| File name: | DSGFO1.exe |
| Full analysis: | https://app.any.run/tasks/3f78794d-71fe-4413-9342-2d2b4bf75a82 |
| Verdict: | Malicious activity |
| Threats: | XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails. |
| Analysis date: | May 16, 2025, 09:07:32 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | 109631AA606A58E7BB394BE02FAF01DC |
| SHA1: | 33B0CABC263A0DB3E167FF6FF5E1A50BAF6DD6ED |
| SHA256: | 1A173A01A41C2E0F8F72C08F1A6F567227EF1F92F445B2E840B1B433D4BE7C0C |
| SSDEEP: | 1536:14DtPwJLqvNDcDMAz6yzbAb6US2WqcUzOE3a4:Y3NDcg4zbAbfWqVzOE3F |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (56.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (21.3) |
| .scr | | | Windows screen saver (10.1) |
| .dll | | | Win32 Dynamic Link Library (generic) (5) |
| .exe | | | Win32 Executable (generic) (3.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:05:14 14:34:07+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 59392 |
| InitializedDataSize: | 2048 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x106ce |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileDescription: | |
| FileVersion: | 1.0.0.0 |
| InternalName: | Server.exe |
| LegalCopyright: | |
| OriginalFileName: | Server.exe |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 856 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1676 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5008 | "C:\Windows\System32\schtasks.exe" /create /f /sc minute /mo 1 /tn "DSGFO1" /tr "C:\Users\admin\DSGFO1.exe" | C:\Windows\System32\schtasks.exe | — | DSGFO1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5048 | "C:\Users\admin\DSGFO1.exe" | C:\Users\admin\DSGFO1.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 5380 | "C:\Users\admin\DSGFO1.exe" | C:\Users\admin\DSGFO1.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 5548 | "C:\Users\admin\Desktop\DSGFO1.exe" | C:\Users\admin\Desktop\DSGFO1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Version: 1.0.0.0 Modules
XWorm(PID) Process(5548) DSGFO1.exe C282.26.74.114:1337 Keys AESsb01 Options Splitter<Xwormmm> Sleep time3 USB drop nameUSB.exe MutexsTlRUd5D0B18p1XF | |||||||||||||||
| 5968 | "C:\Users\admin\DSGFO1.exe" | C:\Users\admin\DSGFO1.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (5548) DSGFO1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | DSGFO1 |
Value: C:\Users\admin\DSGFO1.exe | |||
| (PID) Process: | (5548) DSGFO1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\3C54740F7CC0F23B53E5 |
| Operation: | write | Name: | 91E582DD0FE0224A74B326FAA35161958AAE425DF4B6151646B9C330E7BD5487 |
