comfyui-mixlab-nodes
Yara Scan Results
Generated on 2024-07-14 08:33:03
Passed Tests
Failed Tests
Issues
FILE example/Text-to-Image_3.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'608ad67eea6981c4c378f8b5b4a8e04d' | 32 | 62735 | 0 | b'608ad67eea6981c4c378f8b5b4a8e04d' |
FILE example/AIPC大赛模板_4.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'7b4c2d0ea2522605969ed331bc7b5e0c' | 32 | 62223 | 0 | b'7b4c2d0ea2522605969ed331bc7b5e0c' |
FILE example/Image-to-Image_2.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'e87b8dde1301aafb9ecbaac8f957f72f' | 32 | 65216 | 0 | b'e87b8dde1301aafb9ecbaac8f957f72f' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QeMU' | 4 | 54667 | 0 | b'QeMU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QeMU' | 4 | 54667 | 0 | b'QeMU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QeMU' | 4 | 54667 | 0 | b'QeMU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QeMU' | 4 | 54667 | 0 | b'QeMU' |
FILE nodes/TextGenerateNode.py
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3381 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3398 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3792 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3812 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3832 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3852 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3870 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 3890 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 4006 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 4024 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 4042 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 4060 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 4078 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 4096 | 0 | b'replace(' |
FILE workflow/appinfo-workflow.svg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 20444 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEmU' | 4 | 665085 | 0 | b'QEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEMU' | 4 | 1972529 | 0 | b'QEMU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 20444 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEmU' | 4 | 665085 | 0 | b'QEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEMU' | 4 | 1972529 | 0 | b'QEMU' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 2394297 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 2394297 | 0 | b'vbOx' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 20444 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEmU' | 4 | 665085 | 0 | b'QEmU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEMU' | 4 | 1972529 | 0 | b'QEMU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 20444 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEmU' | 4 | 665085 | 0 | b'QEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEMU' | 4 | 1972529 | 0 | b'QEMU' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 2394297 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 2394297 | 0 | b'vbOx' |
FILE workflow/prompt_result.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'1544d6e71ad8af896e00c785ce6e71cc' | 32 | 81 | 0 | b'1544d6e71ad8af896e00c785ce6e71cc' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'1544d6e71ad8af896e00c785ce6e71cc' | 32 | 29829 | 0 | b'1544d6e71ad8af896e00c785ce6e71cc' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'1544d6e71ad8af896e00c785ce6e71cc' | 32 | 59577 | 0 | b'1544d6e71ad8af896e00c785ce6e71cc' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'e8cebffe8c6030e59873b859b7e8148e' | 32 | 89327 | 0 | b'e8cebffe8c6030e59873b859b7e8148e' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'e8cebffe8c6030e59873b859b7e8148e' | 32 | 120669 | 0 | b'e8cebffe8c6030e59873b859b7e8148e' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'e8cebffe8c6030e59873b859b7e8148e' | 32 | 152011 | 0 | b'e8cebffe8c6030e59873b859b7e8148e' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'e8cebffe8c6030e59873b859b7e8148e' | 32 | 183353 | 0 | b'e8cebffe8c6030e59873b859b7e8148e' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'89aaa03c1cad292668481d803855d0de' | 32 | 214695 | 0 | b'89aaa03c1cad292668481d803855d0de' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'89aaa03c1cad292668481d803855d0de' | 32 | 266313 | 0 | b'89aaa03c1cad292668481d803855d0de' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'89aaa03c1cad292668481d803855d0de' | 32 | 317931 | 0 | b'89aaa03c1cad292668481d803855d0de' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'89aaa03c1cad292668481d803855d0de' | 32 | 369549 | 0 | b'89aaa03c1cad292668481d803855d0de' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'135077e61ea775c30b81acf52cb997a5' | 32 | 421181 | 0 | b'135077e61ea775c30b81acf52cb997a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'0528e058e2ee81ec090657081e9c14dc' | 32 | 460547 | 0 | b'0528e058e2ee81ec090657081e9c14dc' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'0528e058e2ee81ec090657081e9c14dc' | 32 | 545653 | 0 | b'0528e058e2ee81ec090657081e9c14dc' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'135077e61ea775c30b81acf52cb997a5' | 32 | 630747 | 0 | b'135077e61ea775c30b81acf52cb997a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'8c713c814884100d57aa9cdcb70cc907' | 32 | 670107 | 0 | b'8c713c814884100d57aa9cdcb70cc907' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 689197 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 757972 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 826747 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 895522 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 964297 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 1033072 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 1101849 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'b06099bbd49136ffa8630bace57ce3a5' | 32 | 1170624 | 0 | b'b06099bbd49136ffa8630bace57ce3a5' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 705251 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 774026 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 842801 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 911576 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 980351 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 1049126 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 1117903 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 1186678 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 705251 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 774026 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 842801 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 911576 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 980351 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 1049126 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 1117903 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 1186678 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 104288 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 135630 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 166972 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 198314 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 104288 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 135630 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 166972 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 198314 | 0 | b'vbox' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 705251 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 774026 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 842801 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 911576 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 980351 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 1049126 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 1117903 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 1186678 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 705251 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 774026 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 842801 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 911576 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 980351 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 1049126 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 1117903 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 1186678 | 0 | b'qemU' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 104288 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 135630 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 166972 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 198314 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 104288 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 135630 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 166972 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 198314 | 0 | b'vbox' |
FILE web/index.html
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12146 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12995 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 62574 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 62684 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 63103 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 85350 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 85514 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 86534 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 17725 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 19183 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 55842 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 59089 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 67300 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 95604 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 107975 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 114150 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 59208 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 64984 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 92037 | 0 | b'onerror' |
FILE web/javascript/image_mixlab.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1108 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 4817 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4829 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4905 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4991 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5014 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5032 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5074 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5087 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5117 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5156 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5229 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6588 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6599 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6638 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6650 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6693 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6705 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6752 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6784 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6813 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6867 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6880 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6913 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6927 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7084 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7111 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 7172 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7191 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7241 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7316 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7336 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7363 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7424 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7595 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7627 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7860 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7906 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 8377 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 8440 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 8975 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 9148 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 9223 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 9227 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 9765 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 10054 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 10546 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 11587 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 11652 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 11680 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 11796 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 11835 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 11839 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 11880 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12092 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 12179 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12222 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12264 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12289 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12342 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12611 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12871 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12915 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 12949 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 13037 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 13050 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 13056 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 13132 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 13285 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 13808 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 13959 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 14014 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 14132 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 14172 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 14211 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 14215 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 14229 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 14306 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 14448 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 462 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 4244 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 4498 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 11545 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 18151 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 22984 | 0 | b'onload' |
