model/ldm.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'23239fc9081956a3e70de56472b3f296' | 32 | 691 | 0 | b'23239fc9081956a3e70de56472b3f296' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'fe419cd15a750d37a4733589d0d3585c' | 32 | 959 | 0 | b'fe419cd15a750d37a4733589d0d3585c' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b0afda12bf790c03aba2a7431f11d22d' | 32 | 1226 | 0 | b'b0afda12bf790c03aba2a7431f11d22d' |
FILE py/iopaint/model/anytext/ldm/util.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'65f7265353f403714fce3b2595e0b298' | 32 | 2587 | 0 | b'65f7265353f403714fce3b2595e0b298' |
FILE README.MD
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 65980 | 0 | b'https://drive.google.com' | ||
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 102089 | 0 | b'https://drive.google.com' | ||
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 116997 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 65980 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 102089 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 116997 | 0 | b'https://drive.google.com' |
FILE workflow/1280x720car.jpg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'03E87B2F50C159B656AFA35FC479F891' | 32 | 11331 | 0 | b'03E87B2F50C159B656AFA35FC479F891' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'03E87B2F50C159B656AFA35FC479F891' | 32 | 11455 | 0 | b'03E87B2F50C159B656AFA35FC479F891' |
FILE workflow/girl_dino_1024.png
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers3 | $c0 | False | _pusher_ () | b'214455cb0984b4430f1ca3cd1a4aa9d6b2746a63db52c7e7680080ca7fe47b70' | 64 | 903 | 0 | b'214455cb0984b4430f1ca3cd1a4aa9d6b2746a63db52c7e7680080ca7fe47b70' |
FILE workflow/3840x2160car.jpg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'2AC74C94A407AE6EF1966AECF91BD771' | 32 | 2154 | 0 | b'2AC74C94A407AE6EF1966AECF91BD771' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'1C54B6EA896C741EDA9E4D856D5A6AFC' | 32 | 2421 | 0 | b'1C54B6EA896C741EDA9E4D856D5A6AFC' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'1C54B6EA896C741EDA9E4D856D5A6AFC' | 32 | 4831 | 0 | b'1C54B6EA896C741EDA9E4D856D5A6AFC' |
FILE workflow/512x512bkgd.jpg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'00000000000000000000000000000001' | 32 | 7313 | 0 | b'00000000000000000000000000000001' |
FILE image/mask_gradient_example.jpg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|