Value: 004800001F8B0800000000000400ED7C7F7C1BD5B1EFECAEB4BB922539B263D949ECA0FC2028B123E2FC80181212C7CE0F373131714802041259DA384A64AD59C909862628054A290448292D29A517DAD2DBF4D72BB7A505FAB8D04729D0162EF442FB68D3943C6E7BCB6DFBFABBD0777BE17E677625D97128EDFBBCCFFBE37D9E13CD99993367CE9C993973CEAE95F45E7A3B6944E4C3E7ADB7881E22F76725BDF34F099FC8198F44E8CB8167673CA46C7876C6E6DDD9427CD8B1079DD4503C9DCAE7ED627CC08A3B23F978361FEFDED81F1FB23356321C0ECEF674F4AD26DAA068F4FDC0F17459EF2B34335EA3F4B946E82EEFB73B00E2F8EC147292E0AA6B3751B5A57B5D3EFF68B4F20616E5BFD5B6D2B8E2D0BB915CBD7769A75F64E8AFF0C5841FD8678E214DD0EBC6D0C9A2755511ED1B2B5C5959AB3A41C5CEA45370D831621B6C9485AE1A2F87A12B938E95B3D39EAD254FD79A0972A78C247A7187DBAE93217EBA6B3162328F48F1FA7F76453527FE9A9FE96AA29128386F0EA989262034EF538529684B50E82B4C658CA35698C698C658336358956F5EFD02456203D1281DE401760B3A83ADA457FA54E96315F6F453FB34E963A5F619A7F6F9A48FA7B1E3D53E9596A1CF2F7D80BEC98919E8AC31DA6638987EF879F0D4C44CB0EC590005246D306496FCA24E0654E6A8214955E8D1CBEC99A4969898B7A580A8E8893331BA08865A32980B4FCD614F1195C71B32DE288F1FCF4F84A143F85F99FCA6DE00A27016DB9460F7996CFB9BFAD4F1DC8037CD5C771A9A86F56E25C9CB289B1144BF56C20C3E5F09DA7DFE12ECF4457CA5089A83ACD39EC7213C18A8A027A69D996865179161B7A14DCC676E22097882D866453697424B3B681A7CA6BC3F56AAC5E8D89E5294837D36DB55CFEA79C2D264B6107619340DFE0EB05D4D8DCD85052C0545BE067758E361A4AE52AA1BAF8105E2F43491DD2E5656E9854CBB8C83BCC883BCC6C4228EE362EE6A149B124B98710EAFA64E499CCB59E1C0E4E1836C556229E83A4A74A0B9A51BB30B635CD7796FD3753052C612E73368E2CC708DE115C404DE9A8D2160310ED8321EC3DDF67260734E34B82E0E51620A8F2C3BB7ECDB77D1233EA5817DCB7EFBB5226B45DE889BDF54827A9BEE0EF43CA0DA17484EC7DE544366C77EC81F8C8A6BDF54C2818E87594CCC3A82C1F5BEA8AFE31666B187ED156CFE4CCEDD95EC751EE67674F2A4634211951063BC3FEA6F3BC78BDA5FBFE41FCDE772235A1AF7FCE0AB8DDFABC69B5A27BBC67846DAAB64BDB4F4B35436D3ED31EC2EC902B1AF9BF5B33A98A447F5B62B0E2208BE36439AD6D8C146EED23BD8149C3FC1334B4D95A5C99AD7B055E5659C6EC58D632D9CE99A5E9DFA07135641D41AF0E279A2EB6FC885989B0BF5C6B86450685E67B35B6F9175F40D78EFBFE3030DE4E6854A28005C3B789F275A645A6FE706493FCDCE9D57DEB7D8D9D35C1D7EBA83E43C810E77E54195CBA31432BDC6B8359B580BA603A5C38975AC913B43BA19336FCDBAC1D08D9851C665550D8D760FAF4B085D7C1DD3C5655F8DD9EF921587486F33747B3D8F395EDE0BE1897BA199CF820059F9F2F1ACD035EFA686F2FABF094E986D77EB8F3BBDBDA16289DD3BB69C9DDE295E325D58CDABCE77AE81E416CE8D632543649E56323041324C81D345078B5A4C72124C89BBF1219C5C532E2EE35752E4DA327E37458E5563F80C4645D80F4BBF062CBE608428D1572D8FF645BC7ABDE33A2A07B9C6399B035A0974C83C7DA0C34620162807D71813F4898136DC401BE3029DD824EB0E91D166185EB8892A09EF3B25E2D458EF5FBAFC2DBEA27AB19F47F6D172ECA374D7318AF19A57B975B89F376A839C2E7CEEF9A91757865A6F3FCCE1B571593BC81252A41B6289CD6E1EC43E5263B0F7B1F0F8C9F6171E5D729619BFE7EB5FB9F1FC477913E31ED7F078E40BE77FD32358229959FA822237BC2F3EF2A