FILE web/javascript/3d_mixlab.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 798 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 1460 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 1706 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 7940 | 0 | b'onload' |
FILE web/javascript/main_mixlab.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'00204211b3c71288c12ed66516a1a20a' | 32 | 60614 | 0 | b'00204211b3c71288c12ed66516a1a20a' |
FILE web/javascript/ui_mixlab.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 75 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 3843 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 5731 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 36592 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 53053 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 5814 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 32068 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 36648 | 0 | b'onerror' |
FILE web/javascript/layer_mixlab.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 2931 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 2943 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 3003 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3089 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 3112 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3130 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3172 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3185 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 3215 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3254 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3327 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4686 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4736 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4748 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4791 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4803 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4850 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4882 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4911 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5044 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5071 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5132 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5151 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5201 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5276 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5296 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5323 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5384 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5555 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5587 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5820 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 5866 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 19780 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 19948 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 20015 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 20019 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 23007 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 23113 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 23185 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 2872 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 29662 | 0 | b'onload' |
FILE web/lib/photoswipe.esm.min.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 26473 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 26496 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 27028 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27059 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 27284 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 28070 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 28346 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 28542 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 28752 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 29119 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 33610 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 33624 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 33641 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 33748 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 35891 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 42208 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 33655 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 33673 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 34050 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 35916 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 42226 | 0 | b'onerror' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 19195 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 19215 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 19195 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 19215 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 19195 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 19215 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 19195 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 19215 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 19195 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 19215 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 19195 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 19215 | 0 | b'identifier' |
FILE web/lib/filerobot-image-editor.min.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 24092 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 24127 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 24330 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 24437 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 24550 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 24582 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 172266 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 464777 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 479996 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 480090 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 517163 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 528795 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 528889 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 529381 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 529469 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 529555 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 529645 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 534868 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 534970 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 535270 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 535364 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 536011 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 536105 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 536960 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 537054 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 538036 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 538130 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 579072 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 583687 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 583781 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 586200 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 586294 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 587010 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 587104 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 588094 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 588188 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 600442 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 603213 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 603307 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 604479 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 604573 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 605457 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 605551 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 606396 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 606490 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 606932 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 607026 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 609789 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 609883 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 610465 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 610559 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 611092 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 611186 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 613226 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 613320 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 616070 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 616164 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 617251 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 617345 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 618166 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 618260 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 619081 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 619175 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 619972 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 620066 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 620897 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 620991 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 623053 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 623147 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 624809 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 624903 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 625689 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 625783 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 626748 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 626842 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 627067 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 627161 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 628001 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 628095 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 629085 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 629179 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 630324 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 630418 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 632045 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 632139 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 633442 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 633536 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 635487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 635581 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 637473 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 637567 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 638170 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 638264 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 638791 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 638885 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 639648 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 639742 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 640474 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 640568 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 641797 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 641891 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 642897 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 642991 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 645098 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 645192 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 647142 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 647236 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 648697 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 648791 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 649447 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 649541 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 650660 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 650754 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 651463 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 651557 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 651834 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 651928 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 652916 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 653010 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 653912 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 654006 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 654575 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 654669 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 655243 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 655337 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 656020 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 656114 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 656801 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 656895 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 657680 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 