Automated Malware Analysis Report For

Total Page:16

File Type:pdf, Size:1020Kb

Automated Malware Analysis Report For ID: 200939 Cookbook: browseurl.jbs Time: 17:25:00 Date: 14/01/2020 Version: 28.0.0 Lapis Lazuli Table of Contents Table of Contents 2 Analysis Report https://docs.zoho.com/file/io2ap787b5d0ad13c4bdd8a70ad6abae58caf 4 Overview 4 General Information 4 Detection 5 Confidence 5 Classification 5 Analysis Advice 6 Mitre Att&ck Matrix 6 Signature Overview 7 Phishing: 7 Networking: 7 System Summary: 7 Persistence and Installation Behavior: 7 Malware Configuration 8 Behavior Graph 8 Simulations 8 Behavior and APIs 8 Antivirus, Machine Learning and Genetic Malware Detection 8 Initial Sample 8 Dropped Files 8 Unpacked PE Files 8 Domains 9 URLs 9 Yara Overview 9 Initial Sample 9 PCAP (Network Traffic) 9 Dropped Files 9 Memory Dumps 9 Unpacked PEs 9 Sigma Overview 10 Joe Sandbox View / Context 10 IPs 10 Domains 10 ASN 10 JA3 Fingerprints 10 Dropped Files 10 Screenshots 10 Thumbnails 10 Startup 11 Created / dropped Files 11 Domains and IPs 24 Contacted Domains 24 URLs from Memory and Binaries 24 Contacted IPs 27 Public 27 Static File Info 27 No static file info 27 Network Behavior 28 Network Port Distribution 28 TCP Packets 28 UDP Packets 29 DNS Queries 31 DNS Answers 31 HTTPS Packets 33 Copyright Joe Security LLC 2020 Page 2 of 43 Code Manipulations 41 Statistics 41 Behavior 41 System Behavior 41 Analysis Process: iexplore.exe PID: 5224 Parent PID: 700 41 General 41 File Activities 42 Registry Activities 42 Analysis Process: iexplore.exe PID: 5272 Parent PID: 5224 42 General 42 File Activities 42 Registry Activities 42 Analysis Process: iexplore.exe PID: 6048 Parent PID: 5224 42 General 42 File Activities 43 Disassembly 43 Copyright Joe Security LLC 2020 Page 3 of 43 Analysis Report https://docs.zoho.com/file/io2ap787b5d0ad13c4bdd 8a70ad6abae58caf Overview General Information Joe Sandbox Version: 28.0.0 Lapis Lazuli Analysis ID: 200939 Start date: 14.01.2020 Start time: 17:25:00 Joe Sandbox Product: CloudBasic Overall analysis duration: 0h 5m 58s Hypervisor based Inspection enabled: false Report type: light Cookbook file name: browseurl.jbs Sample URL: https://docs.zoho.com/file/io2ap787b5d0ad13c4bdd8a7 0ad6abae58caf Analysis system description: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113 Number of analysed new started processes analysed: 9 Number of new started drivers analysed: 0 Number of existing processes analysed: 0 Number of existing drivers analysed: 0 Number of injected processes analysed: 0 Technologies: EGA enabled Analysis stop reason: Timeout Detection: SUS Classification: sus22.phis.win@5/45@13/9 Cookbook Comments: Adjust boot time Enable AMSI Browsing link: https://help.zo ho.com/portal/community/topic/writer-ends-support- for-internet-explorer-versions-ie8-ie9-and-ie10 Browsing link: https://writer. zoho.com/writer/open/io2ap787b 5d0ad13c4bdd8a70ad6abae58caf#page=1 Browsing link: https://writer. zoho.com/writer/open/io2ap787b 5d0ad13c4bdd8a70ad6abae58caf#p age=1&zoom=auto,-73,792 Browsing link: https://split.to/uqMH3zd Copyright Joe Security LLC 2020 Page 4 of 43 Warnings: Show All Exclude process from analysis (whitelisted): ielowutil.exe, HxTsr.exe, RuntimeBroker.exe, conhost.exe, backgroundTaskHost.exe, CompatTelRunner.exe TCP Packets have been reduced to 100 Excluded IPs from analysis (whitelisted): 92.122.253.130, 104.103.90.39, 152.199.19.161, 23.39.94.151, 40.90.22.191, 40.90.22.189, 40.90.22.190, 204.79.197.200, 13.107.21.200, 52.109.124.23 Excluded domains from analysis (whitelisted): storeedgefd.dsx.mp.microsoft.com.edgekey.net.glo