3258D667CDB9A17BE955CD6EA7192972DFD07E97EE2F54FFD389961F68FBFF7FBFF48FA97DE0DB6E160FAE158E262CCDEF15E2E6C3708B7BFC26DBB76A923ACCBAA821F60C1EDC24D57B9F733778D70F756B98F317781700B55EE53CC9D2ADC0355EE71E6FAB818BBDE5FFA067B576FFC48620BBAF526B72D6C65628A4BF0ED0282FFF4CE82C86B7DCED24F9505177982DC16B6B1C0255233A6B8AC582CD698388375B7EEFB4BF2ADDB88B997F2E661B1CB247BA2BE5860BED6D4AAC40E6E67D138CFDD3A9F6289CBB91FC794731B96CD03AEF0F44AC6CF62B043F422195BBC64D4297ADAA2899594EB30FB6C3E722C894F8B5787EB1768848AC3F74FDCDF76F2E68A855010C366BD2F001B7CF57AEB594654FF889D429FEAC6804F6123CA9B021DC1D628A66EFC1E1F62517FFB3F4FAEDC5BA392F5AC7780C7F2D5DFBDD412DF27DDFEBA31FD9931FDD316F8C86239773F142CB66CAA9C5621ECE4A9F62EDEA0662C312815C98815768B53038D3FF00E35363EEA8F05EC2C4B46FDC1135329EA6B33A3BEF24E1EB3AB654E77CFB6514B0F9723B7765FB8D5DDBF6CCF76F72C8B96AB908AAAB3874BA7182485858C4631241C5063E8B6F7323360E7BC3A12683302DE8C6EC1098E2F2EFA3CD786D9D4D0E1CEABE226BCE6C2AA0D582E35B00D852136A19097D26D9807F95A2CF961DB60D9C352F29AEC2BA5B51DB649857B9074511CE67641269FEE258F9FA2FEBF74570ED3796BA9C5ADD7FFDB3614FFCFD910A0B5AADC25903B951B72B08AD607EB82891136AECA0B19756A621F6FCCFD12A0C4559230074779CAABDD1DE7B3AF916D8D9B338F46C3036097CB8EC7E93B9448F03E85E8BBD94CF4494B8903ACA2061B269438C868F88CF81971A92EF59168381A295CCB46446BA221D32E493E34792BAFA5686DE2D0D84543FB7B3CEDEF7133E83ADE2189EB597C527452DB9914500B37F03A2A5AB00BA3E3B578795AAF1F44D10E6A7B0A3732653877F021892753BDDE6C2CBC8F798168C0BE899718353EEE9DBAF575B1FAFA685D5D7DE2FDA273BC6FF949A47EB2A7BF21106D889A5071334BCAB1E09E70B7B0F31ADCEBEAECF28126DC310F2993DFFEF965F2DFF6FC722242D1066CF086F2CD2C12AD075997382C113A4E272679BE8A557CE41EF1C8B195ECAFF7D19247A9C9BDA3BC41359A22B84A3728374554AF265CA13C3EDDC58936293F3A5B9D54DE17976354A3EC0B290F63BD1EAA3A3DECF91CF5DFF5B95971B93F8622EAAFD327B8DCAC335D971B9ECB0354388F03188C06EDF319A989D6B809511F8A86A201EC31371A95F40853343C3E3D4E0D54E01D0265BC7DA08CBF3D508136CE984AA07490FE89818A9C1228A9D39D19D7FBDC307D2B3E4DDE79A67A7CBE51CC5288BC40C9AB263CAED01FF1593486CF3FED7CCE80D7ADB8EFDDDC7351A505AEDE68FCC97B9A0F05D5B6336335AD9355C3C67C413D15BF4321E5D2A0D1B8ADC6506D9CD4C1B3D5D693E5B30FE71A4DE15C5035B9E8256EA7CAE1C6EF4CB8A04F95FEC4113AE53DD034E63F3FA9FC5EA7D2172A9F976AE20334E6FD109FE5CDC2BFC58FD193DF546A8C363381D5B4065BFDA48AE01CD2DE6CE06E79ED35D7CD7AF71C469EB10E8CBFE6839C727772F61AB798AEAE90D9363901F7B5D6B8DD86FD21891219A27753599B5AF8309A032C322F5940B6EA257E849DB7502BE219621ABF7293F745AAC46ABAD4EE564EB3BB783AD5482C2BBF3CAA477DBF1B3267B08CC60FBA7A4D9DFA6603EABDAAA188AFE3026C5E8325FBCC6BE044DF0FC2E6352D424D63AADE67F0CB00BDDE6F601F2456308A7D15D5135D8C1AB815C4D061940BFA0552D0FD5143FA81253AB9D50C7EA600AD278ECA2604B24A18A61BC855FDEF5AA5786F213936FB16271724172D