657773 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 658253 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 658347 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 660250 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 660344 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 661033 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 661127 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 663315 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 663409 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 664487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 664581 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 666050 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 666144 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 667549 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 667643 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 668699 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 668793 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 669664 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 669758 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 671057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 671151 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 671728 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 671822 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 672397 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 672491 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 673892 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 673986 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 675340 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 675434 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 676581 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 676675 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 678118 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 678212 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 680408 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 680502 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 681775 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 681869 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 682679 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 682773 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 683383 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 683477 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 684038 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 684132 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 686207 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 686301 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 688372 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 688466 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 691207 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 691301 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 752957 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 769826 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 772723 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 774379 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 795229 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 871101 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 871623 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 889053 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 902556 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 218823 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 317129 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 486495 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 807510 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 811877 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 812301 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 845320 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 900298 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 28215 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 28398 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 317179 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 486696 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 807568 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 811931 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 812332 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 845346 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 900800 | 0 | b'onerror' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 79529 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 127892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 138602 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 138625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 139336 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 139359 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 186818 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 223276 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 274625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 274803 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 400845 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 445470 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 524919 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 79529 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 127892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 138602 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 138625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 139336 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 139359 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 186818 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 223276 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 274625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 274803 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 400845 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 445470 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 524919 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 79529 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 127892 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 138602 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 138625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 139336 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 139359 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 186818 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 223276 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 274625 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 274803 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 400845 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 445470 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 524919 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $vmware_mac_4c | False | () | b'001C14' | 6 | 675867 | 0 | b'001C14' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 24735 | 0 | b'MSApp.exe' | ||
anti_av | Antivirus_strings | $a278 | False | Jerome Athias () | b'MSApp.exe' | 9 | 24783 | 0 | b'MSApp.exe' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 79529 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 127892 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 138602 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 138625 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 139336 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 139359 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 186818 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 223276 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 274625 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 274803 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 400845 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 445470 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 524919 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 79529 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 127892 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 138602 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 138625 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 139336 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 139359 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 186818 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 223276 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 274625 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 274803 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 400845 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 445470 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 524919 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 79529 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 127892 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 138602 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 138625 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 139336 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 139359 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 186818 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 223276 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 274625 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 274803 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 400845 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 445470 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 524919 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $vmware_mac_4c | False | () | b'001C14' | 6 | 675867 | 0 | b'001C14' | ||
anti_sandboxing | vmdetect | $vmware_mac_4c | False | nex () | b'001C14' | 6 | 675867 | 0 | b'001C14' |
FILE web/lib/juxtapose.min.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'd90fc2d1f4acc584e08b8eaea5bf4d6c' | 32 | 336 | 0 | b'd90fc2d1f4acc584e08b8eaea5bf4d6c' |
FILE web/lib/miniPaint-4.14.2/dist/bundle.ejs
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
crypto_signatures | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 945592 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
html_wasm | SUSP_HTML_B64_WASM_Blob | $m64 | False | delivr.to () | b'AGFzbQ' | 6 | 928247 | 0 | b'AGFzbQ' | ||
html_wasm | SUSP_HTML_B64_WASM_Blob | $m64 | False | delivr.to () | b'AGFzbQ' | 6 | 933853 | 0 | b'AGFzbQ' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 41021 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 41057 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 41099 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 41149 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 70404 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 70427 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 70455 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 82540 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 142575 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 142674 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 143445 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 143672 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 143795 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 144403 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 144618 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 144740 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 145059 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 661314 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 672438 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 672452 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 672560 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 672790 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 673231 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 673245 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 673367 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 673532 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 687011 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 698135 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 698149 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 698257 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 698487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 698928 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 698942 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 699064 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 699229 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 703598 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 704051 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 706893 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 706981 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707061 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707143 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707233 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707313 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707405 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707483 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707563 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707643 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707721 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 707957 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 708035 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 708113 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 708197 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 708287 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 708379 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 708467 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 711134 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 711642 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 711935 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 713422 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 728095 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 728548 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731390 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731478 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731558 