comfy_mtb
Yara Scan Results
Generated on 2024-07-14 08:45:56
Passed Tests
Failed Tests
Issues
FILE extern/frame_interpolation/moment.gif
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBoX' | 4 | 16739387 | 0 | b'VBoX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBoX' | 4 | 16739387 | 0 | b'VBoX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBoX' | 4 | 16739387 | 0 | b'VBoX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBoX' | 4 | 16739387 | 0 | b'VBoX' |
FILE extern/frame_interpolation/README.md
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 4500 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 4500 | 0 | b'https://drive.google.com' |
FILE extern/GFPGAN/tests/data/test_eye_mouth_landmarks.pth
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
ft_zip | File type signature for basic ZIP files. | ft_zip | $pk | False | Jason Batchelor (Emerson) | 20141217 | b'PK\x03\x04' | 4 | 0 | 0 | b'PK\x03\x04' |
FILE extern/GFPGAN/inputs/whole_imgs/Blake_Lively.jpg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'3B4FA5DCFE8411E68D2FD78047BA731E' | 32 | 586 | 0 | b'3B4FA5DCFE8411E68D2FD78047BA731E' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'3B4FA5DBFE8411E68D2FD78047BA731E' | 32 | 646 | 0 | b'3B4FA5DBFE8411E68D2FD78047BA731E' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'A35BF4747CFEE611997EACFC5D106142' | 32 | 774 | 0 | b'A35BF4747CFEE611997EACFC5D106142' |
FILE extern/GFPGAN/README.md
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 9709 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 9709 | 0 | b'https://drive.google.com' |
FILE utils.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 18945 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 18945 | 0 | b'https://drive.google.com' |
FILE examples/02-film_interpolation.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'18446744073709552000' | 20 | 2724 | 0 | b'18446744073709552000' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'18446744073709552000' | 20 | 8633 | 0 | b'18446744073709552000' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'18446744073709552000' | 20 | 16429 | 0 | b'18446744073709552000' |
FILE web/extern/shodown.min.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9781 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9810 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9943 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10025 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10103 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10126 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10147 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10168 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10289 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10324 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10704 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10841 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 12978 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39219 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39241 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39263 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39286 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39307 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39430 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39497 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39956 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39978 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 40189 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 40212 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 40233 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 41345 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42628 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42784 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42911 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42935 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43200 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43270 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43375 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43504 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43561 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43807 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44523 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44540 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44805 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44823 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44840 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45592 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45631 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45663 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45683 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45791 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45818 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45878 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45901 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46172 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46403 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46424 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46533 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46735 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46813 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46839 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48259 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48288 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48313 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48408 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48432 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48622 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48825 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49115 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49170 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49207 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49229 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49454 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49508 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49762 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49784 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49805 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49826 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50115 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50183 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50219 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50281 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50358 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50654 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50933 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50954 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51094 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51285 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51841 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51864 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51883 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 52497 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 52854 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53084 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53426 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53453 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53493 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53541 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53846 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53964 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 54817 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 54985 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55506 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55524 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55545 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55564 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55583 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55653 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55671 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55693 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55714 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55734 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55757 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55907 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55971 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56382 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56422 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56463 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56829 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56992 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57015 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57116 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57266 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57289 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57539 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57602 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57820 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57850 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57995 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58160 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58405 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58496 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58576 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58653 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58756 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58848 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58969 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59085 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59188 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59286 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59395 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59491 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59718 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60071 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60252 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60439 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60662 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60723 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60812 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60844 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60884 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61577 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61745 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61924 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62119 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62207 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62314 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62421 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62443 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62467 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62491 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62694 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62729 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62920 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62941 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63118 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63390 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63416 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63540 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63561 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63799 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64518 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64550 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64770 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65180 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65277 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65400 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65621 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65800 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65984 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 66044 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 66767 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67318 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67372 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67504 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67841 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67913 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67987 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 68071 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 68153 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 68391 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 70822 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 70845 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 73613 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74607 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74627 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74711 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74741 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74770 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74793 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74839 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74876 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74915 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74950 | 0 | b'replace(' |
FILE web/note_plus.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1643 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1656 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1679 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1643 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1656 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1679 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1643 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1656 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1679 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1643 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1656 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1679 | 0 | b'vbox' |
FILE scripts/download_models.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 1705 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 1705 | 0 | b'https://drive.google.com' |
FILE __pycache__/utils.cpython-310.pyc
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
dangerous-sites | SUSP_Websites | $site_3 | False | christian-byrne () | b'https://drive.google.com' | 24 | 15339 | 0 | b'https://drive.google.com' | ||
suspicious_sites | SUSP_Websites | $site_3 | False | SECUINFRA Falcon Team () | b'https://drive.google.com' | 24 | 15339 | 0 | b'https://drive.google.com' |
FILE html/js/saveTableData.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 147 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 237 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 147 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 237 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 147 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 237 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 147 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 237 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 147 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 237 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 147 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 237 | 0 | b'identifier' |
FILE web_async/ace/mode-typescript.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' |
FILE web_async/ace/worker-css.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 98534 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 104107 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 561 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 95554 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 96393 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 105848 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 105869 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 106161 | 0 | b'onError' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 81994 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 100273 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 81994 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 100273 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 81994 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 100273 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 81994 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 100273 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 81994 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 100273 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 81994 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 100273 | 0 | b'identifier' |
FILE web_async/ace/ext-emmet.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 730 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 1352 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 1422 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3408 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5111 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5375 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5489 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 6991 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10421 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10605 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 11471 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 11633 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 14912 | 0 | b'replace(' |
FILE web_async/ace/ext-options.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' |
FILE web_async/ace/theme-crimson_editor.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 611 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 611 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 611 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 611 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 611 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 611 | 0 | b'identifier' |