balredir.akadns.net, www.bing.com, prod- w.nexus.live.com.akadns.net, lgin.msa.trafficmanager.net, ie9comview.vo.msecnd.net, dual-a-0001.a- msedge.net, tile-service.weather.microsoft.com, storeedgefd.dsx.mp.microsoft.com.edgekey.net, e15275.g.akamaiedge.net, storeedgefd.xbetservices.akadns.net, login.msa.msidentity.com, e11290.dspg.akamaiedge.net, iecvlist.microsoft.com, go.microsoft.com, a-0001.a- afdentry.net.trafficmanager.net, wildcard.weather.microsoft.com.edgekey.net, login.live.com, go.microsoft.com.edgekey.net, nexus.officeapps.live.com, e16646.dscg.akamaiedge.net, storeedgefd.dsx.mp.microsoft.com, cs9.wpc.v0cdn.net Report size getting too big, too many NtDeviceIoControlFile calls found. Detection Strategy Score Range Reporting Whitelisted Detection Threshold 22 0 - 100 false Confidence Strategy Score Range Further Analysis Required? Confidence Threshold 3 0 - 5 true Classification Copyright Joe Security LLC 2020 Page 5 of 43 Ransomware Miner Spreading mmaallliiiccciiioouusss malicious Evader Phishing sssuusssppiiiccciiioouusss suspicious cccllleeaann clean Exploiter Banker Spyware Trojan / Bot Adware Analysis Advice Initial sample is implementing a service and should be registered / started as service Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis Mitre Att&ck Matrix Remote Initial Privilege Credential Lateral Command Network Service Access Execution Persistence Escalation Defense Evasion Access Discovery Movement Collection Exfiltration and Control Effects Effects Valid Graphical User Winlogon Process Masquerading 1 1 Credential File and Application Data from Data Standard Eavesdrop on Remotely Accounts Interface 1 Helper DLL Injection 1 Dumping Directory Deployment Local Compressed Cryptographic Insecure Track Device Discovery 1 Software System Protocol 2 Network Without Communication Authorization Replication Service Port Accessibility Process Injection 1 Network Application Remote Data from Exfiltration Standard Exploit SS7 to Remotely Through Execution Monitors Features Sniffing Window Services Removable Over Other Non- Redirect Phone Wipe Data Removable Discovery Media Network Application Calls/SMS Without Media Medium Layer Authorization Protocol 1 Copyright Joe Security LLC 2020 Page 6 of 43 Remote Initial Privilege Credential Lateral Command Network Service Access Execution Persistence Escalation Defense Evasion Access Discovery Movement Collection Exfiltration and Control Effects Effects External Windows Accessibility Path Rootkit Input Query Windows Data from Automated Standard Exploit SS7 to Obtain Remote Management Features Interception Capture Registry Remote Network Exfiltration Application Track Device Device Services Instrumentation Management Shared Layer Location Cloud Drive Protocol 2 Backups Signature Overview • Phishing • Networking • System Summary • Persistence and Installation Behavior Click to jump to signature section Phishing: Phishing site detected (based on logo template match) HTML body contains low number of good links HTML title does not match URL Invalid T&C link found META author tag missing META copyright tag missing Networking: Found strings which match to known social media urls Performs DNS lookups Urls found in memory or binary data Uses HTTPS System Summary: Classification label Creates files inside the user directory Creates temporary files Reads ini files Spawns processes Found graphical window changes (likely an installer) Uses new MSVCR Dlls Persistence and Installation Behavior: Drops files with a non-matching file extension (content does not match file extension) Copyright Joe Security LLC 2020 Page 7 of 43 Malware Configuration No configs have been found Behavior Graph Hide Legend Legend: Process Signature Created File Behavior Graph ID: 200939 DNS/IP Info URL: https://docs.zoho.com/file/... Is Dropped Startdate: 14/01/2020 Architecture: WINDOWS Is Windows Process Score: 22 Number of created