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731640 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731730 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731810 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731902 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 731980 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732060 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732140 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732218 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732454 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732532 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732610 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732694 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732784 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732876 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 732964 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 735631 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 736139 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 736432 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 737919 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 746919 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 754199 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1002455 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1002478 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1002489 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1002526 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1022293 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1022316 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1022327 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1022341 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1045277 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1045300 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1045356 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1062077 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1062100 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1076770 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1076793 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1076804 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1076829 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1095743 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1095766 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1095777 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1095805 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1114536 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1114559 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1114570 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1114597 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1134522 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1134545 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1134556 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1134569 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1154793 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1154816 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1154827 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1154844 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1173808 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1173831 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1173842 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1173871 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1192161 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1192184 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1192195 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1192229 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1210383 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1210406 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1210417 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1210445 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1232193 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1232216 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1232227 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1232288 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1253324 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1253347 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1253358 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1253370 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1268143 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1268166 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1283091 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1283114 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1283125 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1283147 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1332044 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 229156 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 229910 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 230485 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 237000 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 237037 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 317892 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 321125 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 321472 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 322608 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 323653 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 325174 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 325307 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 352890 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 353204 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 353233 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 358678 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 809762 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 809883 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 810034 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 810304 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 816485 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 818544 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 919224 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 919566 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 941549 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 962909 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 963167 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 963301 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 1332552 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 1332712 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 1368826 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 321513 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 325543 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 816524 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 919233 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 919581 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 940084 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 941711 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 962939 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1333028 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1363236 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1363512 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1364715 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1365246 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1365722 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1366566 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 1367024 | 0 | b'onerror' | ||
findcrypt | BASE64_table | $c0 | False | _pusher_ () | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | 64 | 945592 | 0 | b'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426275 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426295 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426330 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426792 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426812 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426889 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427176 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427196 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427273 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427987 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 959051 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 959326 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360068 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360120 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360135 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360151 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360166 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 361943 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 361956 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362011 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362082 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362128 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362167 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362272 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362502 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426275 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426295 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426330 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426792 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426812 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426889 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427176 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427196 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427273 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427987 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 959051 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 959326 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360068 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360120 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360135 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360151 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360166 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 361943 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 361956 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362011 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362082 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362128 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362167 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362272 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362502 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426275 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426295 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426330 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426792 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426812 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426889 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427176 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427196 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427273 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427987 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 959051 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 959326 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426275 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426295 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426330 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426792 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426812 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 426889 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427176 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427196 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427273 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 427987 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 959051 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 959326 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360068 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360120 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360135 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360151 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 360166 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 361943 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 361956 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362011 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362082 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362128 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362167 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362272 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 362502 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426275 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426295 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426330 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426792 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426812 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 426889 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427176 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427196 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427273 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 427987 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 959051 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 959326 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360068 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360120 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360135 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360151 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 360166 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 361943 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 361956 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362011 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362082 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362128 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362167 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362272 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 362502 | 0 | b'vbox' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426275 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426295 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426330 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426792 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426812 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 426889 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427176 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427196 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427273 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 427987 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 959051 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 959326 | 0 | b'identifier' |