58D4DEC11C3FE1D4A7EDB82DCCC279F034DA5770B99FD55F74B2F9C1024B7C1A47E5E738DF2EEEA7CD33BDDC5B7B714F37E730E85F18A057E5EC816A0E2B5B5B3EDE12801EFA5FCA223E0079767E3D1A736328EF48B10A3AEADDF7BA5D3FF2FB437E772581D33C3CE2C9F8BDD6F0FADC57BC2F19EECA74BAD07F7148A7AF093CD377734D2D3DC82F0B69976F6E40A7763FC38F0BCC0BBC51E0E7A57793AF16A39ED318FE49384FFB3EAC07E937DA07F0247397F61923481DBECF18111AD07E5213A15F068FD5E87412B344E8802F198AD09DBE94A2537DA4D58CD083419689F9997396C69C162A41C371EDEF4D9D4C8CD2E94B1ADB79557004F0606072002792F6167A3FA8ECD275BA38D06A06A93BF2E5B04EAA7902FB69ABFE5DBD8E8EABDF45EF1D9845A71DC62E70EC400976BE6E7C1B9CBB9503B5285B0186979A076AEBE80B011EF59E1A868F044B80EF0E97F41835D524C275F48D08F3EF109DAAC63A1F50197EAC762EEC3920F67C2BB24B8FD0394A3214A45FE837D704E9EF6BBF1C0ED20C8D6148630B7FE2E7352E0F274331BAD74C8423F421E03A5D4EACED2283D7F22F219634B1161D19C36BFCB6CEFC6B54E6DF2FF33E25F243E18BE1CF3742292542AF2BECC3EFC97AAFAE61782FF0F5CAD62047F6A72A6BDBAFAB58EF0B41D6B653653FAC36D9030B050EAB0CAFC1D818DD1AE6555BF0834EE7D4B00D6780CFD9B34B72A8BC4B7E63EEACEDA9503F0FEEACED05CE793D89A64676D65E0E4A9364BC3DF4DED0E5C84C53FAC2E19DB537203F6BA4EFDBB52C69227FB95E7EC3FC86C954AD68AD0D3315445CB9EF820853B5788A10C910530D5C5F21FA9920533154221EF76CC0A5CE126A45AD4BB9BF64C06596989A4F7E50DFAF71A9A4506D5EDF12F263376B0A538D74AEECA1CD1A5353E83CD9556BC9A5960BD52BD454ECCF20C6FC16D4CBA07A7016C583537DEDF47A6026604D701E604770A12F4A7BCDF300BBB50B0067AB5DBE18E4D702A605BE1ED9007842E0EBC4F02581DF12F8B0B211F0D7D88D315A696C051C0A5E0AF82BBAC2770E24D39885E10C8AD43EA69D43CF636FC7C8477B7C5B4AFF4EB64FA7F51186DF0F304C0BDE6FDABEBEB85488A6B9D8770A6D1B470D08156D3ABBE63150B708556F9E083A7876FFB4479D34F783FA86473D107C37A8573CEAA99A43A0FEEC51C5E07B4175CF70A936ED66509779D452ED08A8CC8CEA7C2A5D3DA36A8B4AD70B15336F8CDCE553E9A3DE380A33F5A571E34E8E1BF70B771CED08DCE31BDF67D0CE99D571C6297DD7CF74C7B545B8EFBFCE72A916FD533E835E3CD3A5DEAF7CDE6752D31C977A4D790435F9458F7A52798CEF4567B9544A67EAF94475BEE0B8F9500312AEE46DD019A4EDADDE0C812FF96A64A79528167F28F2882FE451F5F1CF459E401E7DD993BC95BEED6BA0173DEA17F402A2FF7B8F3A16FEBEAF91AE6F73A97B41359139DFA5B6D77CDF37856EF1A80B404D1D67D9346FBE68BC1439E19B469392AEE4A5DACF7DB3C749CEA9D8D952FB3BDF1CFAE40257F276F57550C58512317A537FCB97A02F0AF54D7546F8566D2E3DEF51EBD5B7B05F7F26D4753445F3F9E7916F91DBF798FE15F4350B15C5BD3080BED5422954AB44FDADB47151D59636DA2E94664E563782BA675CDF58ABDBE81F1655A3D246FFE88DABA129FEF192F3E93BAE16BAD19CEE9F4FBFF6A8F6DAD9A0C64A262B9E28455AFD55EA6381A5FE732BD4115AE13FAF427D81BAFDE757A837C2DDFE65152A1CE9F12F1F37C38A4ADF86DA8DFE2AF535E8AC529FA41EFFCA0AF55CB8DFBF4AFC65E80C9F23BE27FC8C578BCAC56FAFFF99F8267152E1DE1F0618F608FE33BD8A1F170DBF0EF1D8CB6B79AC236FBE7BC23C362DA37A0DEEDD6F722F4BFA3CFE93E1AA9E3F474