FILE web_async/ace/theme-gruvbox_dark_hard.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 111 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 205 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 292 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 389 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 450 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 537 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 667 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 760 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 895 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 984 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1068 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1165 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1279 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1341 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1416 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1497 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1560 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1635 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1723 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1796 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1871 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1946 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2040 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2112 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2183 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2245 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2337 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2398 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2470 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2555 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2618 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2694 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2771 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2838 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2928 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3011 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3089 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3162 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3232 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3466 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3526 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3608 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3642 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3804 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 111 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 205 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 292 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 389 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 450 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 537 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 667 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 760 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 895 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 984 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1068 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1165 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1279 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1341 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1416 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1497 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1560 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1635 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1723 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1796 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1871 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1946 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2040 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2112 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2183 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2245 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2337 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2398 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2470 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2555 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2618 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2694 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2771 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2838 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2928 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3011 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3089 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3162 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3232 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3466 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3526 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3608 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3642 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3804 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 111 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 205 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 292 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 389 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 450 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 537 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 667 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 760 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 895 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 984 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1068 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1165 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1279 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1341 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1416 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1497 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1560 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1635 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1723 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1796 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1871 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1946 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2040 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2112 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2183 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2245 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2337 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2398 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2470 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2555 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2618 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2694 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2771 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2838 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2928 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3011 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3089 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3162 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3232 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3466 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3526 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3608 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3642 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3804 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 111 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 205 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 292 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 389 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 450 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 537 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 667 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 760 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 895 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 984 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1068 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1165 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1279 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1341 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1416 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1497 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1560 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1635 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1723 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1796 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1871 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1946 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2040 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2112 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2183 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2245 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2337 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2398 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2470 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2555 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2618 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2694 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2771 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2838 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2928 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3011 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3089 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3162 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3232 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3466 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3526 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3608 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3642 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3804 | 0 | b'vbox' |
FILE web_async/ace/mode-markdown.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 60733 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 56751 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 56760 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 56775 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 56794 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 56674 | 0 | b'onerror' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 15498 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 22894 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 67344 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 15498 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 22894 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 67344 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 15498 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 22894 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 67344 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 15498 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 22894 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 67344 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 15498 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 22894 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 67344 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 15498 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 22894 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 67344 | 0 | b'identifier' |
FILE web_async/ace/ext-language_tools.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 730 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 1352 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 1422 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3408 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5111 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5375 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5489 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 6991 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10421 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10605 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 11471 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 11633 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 14912 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 52166 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 52234 | 0 | b'replace(' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' |
FILE web_async/ace/ext-error_marker.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|
FILE web_async/ace/mode-svg.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 15716 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 23112 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 15716 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 23112 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 15716 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 23112 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 15716 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 23112 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 15716 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 23112 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 15716 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 23112 | 0 | b'identifier' |
FILE web_async/ace/ext-prompt.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9816 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10438 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10508 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 12494 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 14197 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 14461 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 14575 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 16077 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19507 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19691 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20557 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20719 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 23998 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53767 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58138 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61767 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62512 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62801 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62852 | 0 | b'replace(' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' |
FILE web_async/ace/mode-javascript.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' |
FILE web_async/ace/ext-settings_menu.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7949 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 7959 | 0 | b'vbox' |
FILE web_async/ace/snippets/json5.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|
FILE web_async/ace/snippets/typescript.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|
FILE web_async/ace/snippets/json.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|
FILE web_async/ace/worker-base.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 134 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 949 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 969 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 991 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19306 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19360 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19903 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19984 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20006 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20028 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20050 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20123 | 0 | b'replace(' |
FILE web_async/ace/worker-json.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 134 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 949 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 969 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 991 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19306 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19360 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19903 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 19984 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20006 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20028 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20050 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 20123 | 0 | b'replace(' |
FILE web_async/ace/ext-themelist.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 512 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 522 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 512 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 522 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 512 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 522 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 512 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 522 | 0 | b'vbox' |