FILE web/lib/model-viewer.min.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
html_wasm | SUSP_HTML_B64_WASM_Blob | $m64 | False | delivr.to () | b'AGFzbQ' | 6 | 624757 | 0 | b'AGFzbQ' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 537488 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 538120 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 563576 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 564431 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 564514 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 565429 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 565778 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 565812 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 571056 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 572513 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 572547 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 572642 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 573374 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'ONLoad' | 6 | 490160 | 0 | b'ONLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 492578 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 492798 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 492808 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 494202 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 494257 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 495686 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 495696 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 591730 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 592942 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 684838 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 693452 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 694049 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 694167 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 697993 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onload' | 6 | 788473 | 0 | b'onload' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 427875 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 432634 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 492610 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 492857 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 492868 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 494224 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 494279 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 495843 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onError' | 7 | 495854 | 0 | b'onError' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 591739 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 592951 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 684849 | 0 | b'onerror' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onerror | False | delivr.to () | b'onerror' | 7 | 788493 | 0 | b'onerror' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 61 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 573 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 757 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 529673 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 530521 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 536326 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 544655 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 545498 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 551303 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 667399 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 61 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 573 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 757 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 529673 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 530521 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 536326 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 544655 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 545498 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 551303 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 667399 | 0 | b'identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 61 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 573 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 757 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 529673 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 530521 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 536326 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 544655 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 545498 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 551303 | 0 | b'Identifier' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 667399 | 0 | b'identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 61 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 573 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 757 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 529673 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 530521 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 536326 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 544655 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 545498 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'Identifier' | 10 | 551303 | 0 | b'Identifier' | ||
anti_sandboxing | Qemu_Detection | $dev2 | False | () | b'identifier' | 10 | 667399 | 0 | b'identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 61 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 573 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 757 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 529673 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 530521 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 536326 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 544655 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 545498 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'Identifier' | 10 | 551303 | 0 | b'Identifier' | ||
anti_sandboxing | VBox_Detection | $dev2 | False | () | b'identifier' | 10 | 667399 | 0 | b'identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 61 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 573 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 757 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 529673 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 530521 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 536326 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 544655 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 545498 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'Identifier' | 10 | 551303 | 0 | b'Identifier' | ||
anti_sandboxing | VMWare_Detection | $dev2 | False | () | b'identifier' | 10 | 667399 | 0 | b'identifier' |
FILE web/lib/showdown.min.js
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9781 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9810 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 9943 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10025 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10103 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10126 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10147 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10168 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10289 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10324 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10704 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 10841 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 12978 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39219 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39241 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39263 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39286 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39307 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39430 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39497 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39956 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 39978 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 40189 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 40212 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 40233 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 41345 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42628 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42784 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42911 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 42935 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43200 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43270 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43375 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43504 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43561 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 43807 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44523 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44540 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44805 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44823 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 44840 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45592 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45631 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45663 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45683 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45791 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45818 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45878 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 45901 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46172 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46403 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46424 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46533 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46735 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46813 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 46839 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48259 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48288 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48313 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48408 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48432 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48622 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 48825 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49115 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49170 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49207 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49229 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49454 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49508 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49762 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49784 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49805 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 49826 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50115 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50183 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50219 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50281 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50358 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50654 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50933 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 50954 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51094 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51285 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51841 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51864 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 51883 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 52497 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 52854 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53084 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53426 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53453 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53493 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53541 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53846 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 53964 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 54817 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 54985 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55506 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55524 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55545 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55564 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55583 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55653 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55671 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55693 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55714 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55734 