Registry Values Number of created Files Phishing site detected (based on logo template started match) Visual Basic Delphi iexplore.exe Java .Net C# or VB.NET 3 89 C, C++ or other language Is malicious support.zoho.com help.zoho.com started started Internet iexplore.exe iexplore.exe 4 60 33 docs.zoho.com support.zoho.com sylterhofroyalpvtltd.com computational-artichoke-w0ccsrpa5dv58ardn93ucggy.herokudns.com 8.39.54.105, 443, 49753, 49754 8.39.54.110, 443, 49763, 49764 11 other IPs or domains 199.79.62.144, 443, 49765, 49766 34.204.156.91, 443, 49761, 49762 split.to ZOHO-AS-ZOHOUS ZOHO-AS-ZOHOUS unknown unknown United States United States United States United States Simulations Behavior and APIs No simulations Antivirus, Machine Learning and Genetic Malware Detection Initial Sample No Antivirus matches Dropped Files No Antivirus matches Unpacked PE Files No Antivirus matches Copyright Joe Security LLC 2020 Page 8 of 43 Domains Source Detection Scanner Label Link zohostatic.com 0% Virustotal Browse computational-artichoke-w0ccsrpa5dv58ardn93ucggy.herokudns.com 0% Virustotal Browse css.zohostatic.com 0% Virustotal Browse split.to 4% Virustotal Browse js.zohostatic.com 0% Virustotal Browse URLs Source Detection Scanner Label Link https://sylterhofroyalpvtltd.com/error/Hotmail%20SkyNet2/ 1% Virustotal Browse https://sylterhofroyalpvtltd.com/error/Hotmail%20SkyNet2/ 0% Avira URL Cloud safe https://js.zohostatic.com/writer3/Jan_14_2020_2/js/pdf.worker.js 0% Avira URL Cloud safe https://split.to/uqMH3zd) 0% Avira URL Cloud safe https://split.to/uqMH3zd 0% Avira URL Cloud safe https://writer.zooyalpvtltd.com/error/Hotmail%20SkyNet2/a70ad6abae58caf#page=1&zuid 0% Avira URL Cloud safe https://js.zohostatic.com/writer3/Jan_14_2020_2/js/zw_pdfpreview_part1.js 0% Avira URL Cloud safe https://writer.zoh 0% Avira URL Cloud safe https://writer.zoRoot 0% Avira URL Cloud safe https://writer.zom/writer/open/io2ap787b5d0ad13c4bdd8a70ad6abae58cafRoot 0% Avira URL Cloud safe https://sylterhofrqMH3zdoyalpvtltd.com/error/Hotmail%20SkyNet2/Root
Recommended publications
  • HTTP Cookie - Wikipedia, the Free Encyclopedia 14/05/2014
    HTTP cookie - Wikipedia, the free encyclopedia 14/05/2014 Create account Log in Article Talk Read Edit View history Search HTTP cookie From Wikipedia, the free encyclopedia Navigation A cookie, also known as an HTTP cookie, web cookie, or browser HTTP Main page cookie, is a small piece of data sent from a website and stored in a Persistence · Compression · HTTPS · Contents user's web browser while the user is browsing that website. Every time Request methods Featured content the user loads the website, the browser sends the cookie back to the OPTIONS · GET · HEAD · POST · PUT · Current events server to notify the website of the user's previous activity.[1] Cookies DELETE · TRACE · CONNECT · PATCH · Random article Donate to Wikipedia were designed to be a reliable mechanism for websites to remember Header fields Wikimedia Shop stateful information (such as items in a shopping cart) or to record the Cookie · ETag · Location · HTTP referer · DNT user's browsing activity (including clicking particular buttons, logging in, · X-Forwarded-For · Interaction or recording which pages were visited by the user as far back as months Status codes or years ago). 301 Moved Permanently · 302 Found · Help 303 See Other · 403 Forbidden · About Wikipedia Although cookies cannot carry viruses, and cannot install malware on 404 Not Found · [2] Community portal the host computer, tracking cookies and especially third-party v · t · e · Recent changes tracking cookies are commonly used as ways to compile long-term Contact page records of individuals' browsing histories—a potential privacy concern that prompted European[3] and U.S.