FILE web_async/ace/theme-gruvbox.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 101 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 176 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 246 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 301 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 395 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 493 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 546 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 622 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 673 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 727 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 794 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 848 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 915 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 981 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1033 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1086 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1152 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1205 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1271 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1340 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1420 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1531 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1609 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1809 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2033 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2083 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2155 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2179 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2334 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 101 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 176 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 246 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 301 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 395 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 493 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 546 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 622 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 673 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 727 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 794 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 848 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 915 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 981 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1033 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1086 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1152 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1205 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1271 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1340 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1420 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1531 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1609 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1809 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2033 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2083 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2155 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2179 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2334 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 101 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 176 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 246 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 301 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 395 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 493 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 546 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 622 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 673 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 727 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 794 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 848 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 915 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 981 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1033 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1086 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1152 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1205 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1271 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1340 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1420 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1531 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1609 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1809 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2033 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2083 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2155 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2179 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2334 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 101 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 176 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 246 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 301 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 395 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 493 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 546 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 622 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 673 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 727 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 794 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 848 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 915 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 981 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1033 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1086 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1152 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1205 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1271 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1340 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1420 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1531 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1609 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1809 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2033 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2083 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2155 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2179 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2334 | 0 | b'vbox' |
FILE web_async/ace/ext-inline_autocomplete.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 730 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 1352 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 1422 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3408 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5111 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5375 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 5489 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 6991 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10421 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10605 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 11471 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 11633 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 14912 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64560 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64628 | 0 | b'replace(' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31106 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31257 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31507 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31528 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31598 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 31675 | 0 | b'Identifier' |
FILE web_async/ace/mode-python.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 1176 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 1176 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 1176 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 1176 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 1176 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 1176 | 0 | b'identifier' |
FILE web_async/ace/worker-javascript.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488547 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488562 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488587 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488609 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488635 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488647 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488673 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488694 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488721 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488751 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488771 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488793 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488819 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488841 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488862 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488887 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488908 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488933 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488956 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 488977 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489011 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489030 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489051 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489079 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489102 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489116 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489136 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489158 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489170 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489196 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489219 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489258 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489278 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489296 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489314 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489329 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489343 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489365 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489391 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489412 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489444 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489465 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489492 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489525 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489550 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489580 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489611 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489642 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489670 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489691 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489712 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489733 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489754 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489775 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489803 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489824 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489845 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489870 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489896 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489918 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489944 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 489976 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490001 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490021 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490047 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490067 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490107 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490126 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490144 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490166 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490194 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490220 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490245 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490270 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490297 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490312 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490331 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490353 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490375 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490394 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490409 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490428 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490444 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490457 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490474 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490492 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490520 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490536 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490555 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490575 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490593 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490606 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490628 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490654 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490667 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490684 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490696 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490714 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490728 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490748 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490768 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490791 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490820 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490849 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490884 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490919 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490952 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 490985 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491024 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491063 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491086 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491119 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491152 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491175 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491206 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491237 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491255 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491278 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491301 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491322 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491334 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491350 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491371 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491393 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491419 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491447 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491458 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491476 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491498 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491501 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491515 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491535 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491552 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491570 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491587 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491602 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491621 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491641 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491661 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491679 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491698 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491710 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491735 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491753 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491775 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491804 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491823 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491839 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491859 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491879 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491898 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491914 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491931 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491950 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491968 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 491983 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 488161 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 561 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 488139 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 496422 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 497947 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 497985 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 498428 | 0 | b'onError' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'7976931348623157e308' | 20 | 339759 | 0 | b'7976931348623157e308' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 22546 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 22734 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 22762 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 22817 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31915 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 40592 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 346895 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 360481 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361391 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361428 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361465 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361503 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 366993 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 368893 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 369631 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 369789 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 370169 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 370238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 370310 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371240 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371477 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371725 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371775 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 372408 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 372795 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 373753 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375118 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375535 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375613 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 377376 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 378396 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 380002 