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55757 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55907 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 55971 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56382 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56422 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56463 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56829 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 56992 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57015 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57116 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57266 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57289 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57539 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57602 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57820 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57850 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 57995 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58160 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58405 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58496 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58576 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58653 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58756 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58848 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 58969 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59085 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59188 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59286 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59395 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59491 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 59718 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60071 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60252 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60439 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60662 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60723 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60812 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60844 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 60884 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61577 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61745 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 61924 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62119 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62207 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62314 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62421 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62443 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62467 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62491 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62694 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62729 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62920 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 62941 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63118 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63390 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63416 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63540 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63561 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 63799 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64518 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64550 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 64770 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65180 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65277 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65400 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65621 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65800 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 65984 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 66044 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 66767 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67318 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67372 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67504 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67841 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67913 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 67987 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 68071 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 68153 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 68391 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 70822 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 70845 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 73613 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74607 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74627 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74711 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74741 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74770 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74793 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74839 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74876 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74915 | 0 | b'replace(' | ||
powershell_obfuscation | OBFUS_PowerShell_Common_Replace | $replace | False | SECUINFRA Falcon Team () | b'replace(' | 8 | 74950 | 0 | b'replace(' |
FILE data/extension-node-map.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 287745 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 376696 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 43321 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 64104 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 107465 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 220054 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 386012 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 423147 | 0 | b'onLoad' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'7361b8eb966f29c8238fd323409efb68' | 32 | 40 | 0 | b'7361b8eb966f29c8238fd323409efb68' |
FILE assets/poster-workflow.svg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QeMu' | 4 | 1929655 | 0 | b'QeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEMU' | 4 | 3011185 | 0 | b'QEMU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEmU' | 4 | 3282148 | 0 | b'QEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 3327136 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QeMu' | 4 | 3753352 | 0 | b'QeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QemU' | 4 | 3919364 | 0 | b'QemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 5636175 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 6238527 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 6429742 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 7666568 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 9773173 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qeMu' | 4 | 9791055 | 0 | b'qeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QeMu' | 4 | 1929655 | 0 | b'QeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEMU' | 4 | 3011185 | 0 | b'QEMU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEmU' | 4 | 3282148 | 0 | b'QEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 3327136 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QeMu' | 4 | 3753352 | 0 | b'QeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QemU' | 4 | 3919364 | 0 | b'QemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 5636175 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 6238527 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 6429742 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 7666568 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 9773173 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qeMu' | 4 | 9791055 | 0 | b'qeMu' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 450245 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VbOx' | 4 | 1923682 | 0 | b'VbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBoX' | 4 | 3335882 | 0 | b'VBoX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 3827757 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 5449846 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 5933020 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 6477154 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 8527638 | 0 | b'VBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vBox' | 4 | 8996826 | 0 | b'vBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 9351525 | 0 | b'VBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBOX' | 4 | 9368390 | 0 | b'VBOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VbOX' | 4 | 9475641 | 0 | b'VbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 10007094 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 450245 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VbOx' | 4 | 1923682 | 0 | b'VbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBoX' | 4 | 3335882 | 0 | b'VBoX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 3827757 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 5449846 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 5933020 | 0 | b'vbox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 6477154 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 8527638 | 0 | b'VBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vBox' | 4 | 8996826 | 0 | b'vBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 9351525 | 0 | b'VBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBOX' | 4 | 9368390 | 0 | b'VBOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VbOX' | 4 | 9475641 | 0 | b'VbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 10007094 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $vmware | False | () | b'VMXh' | 4 | 7717397 | 0 | b'VMXh' | ||
Detect_Sandbox_Unprotect | VMWare_Detection | $vmware1 | False | () | b'VMXh' | 4 | 7717397 | 0 | b'VMXh' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QeMu' | 4 | 1929655 | 0 | b'QeMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEMU' | 4 | 3011185 | 0 | b'QEMU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEmU' | 4 | 3282148 | 0 | b'QEmU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 3327136 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QeMu' | 4 | 3753352 | 0 | b'QeMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QemU' | 4 | 3919364 | 0 | b'QemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 5636175 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 6238527 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 6429742 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 7666568 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 9773173 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qeMu' | 4 | 9791055 | 0 | b'qeMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QeMu' | 4 | 1929655 | 0 | b'QeMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEMU' | 4 | 3011185 | 0 | b'QEMU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEmU' | 4 | 3282148 | 0 | b'QEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 3327136 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QeMu' | 4 | 3753352 | 0 | b'QeMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QemU' | 4 | 3919364 | 0 | b'QemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 5636175 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 6238527 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 6429742 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 7666568 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 9773173 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qeMu' | 4 | 9791055 | 0 | b'qeMu' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 450245 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VbOx' | 4 | 1923682 | 0 | b'VbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBoX' | 4 | 3335882 | 0 | b'VBoX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 3827757 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 5449846 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbox' | 4 | 5933020 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 6477154 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 8527638 | 0 | b'VBox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vBox' | 4 | 8996826 | 0 | b'vBox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 9351525 | 0 | b'VBox' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBOX' | 4 | 9368390 | 0 | b'VBOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VbOX' | 4 | 9475641 | 0 | b'VbOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 10007094 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 450245 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VbOx' | 4 | 1923682 | 0 | b'VbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBoX' | 4 | 3335882 | 0 | b'VBoX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 3827757 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 5449846 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbox' | 4 | 5933020 | 0 | b'vbox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 6477154 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 8527638 | 0 | b'VBox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vBox' | 4 | 8996826 | 0 | b'vBox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 9351525 | 0 | b'VBox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBOX' | 4 | 9368390 | 0 | b'VBOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VbOX' | 4 | 9475641 | 0 | b'VbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 10007094 | 0 | b'vbOx' | ||
anti_sandboxing | VMWare_Detection | $vmware | False | () | b'VMXh' | 4 | 7717397 | 0 | b'VMXh' | ||
anti_sandboxing | VMWare_Detection | $vmware1 | False | () | b'VMXh' | 4 | 7717397 | 0 | b'VMXh' | ||
anti_sandboxing | vmdetect | $vmware | False | nex () | b'VMXh' | 4 | 7717397 | 0 | b'VMXh' | ||
anti_sandboxing | vmdetect | $vmware1 | False | nex () | b'VMXh' | 4 | 7717397 | 0 | b'VMXh' |