E0FF9094CA5D72232969F3C2869B0E6CB22ECEBEBF85522F16F974C3A20BFCB7B4A346FE75F78D2BFD1A9B83BE3474566B15A858AF4BE24B83FF297665CAE9E7EC6AF8AF758521349975386FE4855C6C5FF452943D59371F18E4880E6D628C8698EEB14C020CD059C8473846187C04E813D022F1278096003A504CF0ABC52E028E054BA09304EF789CE63021F10F80CE01C3A2992AF09E737028F083C2A302470B2C06681B33D3EEFA5C9029B05CE16F8303585F7D20BF4847A25E0476A47E94F90BF969E515E540E5340E1B12F00DE4D51C0FB20CF9CA8F27C44A79715B3E6BFD014E5A8FA15E4DDCFD547C0F963F0319A2BA36600FE13E01A5D015C041850DF173C0EBC3D7292A2EA9DE6BF027EACE697D4A1CCD37F4753D49F86FF44EDCA6CE32DC0BEC85B907F4CD794B92ACF3E4369D14D658652A7CF51E62A7B6AE72B01F5A4BE50E9506FD774CCF8B2FF5CF03FAF2D035C62742B3D6273A73AC55CA7B09EB4D2A33E15DE0D0DFF6AE4015F53F62997C8D819CAFB0532DEA1321E555E8D30FC7AE0EF20F959E5934A4A9D8D9324ABBEE9FFB472A53A12794499A23EA03FA91C522FC39E6AC75CDF51EE1378545917F82EF807CC97015FF59F506E528F065E558EA831E3A762C32F95FBD46743BF572E52B6876BD48B943FC07BC7D41B238DEA31F587A116C0A7F5B354F6E172C0DB942EF501CCB25EBD049C4D802EE787A12C705EEF25CA24948494F83C2BF0EBEA6FF5F7A8CFA823B5CB01B7AA3701EEA9B95DBD52C9191F02BE017887F8B943FC3C2A961F52DEABFE587D19D6FE4C3DA4FC4FC4F390B245F92DE07ADC544FC2C23FAA4795F3037FC6D8B935AA765469AA0D691CF7987648BC774CE2D8AE3C5A3B4D639D676AAFA90FD69EADDD047CB17644E19D7244A9359769BF51BF1DECD28E2961FD5DDA14F538E2FE1BF59A484CEB5137856F005C02DB1E263E5F1E263E571E263E41FEA4FAD5FBB5C572475A46FFE6DF48CBE8F7FEEF01E755BFAC66233F85CE07037FD64CCA50836F2E7D823E6824716BBD1E75BC9E0E034EA3CF01CEA207015BE969C04502CF174E173D07B85E38FD022FA39F02A669929EA4BDB841ACC4D966015E437BF42E2A500190F11ECC75BF91164E5A3859701E364A227F1DDD2CF00E812C73137ABF69DC2BBD9F90DE4F807F0BE06705FF9240963F066D738DC745F209E13F01C9E70099FF8CC057A4F755D1F3AA8C7A55F4BC2AF201E513F403E33A457A15E6682A5BA8A977D3426396E0B3545E6F97CABD8FFB99F3B89F75BE22F82B8293CE38E98CC7058F0BBE52E04E81250F72EFBD823FEE419137187F176D4605BC025EBD913E449FA6275043FA906BC822E5F3CABF2B75EA2C75BEBA5DB5D5BF53B76A25EDFDDA1DDA87B58F6A5FD47EACFD5CF37185C61FBEE719A8EB517996FE65F0323C46FFCEDC09F860D0027CB9660FE055411B70835604BC3972B59F9F501836A9D7FA559C169A7CA3C90FC8FA547C02F2CEBF467EFB10E6DF7603AAF8D40246F8250D9E35EAB1826F198F23B7962007BBE8E3DA43DA53DA73DA71AD4B59410F45F8B8E8A4CF4554EA522EA252849FA9B6524B2D1F59073CFA5AFA5880DB43A8DFDC5E475F90F6067A23CCED8D1416B99B69838C3B4C5F9327B5DBE893D21EA1E7C25841A9FA3D2CF7E7D9C0986FBAF1FDC0B74A04C6F3DCA7C3E0185E08CFF9A7CA857CDFD5278EE5AF19B93F3CE023217E73E283677C78EA0BC237119C33F578CEABC7FDB181B87726FD415A4B5AA241B467299FD5CE525EE087B1D4029ADDB3A9637E3BEDD8901A1AC8A466EFD821E4E676EAB2F3FC35B82DA9DC88B5139CDD8E95CAF4A776591B07F658E9629F63EFCB662C075D6BBB7B162DA48B0B968366C46D36DB3DF922B70B6959AF9D19C95917D0B23E27BB2F55