    [Show full text]
  • Discontinued Browsers List
    Discontinued Browsers List Look back into history at the fallen windows of yesteryear. Welcome to the dead pool. We include both officially discontinued, as well as those that have not updated. If you are interested in browsers that still work, try our big browser list. All links open in new windows. 1. Abaco (discontinued) http://lab-fgb.com/abaco 2. Acoo (last updated 2009) http://www.acoobrowser.com 3. Amaya (discontinued 2013) https://www.w3.org/Amaya 4. AOL Explorer (discontinued 2006) https://www.aol.com 5. AMosaic (discontinued in 2006) No website 6. Arachne (last updated 2013) http://www.glennmcc.org 7. Arena (discontinued in 1998) https://www.w3.org/Arena 8. Ariadna (discontinued in 1998) http://www.ariadna.ru 9. Arora (discontinued in 2011) https://github.com/Arora/arora 10. AWeb (last updated 2001) http://www.amitrix.com/aweb.html 11. Baidu (discontinued 2019) https://liulanqi.baidu.com 12. Beamrise (last updated 2014) http://www.sien.com 13. Beonex Communicator (discontinued in 2004) https://www.beonex.com 14. BlackHawk (last updated 2015) http://www.netgate.sk/blackhawk 15. Bolt (discontinued 2011) No website 16. Browse3d (last updated 2005) http://www.browse3d.com 17. Browzar (last updated 2013) http://www.browzar.com 18. Camino (discontinued in 2013) http://caminobrowser.org 19. Classilla (last updated 2014) https://www.floodgap.com/software/classilla 20. CometBird (discontinued 2015) http://www.cometbird.com 21. Conkeror (last updated 2016) http://conkeror.org 22. Crazy Browser (last updated 2013) No website 23. Deepnet Explorer (discontinued in 2006) http://www.deepnetexplorer.com 24. Enigma (last updated 2012) No website 25.
    [Show full text]
  • Charles University in Prague
    Vrije Universiteit Amsterdam Faculty of sciences MASTER THESIS Milan Slančík Advanced floor plan designer in Flex Department of computer science Supervisor: Prof dr Anton Æliëns Second reader: Dr Evert Wattel Study program: Informatics, Multimedia Computer Science Acknowledgements First of all, I wish to express my sincere gratitude and appreciation to my supervisor, Prof Dr Anton Æliëns, for his thoughtful guidance, his valuable suggestions, comments during discussions, prompt response to my emails and speedy feedback. My gratitude also goes to my second reader, Dr Evert Wattel for his ideas, willingness to read drafts and test the application in advance. Last, but not least, I would like to give my sincere thanks also to my parents, who have supported me throughout the writing process. Contents 1 INTRODUCTION ....................................................................................................................................................... 8 1.1 BACKGROUND ............................................................................................................................................................ 8 1.2 STRUCTURE OF THIS DOCUMENT ............................................................................................................................ 8 2 AIM OF THE WORK AND RESEARCH ISS UES ........................................................................................... 9 3 RELATED WORK...................................................................................................................................................
    [Show full text]
  • Q Id Q Desc Op1 Op2 Op3 Op4 Ans AC1 in an Access Database The
    q_id q_desc op1 op2 op3 op4 ans In an Access database the tables, queries, forms and reports are AC1 ____________ Objects Elements Files Parts A The financial transactions are to be Sampled ____________ leading to different Collected and and Grouped and Assets and AC2 steps in Accounts Compilation. computed stratified summarized liability C ____________ is/are used to set Candidate AC3 relationships between tables. Primary key key Both A and B Neither A nor B C Value The methods LIFO, FIFO, Moving Value closing clearing Value expense Value income AC4 Average are used to ____________ stock stock stock stock A This data type field gets values from another table, a query or a list of AC5 values that are supplied. Memo Lookup Hyperlink AutoNumber B The report prepared taking the asset and liability type accounts from the Income AC6 Trial Balance is called ____________ P & L statement statement Balance sheet Asset sheet C When it is mandatory for a user to input data in a field ,the field property AC7 to be set is ____________ Field Size Format Field value Required D The report that depicts operating profit/loss for a period is Trading Suspense AC8 ____________ Trial balance account P & L statement accounts C In MS Access you can add, edit, Datamenu Tabledesign AC9 modify data of a table in this view. Datasheet view view Datatable view view A The day book contains transactions Income or Sales or AC10 relating to ____________ expenditure purchase Asset or liability Profit or loss B Access automatically creates this sheet in a table that is in a one-to- Datadesign AC11 one/one-to-many relationship.
    [Show full text]
  • 3.1 What Is the Restaurant Game?