FILE assets/gpt-workflow.svg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEMU' | 4 | 772994 | 0 | b'QEMU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 993343 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEMU' | 4 | 772994 | 0 | b'QEMU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 993343 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vBoX' | 4 | 370636 | 0 | b'vBoX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 696658 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 858829 | 0 | b'VBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vBoX' | 4 | 370636 | 0 | b'vBoX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 696658 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 858829 | 0 | b'VBox' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEMU' | 4 | 772994 | 0 | b'QEMU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 993343 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEMU' | 4 | 772994 | 0 | b'QEMU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 993343 | 0 | b'qEMu' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vBoX' | 4 | 370636 | 0 | b'vBoX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 696658 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 858829 | 0 | b'VBox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vBoX' | 4 | 370636 | 0 | b'vBoX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 696658 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 858829 | 0 | b'VBox' |
FILE assets/NeilArmstrong.glb
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'068C5C38A97311E99B3FF96EE56FFE95' | 32 | 5166498 | 0 | b'068C5C38A97311E99B3FF96EE56FFE95' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'068C5C39A97311E99B3FF96EE56FFE95' | 32 | 5166558 | 0 | b'068C5C39A97311E99B3FF96EE56FFE95' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'068C5C36A97311E99B3FF96EE56FFE95' | 32 | 5166638 | 0 | b'068C5C36A97311E99B3FF96EE56FFE95' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'068C5C37A97311E99B3FF96EE56FFE95' | 32 | 5166698 | 0 | b'068C5C37A97311E99B3FF96EE56FFE95' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'017D6566A97311E9BB6792A82BFE0070' | 32 | 6764614 | 0 | b'017D6566A97311E9BB6792A82BFE0070' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'017D6567A97311E9BB6792A82BFE0070' | 32 | 6764674 | 0 | b'017D6567A97311E9BB6792A82BFE0070' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'017D6564A97311E9BB6792A82BFE0070' | 32 | 6764754 | 0 | b'017D6564A97311E9BB6792A82BFE0070' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'017D6565A97311E9BB6792A82BFE0070' | 32 | 6764814 | 0 | b'017D6565A97311E9BB6792A82BFE0070' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'E8CF0241A97211E99840E2848D064A87' | 32 | 7401318 | 0 | b'E8CF0241A97211E99840E2848D064A87' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'E8CF0242A97211E99840E2848D064A87' | 32 | 7401378 | 0 | b'E8CF0242A97211E99840E2848D064A87' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'E8CF023FA97211E99840E2848D064A87' | 32 | 7401458 | 0 | b'E8CF023FA97211E99840E2848D064A87' | ||
findcrypt | Big_Numbers1 | $c0 | False | _pusher_ () | b'E8CF0240A97211E99840E2848D064A87' | 32 | 7401518 | 0 | b'E8CF0240A97211E99840E2848D064A87' |
FILE assets/fonts/王汉宗颜楷体繁.ttf
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
userdb_jclausing | _TrueType_Font_file_ | $1 | False | () | b'\x00\x01\x00\x00\x00\x0f\x00\x80\x00\x03\x00pOS/2' | 16 | 0 | 0 | b'\x00\x01\x00\x00\x00\x0f\x00\x80\x00\x03\x00pOS/2' |
FILE assets/fonts/庞门正道粗书体6.0.ttf
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'46326547654646465467' | 20 | 126300 | 0 | b'46326547654646465467' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'76764646547654767654' | 20 | 507171 | 0 | b'76764646547654767654' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'46464646465467654676' | 20 | 576480 | 0 | b'46464646465467654676' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'76465463276767676764' | 20 | 5419528 | 0 | b'76465463276767676764' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'64246467467656767654' | 20 | 6912451 | 0 | b'64246467467656767654' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'65424643267467676426' | 20 | 10433749 | 0 | b'65424643267467676426' | ||
findcrypt | Big_Numbers0 | $c0 | False | _pusher_ () | b'46765465254676767467' | 20 | 10855276 | 0 | b'46765465254676767467' |
FILE assets/all-workflow.svg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 414335 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 430599 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 1140282 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 414335 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 430599 | 0 | b'qemU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 1140282 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vBOx' | 4 | 1052880 | 0 | b'vBOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 1084726 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VbOx' | 4 | 1250510 | 0 | b'VbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vBOx' | 4 | 1327333 | 0 | b'vBOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 2530418 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 3287737 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vBOx' | 4 | 1052880 | 0 | b'vBOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 1084726 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VbOx' | 4 | 1250510 | 0 | b'VbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vBOx' | 4 | 1327333 | 0 | b'vBOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 2530418 | 0 | b'vbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 3287737 | 0 | b'vbOX' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 414335 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qemU' | 4 | 430599 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 1140282 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 414335 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qemU' | 4 | 430599 | 0 | b'qemU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 1140282 | 0 | b'qEmu' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vBOx' | 4 | 1052880 | 0 | b'vBOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 1084726 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VbOx' | 4 | 1250510 | 0 | b'VbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vBOx' | 4 | 1327333 | 0 | b'vBOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 2530418 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOX' | 4 | 3287737 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vBOx' | 4 | 1052880 | 0 | b'vBOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 1084726 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VbOx' | 4 | 1250510 | 0 | b'VbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vBOx' | 4 | 1327333 | 0 | b'vBOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 2530418 | 0 | b'vbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOX' | 4 | 3287737 | 0 | b'vbOX' |
FILE assets/layers-workflow.svg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 77 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 14369 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 45298 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 56075 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 57487 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 60107 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 61519 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 118390 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 123848 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 140218 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 148786 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 168230 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 173060 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 174683 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 202000 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 210700 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 227416 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 240165 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 277591 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 279776 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 296568 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 311390 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 313822 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 367609 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 379746 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 405544 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 412474 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 414022 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 415267 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 423587 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 426489 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 530390 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 588028 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 592136 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 602166 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 628556 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 639572 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 641212 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 652233 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 685225 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 761543 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 828026 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 831751 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 936806 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 962277 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 977267 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1000273 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 1027100 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 1027960 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1028785 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 1050103 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 1063823 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 1090588 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1163280 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 1221862 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 1274103 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 1316735 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 1360900 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 1378059 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 1392896 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 1429952 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 1454736 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1464168 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1495568 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 1516712 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 1556506 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 1559284 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 1560670 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1596882 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1630960 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 1636038 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 1673780 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1685548 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1784596 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1816984 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 1820420 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 1820971 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1863014 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1931796 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 1944171 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 1948392 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 1977200 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 2012629 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2022244 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2029624 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2067480 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 2071339 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2093218 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 2094432 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 2290858 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 2310856 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2354323 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 2429693 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2441357 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 2452790 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 2467936 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2527214 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 2549645 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 2559052 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2560280 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2564666 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 2565878 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 2586419 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2605299 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 2617281 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 2678576 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 2693866 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 2722619 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 2753894 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 2855876 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 2885511 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 2904030 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 2919651 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 2936943 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 2963229 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 3004948 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3005585 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3062149 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 3081263 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 3088806 