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 381437 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 386756 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 387108 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 387617 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 387883 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 388904 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 389000 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 389625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392469 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392491 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392510 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392776 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 397254 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 397691 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 398092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 398914 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 399373 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 400697 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 402992 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 404511 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 406310 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 406623 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 407087 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 407132 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 407387 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 407581 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 409449 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 409837 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 412783 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 413168 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 413630 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 415255 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 415637 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 416108 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 416414 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 416658 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 417041 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 417086 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 417274 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 418787 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 419047 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 419294 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 420986 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 421096 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 423323 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 424979 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 426818 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 426850 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 429959 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 429989 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 430019 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 430062 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 430107 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 430138 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 434663 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 435459 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 435625 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 446235 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 447536 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 447892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 447909 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 448007 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 448234 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 449633 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 449663 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 449837 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450859 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450908 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450941 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450989 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451029 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451087 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451131 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451185 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 452711 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 455674 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 459502 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 462640 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 465023 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 476524 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 476670 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 476818 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 484905 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 22546 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 22734 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 22762 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 22817 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31915 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 40592 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 346895 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 360481 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361391 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361428 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361465 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361503 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 366993 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 368893 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 369631 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 369789 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 370169 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 370238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 370310 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371240 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371477 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371725 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371775 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 372408 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 372795 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 373753 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375118 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375535 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375613 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 377376 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 378396 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 380002 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 381437 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 386756 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 387108 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 387617 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 387883 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 388904 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 389000 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 389625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392469 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392491 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392510 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392776 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 397254 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 397691 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 398092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 398914 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 399373 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 400697 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 402992 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 404511 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 406310 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 406623 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 407087 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 407132 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 407387 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 407581 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 409449 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 409837 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 412783 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 413168 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 413630 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 415255 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 415637 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 416108 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 416414 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 416658 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 417041 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 417086 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 417274 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 418787 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 419047 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 419294 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 420986 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 421096 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 423323 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 424979 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 426818 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 426850 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 429959 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 429989 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 430019 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 430062 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 430107 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 430138 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 434663 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 435459 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 435625 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 446235 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 447536 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 447892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 447909 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 448007 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 448234 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 449633 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 449663 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 449837 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450859 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450908 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450941 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450989 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451029 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451087 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451131 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451185 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 452711 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 455674 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 459502 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 462640 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 465023 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 476524 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 476670 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 476818 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 484905 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 22546 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 22734 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 22762 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 22817 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31915 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 40592 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 346895 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 360481 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361391 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361428 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361465 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361503 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 366993 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 368893 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 369631 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 369789 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 370169 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 370238 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 370310 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371240 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371477 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371725 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371775 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 372408 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 372795 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 373753 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375118 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375535 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375613 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 377376 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 378396 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 380002 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 381437 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 386756 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 387108 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 387617 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 387883 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 388904 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 389000 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 389625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392469 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392491 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392510 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392776 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 397254 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 397691 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 398092 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 398914 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 399373 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 400697 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 402992 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 404511 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 406310 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 406623 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 407087 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 407132 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 407387 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 407581 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 409449 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 409837 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 412783 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 413168 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 413630 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 415255 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 415637 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 416108 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 416414 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 416658 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 417041 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 417086 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 417274 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 418787 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 419047 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 419294 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 420986 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 421096 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 423323 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 424979 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 426818 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 426850 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 429959 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 429989 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 430019 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 430062 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 430107 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 430138 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 434663 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 435459 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 435625 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 446235 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 447536 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 447892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 447909 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 448007 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 448234 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 449633 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 449663 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 449837 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450859 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450908 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450941 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450989 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451029 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451087 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451131 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451185 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 452711 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 455674 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 459502 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 462640 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 465023 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 476524 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 