    Learning Plan Networks in Conversational Video Games by Jeffrey David Orkin B.S., Tufts University (1995) M.S., University of Washington (2003) Submitted-to the Program in Media Arts and Sciences in partial fulfillment of the requirements for the degree of Master of Science at the MASSACHUSETTS INSTITUTE OF TECHNOLOGY August 2007 © Massachusetts Institute of Technology 2007. All rights reserved. A uthor ........................... .............. Program in Media Arts and Sciences August 13, 2007 C ertified by ...................................... Associate Professor Thesis Supervisor Accepted by................................... Deb Roy 1 6lsimnhairperson, Departmental Committee on Graduate Students QF TECHNOLOGY SEP 14 2007 ROTCH LIBRARIES 2 Learning Plan Networks in Conversational Video Games by Jeffrey David Orkin Submitted to the Program in Media Arts and Sciences on August 13, 2007, in partial fulfillment of the requirements for the degree of Master of Science Abstract We look forward to a future where robots collaborate with humans in the home and workplace, and virtual agents collaborate with humans in games and training simulations. A representation of common ground for everyday scenarios is essential for these agents if they are to be effective collaborators and communicators. Effective collaborators can infer a partner's goals and predict future actions. Effective communicators can infer the meaning of utterances based on semantic context. This thesis introduces a computational cognitive model of common ground called a Plan Network. A Plan Network is a statistical model that provides representations of social roles, object affordances, and expected patterns of behavior and language. I describe a methodology for unsupervised learning of a Plan Network using a multiplayer video game, visualization of this network, and evaluation of the learned model with respect to human judgment of typical behavior.
    [Show full text]
  • Programming-Javascri
    www.allitebooks.com www.allitebooks.com Programming JavaScript Applications Eric Elliott www.allitebooks.com Programming JavaScript Applications by Eric Elliott Copyright © 2014 Eric Elliott. All rights reserved. Printed in the United States of America. Published by O’Reilly Media, Inc., 1005 Gravenstein Highway North, Sebastopol, CA 95472. O’Reilly books may be purchased for educational, business, or sales promotional use. Online editions are also available for most titles (http://my.safaribooksonline.com). For more information, contact our corporate/ institutional sales department: 800-998-9938 or [email protected]. Editors: Simon St. Laurent and Meghan Blanchette Indexer: Lucie Haskins Production Editor: Kara Ebrahim Cover Designer: Randy Comer Copyeditor: Eliahu Sussman Interior Designer: David Futato Proofreader: Amanda Kersey Illustrator: Rebecca Demarest July 2014: First Edition Revision History for the First Edition: 2014-06-25: First release See http://oreilly.com/catalog/errata.csp?isbn=9781491950296 for release details. Nutshell Handbook, the Nutshell Handbook logo, and the O’Reilly logo are registered trademarks of O’Reilly Media, Inc. Programming JavaScript Applications, the image of an argali, and related trade dress are trade‐ marks of O’Reilly Media, Inc. Many of the designations used by manufacturers and sellers to distinguish their products are claimed as trademarks. Where those designations appear in this book, and O’Reilly Media, Inc. was aware of a trademark claim, the designations have been printed in caps or initial caps. While every precaution has been taken in the preparation of this book, the publisher and author assume no responsibility for errors or omissions, or for damages resulting from the use of the information contained herein.
    [Show full text]
  • Documentation, 5.1 MB
    MenuBox by Cloanto Corporation © 1998-2021 Cloanto Corporation The MenuBox software and documentation are Copyright © 1998-2021 Cloanto Corporation. All rights reserved. No part of this package may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language or computer language, in any form or by any means, magnetic, memristive, optical, quantum mechanical, electronic, biological, chemical, mechanical, acoustic, manual or otherwise without the prior written permission of the copyright holders, or as indicated here or in the EULA. The use of this document is subject to the terms of the EULA that accompanies the MenuBox package. Cloanto may have copyrights, trademarks, patents, patent applications, and other intellectual property rights covering items contained in MenuBox and its documentation. Except as expressly provided in any written license agreement from Cloanto, the furnishing of this product and its documentation does not give you any license to these copyrights, trademarks, patents, or other intellectual property. Cloanto and MenuBox are either registered trademarks or trademarks of Cloanto Corporation in the United States and/or other countries. Microsoft, Windows, Windows Me, Windows NT, Windows XP, Windows Vista, Windows 7, Windows 8, Windows Server 2003, Windows Server 2008 and Windows Server 2012 are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. All other trademarks and service marks are the property of their respective owners. Contents Table of Contents Part 1 Introducing MenuBox 6 1 New.. .F..e..a..t.u..r.e..s.. .................................................................................................................. 7 Part 2 Getting Started 11 1 Ov.e..r.v..i.e..w..