B47A868673D690952FA68A593BDF6D1553D95CE102EA5F455D98A36875D943C3E81AC859DD5DB4C9CA59A90263DDC08A8CECC667AD55DC9ACD67ECFD8C77514F7737ADC35A5042FAFB3650FF063C67F68F168AD650B26723F5E1F45FD54FBDFDB46975D7665ABFFA12EADFD4D5B5B1EF12DAD195B30B238E85855377B6306C17AC1D3B7AF285622A9F06E659348E8595B303BA53C5140D15D2B693CB0E94CD5C9749B369DCECC6A7379B76EC82BDAB98DC922D8CA472AB52856C9AF2DBFA1DC04B18428A9B55D66036BF090EF6FC4C9BB27BF2999495EB4DE55383568606ADE20E44248F8941650B6371D89DAE90FDA3F9F46EC7CE67AFE6BE0CEDDE9A07D30258E3D843EBF60311FF3A56AF55DC6D67BC1596D727136105153A63ED4A8DE4AA74B68CEC76F3A0DF1E7140F1A25385DD5D76C6A20254F432C2133956A18028BB747678B7E508DA0F7FA58B82B25D3D4358252B711136A2170319EF71C392423AD0A6917C313B646D1E1DB6D6A5F2999C0C614AD6E67276BBCD26A84FE50781ADC9026C75B2456B4336EFE9F6949064B760886AD14EDB39213CADD46FA7F77AA804008E40AEC802CB38D6271E28D3FD69C7B2F25DA961A13A878773D9B4E439623F8EEEB78A457E212A7CCE42AB9C80B43A932DDACE2AC7DE2FCBEEC746F156202EC57A9CB556DE72C0CE74168B4E7660045D6B47B263A875566E78BD35BADF76C68A9447719CAAEC6E6B606470D0722EB4F3BC8B4FD7C9765479A71858ED8079C8F4EC385E67A1600D0DE44637678B63D9581532DCC9B8D5618CE1A82A2EEFC2D4D0E9D438A98C359472F656BB36A71C84678D0379AC77EFC4854167C6CA4FD4C5A9B1C5723841AB9DBDA36B1D7B64B8CBCE718A8EEB2A8FEBB60A69273B3CBED30D8DC416D5207595608589839169999174716247973D3CEA6407779FB60B5B363F5AEDF07642B9546673D9E2985EC99555A3EC1A5B1ACE5EC975C95D174392BB5BD825FB53FB10D87C061BC7CA02F54A924BF0F87E941419CED564D5C8AE5D965361797263B90CFA90E0E53AEC163666ACCEA7EDCC989E6E27B51F6492F7FE18B6B7C4A41720EEF12A97FBAB04ACCD43B0120F1BAF11121B6C34438541371544011CC4A5AA8CBB2385B3263702086D6BEC1C8EB6BE5471B7AC7C6B36032CEF36CCD860E50781BACBF588812D7B112E54DFAE542E37904AEFA5ADA96CB142206DF3855DB633B4269BC74190436539FDF190EC1DEDB79C7DD9B45548E20CB51C8897D7C526DB799C9C5C38733498C92E5A98CCE472DEA92BE8266BC8C6316915F616ED61E1F42193BD73A5CFB673B4F6D2EC30566DA586A817C2CEA847F0CAFA52D84574D18835627129D88AEDD483993D03D00C0D597058BA33376823C9760F117BAE4A0DD8C5A23D443D5DCEE870D1AE2CBA5226719ED1407F1A109909632C605EB1742BA76B8593C50E1FF538A75D7C122BCC0EE6A92F3782A4A91EF6C931878EE81A5372B1B5C75215BDF95DD9C111671C736DCE1E48E5B2578F636EB2767925C1B5D22E6485288C25565F95B6A432F01EA5CCFED557159D544F7E974D72B671714D0BE99D188223E76457588E90975A8E3DE132B42A5B1C4A0DBBC7F8808BF7E72C6B18736CB287C7C79D520EF5762F71A3E0A553F9C64643EC93F1B738F038DC1398DE1E99D8D13BBAD51A28E7E929BDFDC3563A9BCAB99B88BC75799B451CB7A99A0CF088E35E162DC62A21C958DDB61B723EEDE434F306B39D65A592ADB8143283215C8468EEB39CA2275CB61F91AFA05D483AC7BBC4AD761C1BB35AC57174D7885340D38950E3BE0A2C9976A134BDA845DC76AEEEDFD16DA5C5C58E17AD2ACDBDB0725C6F95BE180BEE2B3AB4D6490DEFCEA60B95C2954D0DE6ED4291596CFF2A7B249F29BC4DA1E8B6C4FB6E89