476670 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 476818 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 484905 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 22546 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 22734 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 22762 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 22817 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 31915 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 40592 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 346895 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 360481 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361391 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361428 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361465 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 361503 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 366993 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 368893 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 369631 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 369789 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 370169 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 370238 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 370310 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371240 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371477 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371725 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 371775 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 372408 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 372795 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 373753 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375118 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375535 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375613 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 377376 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 378396 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 380002 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 381437 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 386756 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 387108 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 387617 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 387883 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 388904 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 389000 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 389625 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392469 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392491 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392510 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 392776 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 397254 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 397691 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 398092 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 398914 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 399373 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 400697 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 402992 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 404511 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 406310 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 406623 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 407087 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 407132 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 407387 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 407581 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 409449 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 409837 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 412783 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 413168 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 413630 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 415255 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 415637 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 416108 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 416414 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 416658 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 417041 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 417086 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 417274 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 418787 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 419047 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 419294 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 420986 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 421096 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 423323 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 424979 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 426818 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 426850 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 429959 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 429989 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 430019 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 430062 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 430107 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 430138 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 434663 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 435459 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 435625 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 446235 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 447536 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 447892 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 447909 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 448007 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 448234 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 449633 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 449663 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 449837 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450859 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450908 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450941 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 450989 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451029 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451087 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451131 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 451185 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 452711 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 455674 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 459502 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 462640 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 465023 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 476524 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 476670 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 476818 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 484905 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 22546 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 22734 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 22762 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 22817 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 31915 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 40592 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 346895 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 360481 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361391 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361428 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361465 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 361503 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 366993 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 368893 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 369631 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 369789 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 370169 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 370238 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 370310 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371240 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371477 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371725 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 371775 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 372408 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 372795 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 373753 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375118 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375535 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375613 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 377376 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 378396 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 380002 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 381437 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 386756 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 387108 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 387617 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 387883 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 388904 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 389000 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 389625 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392469 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392491 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392510 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 392776 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 397254 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 397691 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 398092 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 398914 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 399373 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 400697 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 402992 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 404511 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 406310 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 406623 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 407087 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 407132 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 407387 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 407581 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 409449 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 409837 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 412783 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 413168 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 413630 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 415255 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 415637 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 416108 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 416414 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 416658 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 417041 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 417086 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 417274 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 418787 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 419047 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 419294 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 420986 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 421096 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 423323 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 424979 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 426818 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 426850 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 429959 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 429989 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 430019 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 430062 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 430107 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 430138 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 434663 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 435459 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 435625 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 446235 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 447536 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 447892 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 447909 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 448007 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 448234 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 449633 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 449663 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 449837 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450859 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450908 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450941 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 450989 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451029 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451087 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451131 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 451185 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 452711 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 455674 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 459502 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 462640 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 465023 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 476524 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 476670 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 476818 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 484905 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 22546 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 22734 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 22762 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 22817 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 31915 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 40592 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 346895 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 360481 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361391 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361428 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361465 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 361503 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 366993 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 368893 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 369631 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 369789 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 370169 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 370238 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 370310 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371240 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371477 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371725 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 371775 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 372408 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 372795 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 373753 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375118 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375535 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375613 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 377376 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 378396 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 380002 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 381437 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 386756 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 387108 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 387617 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 387883 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 388904 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 389000 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 389625 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392469 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392491 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392510 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 392776 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 397254 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 397691 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 398092 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 398914 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 399373 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 400697 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 402992 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 404511 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 406310 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 406623 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 407087 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 407132 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 407387 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 407581 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 409449 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 409837 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 412783 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 413168 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 413630 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 415255 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 415637 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 416108 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 416414 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 416658 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 417041 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 417086 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 417274 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 418787 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 419047 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 419294 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 420986 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 421096 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 423323 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 424979 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 426818 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 426850 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 429959 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 429989 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 430019 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 430062 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 430107 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 430138 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 434663 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 435459 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 435625 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 446235 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 447536 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 447892 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 447909 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 448007 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 448234 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 449633 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 449663 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 449837 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450859 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450908 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450941 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 450989 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451029 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451087 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451131 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 451185 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 452711 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 455674 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 459502 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 462640 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 465023 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 476524 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 476670 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 476818 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 484905 | 0 | b'Identifier' |