    [Show full text]
  • Appwave™ Enterprise Store 4.1 Administrator Guide
    Product Documentation AppWave™ Enterprise Administrator Guide Version 4.2 Published August, 2013 © 2013 Embarcadero Technologies, Inc. Embarcadero, the Embarcadero Technologies logos, and all other Embarcadero Technologies product or service names are trademarks or registered trademarks of Embarcadero Technologies, Inc. All other trademarks are property of their respective owners. Embarcadero Technologies, Inc. is a leading provider of award-winning tools for application developers and database professionals so they can design systems right, build them faster and run them better, regardless of their platform or programming language. Ninety of the Fortune 100 and an active community of more than three million users worldwide rely on Embarcadero products to increase productivity, reduce costs, simplify change management and compliance and accelerate innovation. The company's flagship tools include: Embarcadero® Change Manager™, CodeGear™ RAD Studio, DBArtisan®, Delphi®, ER/Studio®, JBuilder® and Rapid SQL®. Founded in 1993, Embarcadero is headquartered in San Francisco, with offices located around the world. Embarcadero is online at www.embarcadero.com. Contents Welcome to AppWave . 11 About This Document . .11 Introduction to AppWave Enterprise . .11 Additional Product Information. .13 Installation Information . 15 Installing AppWave . .15 Default Installation . 15 Custom Installation. 16 Upgrading AppWave from Previous Versions . .19 Providing Users with AppWave Browser. .20 Administrator Installing AppWave Browser . 20 Admin directly installs AppWave Browser on a machine for all users . 21 AppWave Configuration and Administration . 25 Using the Dashboard Commands. .26 Download AppWave Browser . 27 Services Status . 28 Set Up Embarcadero Licenses. 29 Download Applications . 31 Manage Mastering Plug-ins. 33 Import LDAP Users and Groups . 34 Examples . 37 Updating and Deleting LDAP Users .
    [Show full text]
  • December 2003
    DCU DUBLIN CITY UNIVERSITY SCHOOL OF ELECTRONIC ENGINEERING The YBox - A Front-E nd Processing Engine for W eb Com m unity based A pplications Liam Fraw ley December 2003 MASTER OF ENGINEERING IN ELECTRONIC SYSTEMS Supervised by Dr. D. M olloy The YBox - A Front-End Processing Engine for Web Community based Applications Acknowledgements I would like to thank my supervisor Dr. Derek Molloy for his guidance, enthusiasm and commitment to this project. I would also like to thank my family for their patience throughout the entire project Finally I would like to express my deep appreciation to Fiona for her support and understanding over the past two and a half years. The YBox - A Front-End Processing Engine for Web Community based Applications Declaration I hereby declare that, except where otherwise indicated, this document is entirely my own work and has not been submitted in whole or in part to any other university. Date: 2 .1 -0 2 - Ù3 iii The YBox - A Front-End Processing Engine for Web Community based Applications A b stract This document describes the YBox framework that enables web application developers to rapidly develop web applications for the Java 2 Enterprise Edition (J2EE) platform, The YBox is a fully implemented and tested framework that provides a “front-end” for Servlet Containers and contains functionality that all user- based web applications for virtual communities require. The YBox extends the functionality of the Servlet Container and the Servlet 2.3 API and is implemented in a platform independent manner, which means the YBox will run on any operating system or any Servlet Container.