AA4683C6C5E66DC68EBB887892A7D45D293EF6F03B282A87E8EDB4BC6DBF9703056F07A3EC4DE4551849A7D2E59EE928D95C0660957B4D2CB8675E672EC7E75D8137948BB857B835B9D460011BC56DCBBF8A9653CDBB8611975D0FC53EB71C0B97DCD557629D1593DD078E42720D0A5A81DC44E33253A0F4AA1194BDBCABB16B77CA2954EEB25EA616CA27B69BC98509195CF0B2AE401B87F98EC658B99461CDE932EAD972A1554CBA4B134B10C9EA23115F7DA9339371B7A5D76DE5F1F138EE93944778F778EF46EE11BDA3DE8620EF1AE45E07BCA70E5473EEC965518C5D232867ED2ACAEAD7597C83A1BCD7CA7D86ECE11DABAFE284CB621EB4455449006CD755397758B7FB98413D728422EE4CACCEEFCBE251861F1569AF353A90D961ED637CC8C679E7E17D7616D07B3A2DA69CA21718EE01E81C6098DF86BA88E61269D66183E13906D5A07237E17FEFC5D54E1E7989AF0FEE35C0B1061DDE82AE63CB279547B915D72320EED55E8F91B9AA9AD9A8709D8E931AA5CCA81C16B89897A7EEB7D223C8DCD1A45BAB07B9208CBA079777F7E35072E8D7A486B2A02E424A429E7DDA93B7AEF4A86AF622704820B0F033A38F7037C0537F96F294A44D847B19D9E03894169C8C4DD44DF349E1B701357DD44317D25AFE3D49631746DA90C0C510B20E5A0B3A5CF956AFDD867616F11F326613FFA1C015C47FE61045BB6586BD9073A0699848DB4ED490A5214AC1228BCEA63DE05AF2AD4A227366F7263A7EDBFA87DA3B6E3B70F6DC19E48B2B8AA9C549F1038946998C3050FD7155894484DB69C47DC02311BDA1AE5BA90BB98DE93629B759E933D0E38B533D31663248315869185ADD01B5EE809F54B5B9D920A52E1B2DFDC81FA7BAD249832741EB8760E99089BED24FF097C735B101CD4D3A0CA82BBDA61B6A735DE9B04E4C1D86BD111F507981546368D1D2D168E91E7484E29A122DFD215AFA53B4F41F903023B20CD34F54772880392126F028AC696E6E8622136291E64971BDAE745F8BDF34A387A6D41D6A680E19A66AAAFCC3D3C61513DD585D8B1FE241F190DFC0643C024A8206B1E0FDCDB290C321C35757BAB3C5DFE207C1FA61800AFF61B92A26981B8CFB4C6FAE088B1EAEFC8D18BA5A1DAAF222593F23CDB0C968894402AA1F2E3B1C241F8808742CD749332311899869B28BA2A5173040651FF923AA3E05BC48F4502FE4248A0497B4F86B0DACE9580B3E26FFA83A1113F07D8B5FFC753182DFE28F6886C269202374360BD661E4E721052FB4B01B6431FC8517B401585177A8257AE87278C11387B49FD85775AE8607EA4A0FD6951E9635EA3C498B9FE31C3D9495B478D88C6BCC33CD15462322664A701FAD2B7D5DFEDE59577A1286D6959E11FEB36062C188297B0C9F665570881D968CC2909754BD4917BC09DE6CE2E5959EE57FF3587A81ED75878BE5ACEB1E767B73002195C4F23A5E02E6D3EB0E8D18B2C291A01E67873DC9EE6C9EA472EA61DDAE6109A3B679ACA1CD6A3945EFACDB0055B21A8EB7CF500326B24933E1661588DA0C44764FD66FA8D361C374F24F52683AF982CA74C266AAC7165365D3D593817608ADD7A8F52C554F1C1850F0AA0187BCD484F53499938C00E3D16DA6D9D4D404541CF26893F9D5ABB76F99B2F8959BCC2FAED8716DF4A5E0793EFEDA9AE16D76AF35BD36E5B52B35BDEE00DC513A04A489919B541DB9A6327A44D5831A22CDF89DAADE0C91758CDFAFEAD86E843A0120588AC14A0607242887DC1D7E88394D26F99B236EC632F33EE4107245CC3E1641A722896B904FF5FB035324C322801191E1040A51406D62198000B628027DD444CDC018B59971382680CD4C7559639202F7C2C10B144599345DEA62B364E34B484D76DC58654876AD092D3B96BDAB22A5547815