FILE web_async/ace/theme-ambiance.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 2538 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 2538 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 2538 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 2538 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 2538 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 2538 | 0 | b'identifier' |
FILE web_async/ace/ace.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 61061 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 61086 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 294747 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 303502 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 303534 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 303576 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 303601 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 305668 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 347798 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 347985 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 350841 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 350898 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 351343 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 351402 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 351886 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 351942 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 352487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 352549 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 354310 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 354374 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 362859 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 363127 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 403614 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 403668 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 11702 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 11818 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 407988 | 0 | b'onerror' |
FILE web_async/ace/theme-gruvbox_light_hard.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 112 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 207 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 295 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 390 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 452 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 540 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 671 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 765 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 898 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 988 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1073 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1171 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1283 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1346 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1422 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1504 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1568 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1644 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1733 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1807 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1883 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1959 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2054 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2127 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2199 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2262 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2355 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2417 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2490 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2576 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2640 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2717 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2795 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2863 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2954 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3038 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3117 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3191 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3262 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3479 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3813 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3874 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3957 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3992 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 4155 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 112 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 207 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 295 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 390 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 452 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 540 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 671 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 765 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 898 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 988 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1073 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1171 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1283 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1346 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1422 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1504 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1568 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1644 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1733 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1807 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1883 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1959 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2054 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2127 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2199 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2262 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2355 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2417 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2490 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2576 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2640 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2717 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2795 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2863 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2954 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3038 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3117 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3191 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3262 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3479 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3813 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3874 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3957 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3992 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 4155 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 112 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 207 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 295 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 390 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 452 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 540 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 671 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 765 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 898 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 988 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1073 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1171 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1283 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1346 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1422 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1504 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1568 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1644 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1733 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1807 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1883 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 1959 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2054 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2127 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2199 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2262 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2355 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2417 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2490 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2576 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2640 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2717 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2795 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2863 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 2954 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3038 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3117 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3191 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3262 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3479 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3813 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3874 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3957 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 3992 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 4155 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 25 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 112 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 207 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 295 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 390 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 452 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 540 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 671 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 765 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 898 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 988 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1073 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1171 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1283 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1346 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1422 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1504 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1568 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1644 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1733 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1807 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1883 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 1959 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2054 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2127 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2199 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2262 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2355 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2417 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2490 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2576 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2640 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2717 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2795 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2863 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 2954 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3038 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3117 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3191 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3262 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3479 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3813 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3874 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3957 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 3992 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 4155 | 0 | b'vbox' |
FILE web_async/ace/mode-html.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 56088 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 52106 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 52115 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 52130 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 52149 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 52029 | 0 | b'onerror' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 5824 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 13220 | 0 | b'identifier' |
FILE web_async/ace/theme-sqlserver.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 375 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 375 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 375 | 0 | b'identifier' |
FILE web_async/ace/worker-html.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 22967 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 32484 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 33501 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 77042 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 77055 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 86219 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 86289 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 86388 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 94226 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 94243 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 94271 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 115811 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 123249 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 123285 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 123320 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 123414 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 123421 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 123464 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 123855 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 124874 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 561 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 193866 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 195332 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 195370 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 195813 | 0 | b'onError' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 140934 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 140958 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 146325 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 146347 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 140934 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 140958 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 146325 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 146347 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 140934 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 140958 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 146325 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 146347 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 140934 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 140958 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 146325 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 146347 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 140934 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 140958 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 146325 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 146347 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 140934 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 140958 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 146325 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 146347 | 0 | b'Identifier' |
FILE errors.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|