    [Show full text]
  • 3500+ IMPORTANT QUESTIONS for ITT ONLINE EXAM ** by A.Amogh [email protected] 09666460051
    ** 3500+ IMPORTANT QUESTIONS FOR ITT ONLINE EXAM ** By A.Amogh [email protected] 09666460051 Amogh Ashtaputre @amoghashtaputre Amogh Ashtaputre Amogh Ashtaputre ** 3500+ IMPORTANT QUESTIONS FOR ITT ONLINE EXAM ** COMPILED BY A.AMOGH. FEEDBACK CAN BE SENT @ [email protected]. 09666460051. QUESTIONS A B C D ANS TALLY The ------ key can be used to select an existing F1 ALT+F1 CTRL+F1 None of the above A company from list of companies. Import and Export of data between Tally and Tally ODBC Tally IMP Tally INI None of the above A other programs is possible only through ---------- Program. The re-order point is the inventory quantity that TRUE false A triggers a stock replishment activity. A created company's detail can be modified F3 ALT+F3 CTRL+F3 None of the above B through keys A/An ------------- is the official notice that the firm Invoice Bill A or B None of the above C sends to its customers to advise then to the amount of money that is owed. In tally, all masters have ________main options Two Three Four Five B In tally, to create a new column in balance sheet Ctrl+C Alt+C Alt+Ctrl+C None of the above B press _______ In tally,the use of group behaves like a sub- TRUE FALSE A ledger, option is that we can summarize many ledger accounts into one line statements In tally, we can alter ledger details using either TRUE FALSE A single or multiple modes but not able to delete a ledger from multiple modes. In tally,a group company is marked with an * $ & ^ A ______________ The systems that work together to order, receive, Purchasing and Purchasing and Accounts payable and Purchasing, D and pay for replenishment of stock are --------------- Accounts Receiving Receiving Receiving and payable Accounts payable Tally allows deleting a ledger from --------- Single Multiple A or B none of the above A alteration mode.
    [Show full text]
  • Web User Profiling Based on Browsing Behavior Analysis Xiao-Xi Fan, Kam-Pui Chow, Fei Xu
    Web User Profiling Based on Browsing Behavior Analysis Xiao-Xi Fan, Kam-Pui Chow, Fei Xu To cite this version: Xiao-Xi Fan, Kam-Pui Chow, Fei Xu. Web User Profiling Based on Browsing Behavior Analysis. 10th IFIP International Conference on Digital Forensics (DF), Jan 2014, Vienna, Austria. pp.57-71, 10.1007/978-3-662-44952-3_5. hal-01393760 HAL Id: hal-01393760 https://hal.inria.fr/hal-01393760 Submitted on 8 Nov 2016 HAL is a multi-disciplinary open access L’archive ouverte pluridisciplinaire HAL, est archive for the deposit and dissemination of sci- destinée au dépôt et à la diffusion de documents entific research documents, whether they are pub- scientifiques de niveau recherche, publiés ou non, lished or not. The documents may come from émanant des établissements d’enseignement et de teaching and research institutions in France or recherche français ou étrangers, des laboratoires abroad, or from public or private research centers. publics ou privés. Distributed under a Creative Commons Attribution| 4.0 International License Chapter 5 WEB USER PROFILING BASED ON BROWSING BEHAVIOR ANALYSIS Xiao-Xi Fan, Kam-Pui Chow and Fei Xu Abstract Determining the source of criminal activity requires a reliable means to estimate a criminal’s identity. One way to do this is to use web browsing history to build a profile of an anonymous user. Since an individual’s web use is unique, matching the web use profile to known samples pro- vides a means to identify an unknown user. This paper describes a model for web user profiling and identification. Two aspects of brows- ing behavior are examined to construct a user profile, the user’s page view number and page view time for each domain.
    [Show full text]
  • Le Livre Du Pegasos » Compilation of Articles on the Pegasos Volume 3 : Morphos
    The Pegasos book « Le livre du Pegasos » Compilation of articles on the Pegasos Volume 3 : MorphOS May 2007 edition - By Geoffrey CHARRA (V2.3) Translated from french by Geoffrey CHARRA (December 2007), With the help of Eric WALTER, Thibault JEANSON, Denis HILLIARD (translation) and Fulvio PERUGGI (corrections) Sponsored by The Pegasos book – Volume 3 : MorphOS Contents 1 Presentation of MorphOS .............................................................................................. 6 2 Installation of MorphOS ............................................................................................... 8 2.1 Preparation ........................................................................................................... 8 2.2 Booting from CD .................................................................................................... 8 2.3 Installing the Hard Drive ........................................................................................ 9 2.3.1 Partition 0 (boot) ............................................................................................ 9 2.3.2 Partition 1 (system) ...................................................................................... 10 2.3.3 Partition 2 to N (data) ................................................................................... 11 2.3.4 Save of partition table and check ..................................................................... 11 2.4 Format the Partitions ..........................................................................................
    [Show full text]