BA9B0CC62645B7F94C5EA8C90B3579A1262FD4E4859ABC50469B7C0904D354BC7F263D9D7FF7BB598D6DC5E974A19DAF3CE2E0D8C58548819CFB9DB93A85C2E39F43E4BB42384E14AAABBCDE88FFB763F1F8C2050B1712CD5568F6C28E5DE79E9B5A989A6FA597EE9ABF38BD243D7F6947477AFEC273DA5303A9A5E764DAAD73894298A33DB980FF10AD55686AF2C2D59B2BAF7CDABC9704CBF9AB88303532B9D2C52FD572A9517E993489C7C42B3DF1C5F2AF69CCF2D7B29A140AF68E6EB686205FB4CCF6CA749D0A2D3AF5DA9ADC8CA7D7421257493B3F981BE577849972E7AA912C3FFA98EDE794355CAAD0FA53EFCFFDC5914CD64EBAEFD2A0C93BBFDDE75ACBA930FAB3FC1A935F5579AFEF6C2700CDED9E6A53F1BEB798526871F9A66A0D242B2F11CA6F3631859D1A5E572C0EBB37B732BF6EE23BEEFAD3BD0A27C26EAFC135BDF224C55F1E8E8031F6A15A02059E3CA69505C63E8F94B5546EDB445FC6E7B96FFDEA1F390C47F0C94D707619E357E496D3162FBF776F8B9703BFD875755BDC7BAC5E9EB746F0E09D6B8BF78D0CC03A5CB936DB7BADFCF20124DB92F49273DA3B162DB6162CED98357132F7A65E66C0D0B1FFF6BFAFB39BFFB2CD4FEFA8B2FF47F9FF4038CDCF8B3BC652B8663ADDB95C6F2A9B777F7F6059F29A867FDE3A133A269D5609B9DF916E72FF0781717CF6DB82D3F0F987BF17BB6D27D1B231FF7FC2328DFFC1E216DCEC7600AEC6BDB01F37BF8DB8FBED901BE01AF77F5DA0477DBF7A93BC6F7D8CD5B9C2A3F8B753A7FCB708F2BD5B055A53B8F5ADC1BD33871B5E0F6E8EBBE4DB84843B228FDA8CDE14B805F4A708B771F4E63D0D5FF47D54BE61D20FBE2337D7C1D368BA4A641654FE2CA601F9DEFA54F147176486F087EFAC452A789A678EE91B96F947B1DA94C855EDE76F5796E773EFB069B163789C9D7C971E0255AC48ED052EF75CD8618ED1B1051F07FDD5B1EDB88B2FA87C784EFED6668FD8CAB279D8941B63D9DBCF95A40C24731267D6B141EED33CBA4BFA47C5F241DA4DFCFF594CE4C5E9183E715A083B16127F856C9EF8A8AAC78D54462CE098EEAD789320C5736EF4F4653DBBCBEBCEFF4DF62F13BFF7C9B342064F2869488C8DCD5FF2F762F1F7F8B1A77AFD549F2F95319DFC9D00D13C002B46E189771AF77FF5A7CFFD7EFDEF57BCA3E4FFFFF97FF0E73F01866FE86C00480000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5548 | DSGFO1.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSGFO1.lnk | binary | |
MD5:C0FAC6C32FBA7EF1D308D335B63E75A2 | SHA256:E3F7F57517D8189778DA51D572BCC5AF0688B620EDF760F98730938AB38FAAAF | |||
| 5548 | DSGFO1.exe | C:\Users\admin\DSGFO1.exe | executable | |
MD5:109631AA606A58E7BB394BE02FAF01DC | SHA256:1A173A01A41C2E0F8F72C08F1A6F567227EF1F92F445B2E840B1B433D4BE7C0C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2104 | svchost.exe | GET | 200 | 23.216.77.21:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2104 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 23.216.77.21:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5548 | DSGFO1.exe | 82.26.74.114:1337 | — | Virgin Media Limited | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5548 | DSGFO1.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Initial Packet |
5548 | DSGFO1.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Initial Packet |