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 3109429 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 3116027 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 3126364 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 3164610 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 3176055 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 3211848 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 3223951 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 3234646 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 3256517 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 3275929 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 3325102 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 3363215 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 3369565 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 3378151 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 3395086 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3411361 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 3452479 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 3456376 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 3533786 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 3634522 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 3655564 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 3690862 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 3769932 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 3848990 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 3857175 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 3923519 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 4158444 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4178442 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 4221909 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 4292692 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 4319009 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4354164 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 4369315 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 4399112 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 4448100 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 4504723 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4511122 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 4560294 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 4601090 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 4605243 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 4622243 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 4664254 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 4671296 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 4701625 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 4720589 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4736272 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 4740312 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 4743777 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 4759197 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4794574 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 4797933 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 4805790 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 4851221 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4927540 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 4996590 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5018438 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 5032410 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 5037947 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5050565 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5061289 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 5089364 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5103693 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 5109045 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5110136 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 5199149 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5205836 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5213864 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5252388 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5253651 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5273044 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 5349984 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 5358772 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 5366295 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5399872 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5400855 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5512745 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5532577 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 5544999 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5568525 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 5571404 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5610567 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5618917 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 5619803 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 5623775 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 5703711 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5724067 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 5724111 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 5778134 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 5782557 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5805151 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 5845358 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 5999976 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 6033154 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 6158311 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 6264949 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 6268220 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6268611 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 6270602 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6283489 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 6339101 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 6366219 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 6374844 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 6452146 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 6467878 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 6493357 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 6495775 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 6496422 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 6512949 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 6534592 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 6544440 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 6557593 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 6566855 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 6584590 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6589331 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6604002 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 6605166 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 6626473 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 6757388 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 6825163 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVG' | 3 | 6909007 | 0 | b'sVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 6980916 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 7031250 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 7069264 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'Svg' | 3 | 7081267 | 0 | b'Svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 7119133 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 7137415 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svG' | 3 | 7145032 | 0 | b'svG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'sVg' | 3 | 7161741 | 0 | b'sVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVg' | 3 | 7165987 | 0 | b'SVg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SvG' | 3 | 7208933 | 0 | b'SvG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'SVG' | 3 | 7309407 | 0 | b'SVG' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $svg | False | delivr.to () | b'svg' | 3 | 7459449 | 0 | b'svg' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 7451350 | 0 | b'onLoad' | ||
svg_onload_onerror | SUSP_SVG_Onload_Onerror_Jul23 | $onload | False | delivr.to () | b'onLoad' | 6 | 7451586 | 0 | b'onLoad' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 825351 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 1095473 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEMu' | 4 | 3503389 | 0 | b'QEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 3698610 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 6775691 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qeMu' | 4 | 7101861 | 0 | b'qeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 7286342 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 825351 | 0 | b'qEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 1095473 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEMu' | 4 | 3503389 | 0 | b'QEMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 3698610 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 6775691 | 0 | b'qEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qeMu' | 4 | 7101861 | 0 | b'qeMu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 7286342 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VbOX' | 4 | 1829327 | 0 | b'VbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 2077342 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 3465551 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vBOx' | 4 | 3558820 | 0 | b'vBOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VbOx' | 4 | 4985864 | 0 | b'VbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 5895906 | 0 | b'VBox' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VbOX' | 4 | 1829327 | 0 | b'VbOX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 2077342 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 3465551 | 0 | b'vbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vBOx' | 4 | 3558820 | 0 | b'vBOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VbOx' | 4 | 4985864 | 0 | b'VbOx' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 5895906 | 0 | b'VBox' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEMu' | 4 | 825351 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 1095473 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEMu' | 4 | 3503389 | 0 | b'QEMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 3698610 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmu' | 4 | 6775691 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qeMu' | 4 | 7101861 | 0 | b'qeMu' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 7286342 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEMu' | 4 | 825351 | 0 | b'qEMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 1095473 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEMu' | 4 | 3503389 | 0 | b'QEMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 3698610 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmu' | 4 | 6775691 | 0 | b'qEmu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qeMu' | 4 | 7101861 | 0 | b'qeMu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 7286342 | 0 | b'qEmU' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VbOX' | 4 | 1829327 | 0 | b'VbOX' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 2077342 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vbOx' | 4 | 3465551 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vBOx' | 4 | 3558820 | 0 | b'vBOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VbOx' | 4 | 4985864 | 0 | b'VbOx' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'VBox' | 4 | 5895906 | 0 | b'VBox' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VbOX' | 4 | 1829327 | 0 | b'VbOX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 2077342 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vbOx' | 4 | 3465551 | 0 | b'vbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vBOx' | 4 | 3558820 | 0 | b'vBOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VbOx' | 4 | 4985864 | 0 | b'VbOx' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'VBox' | 4 | 5895906 | 0 | b'VBox' |
FILE assets/Image-to-3D_1.json
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 418907 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 847451 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 1275217 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 418907 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 847451 | 0 | b'qEmU' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 1275217 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 418907 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 847451 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'qEmU' | 4 | 1275217 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 418907 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 847451 | 0 | b'qEmU' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'qEmU' | 4 | 1275217 | 0 | b'qEmU' |
FILE assets/ChinesePrompt_workflow.svg
Test Name | Test Description | Match Rule | Match String | Is XOR | Author | Test Creation Date | Matched data | Length | Offset | XOR key | Plaintext |
---|---|---|---|---|---|---|---|---|---|---|---|
Detect_Sandbox_Unprotect | Qemu_Detection | $desc3 | False | () | b'QEmu' | 4 | 2473346 | 0 | b'QEmu' | ||
Detect_Sandbox_Unprotect | Qemu_Detection | $dev3 | False | () | b'QEmu' | 4 | 2473346 | 0 | b'QEmu' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $data1 | False | () | b'vboX' | 4 | 779478 | 0 | b'vboX' | ||
Detect_Sandbox_Unprotect | VBox_Detection | $dev3 | False | () | b'vboX' | 4 | 779478 | 0 | b'vboX' | ||
anti_sandboxing | Qemu_Detection | $desc3 | False | () | b'QEmu' | 4 | 2473346 | 0 | b'QEmu' | ||
anti_sandboxing | Qemu_Detection | $dev3 | False | () | b'QEmu' | 4 | 2473346 | 0 | b'QEmu' | ||
anti_sandboxing | VBox_Detection | $data1 | False | () | b'vboX' | 4 | 779478 | 0 | b'vboX' | ||
anti_sandboxing | VBox_Detection | $dev3 | False | () | b'vboX' | 4 | 779478 | 0 | b'vboX' |