File name:

Extreme Injector v3.7.3.exe

Full analysis: https://app.any.run/tasks/73400547-20a7-4181-a290-2db09816036d
Verdict: Malicious activity
Threats:

njRAT is a remote access trojan. It is one of the most widely accessible RATs on the market that features an abundance of educational information. Interested attackers can even find tutorials on YouTube. This allows it to become one of the most popular RATs in the world.

Analysis date: July 05, 2023, 19:01:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
njrat
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C239929068F7078F664C67D4EE295058

SHA1:

F879857ED6CB591D341ACE73B1A32CCA2FEC1877

SHA256:

233ABE1029C0EBD8395C5CB62C0707294F02950D43D416FC4BCFCF97488384EB

SSDEEP:

49152:TQCoCHblagLunu0iKs5jYcgL/vm6RXJZH:cCoCHb8gZ9V5jY7RX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • server.exe (PID: 924)
      • Server.exe (PID: 1836)
      • Extreme Injector v3.exe (PID: 3456)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector v3.exe (PID: 2680)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector v3.exe (PID: 3992)
      • Extreme Injector v3.exe (PID: 2696)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector v3.exe (PID: 2636)
      • Extreme Injector v3.exe (PID: 1680)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3616)
      • Extreme Injector v3.exe (PID: 3296)
      • Extreme Injector v3.exe (PID: 3204)
      • Extreme Injector v3.exe (PID: 3944)
      • Extreme Injector v3.exe (PID: 2300)
      • Extreme Injector v3.exe (PID: 2520)
      • Extreme Injector v3.exe (PID: 2512)
      • Extreme Injector v3.exe (PID: 3600)
      • Extreme Injector v3.exe (PID: 1232)
      • Extreme Injector v3.exe (PID: 2816)
      • Extreme Injector v3.exe (PID: 3264)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 3116)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector v3.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 1232)
    • Creates a writable file the system directory

      • server.exe (PID: 924)
    • Create files in the Startup directory

      • server.exe (PID: 924)
    • NJRAT detected by memory dumps

      • server.exe (PID: 924)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Server.exe (PID: 1836)
      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 3456)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector.exe (PID: 2780)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector v3.exe (PID: 2680)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector v3.exe (PID: 3992)
    • Executable content was dropped or overwritten

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Server.exe (PID: 1836)
      • server.exe (PID: 924)
    • Starts itself from another location

      • Server.exe (PID: 1836)
    • Application launched itself

      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 3456)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector.exe (PID: 1276)
      • Extreme Injector.exe (PID: 1476)
      • Extreme Injector.exe (PID: 452)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector.exe (PID: 2236)
      • Extreme Injector.exe (PID: 2916)
      • Extreme Injector.exe (PID: 2644)
      • Extreme Injector.exe (PID: 3992)
      • Extreme Injector.exe (PID: 568)
      • Extreme Injector.exe (PID: 2508)
      • Extreme Injector.exe (PID: 2084)
      • Extreme Injector.exe (PID: 1168)
      • Extreme Injector.exe (PID: 2620)
      • Extreme Injector.exe (PID: 2096)
      • Extreme Injector.exe (PID: 1364)
      • Extreme Injector.exe (PID: 3172)
      • Extreme Injector.exe (PID: 872)
      • Extreme Injector.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3020)
      • Extreme Injector.exe (PID: 3532)
      • Extreme Injector.exe (PID: 3004)
      • Extreme Injector.exe (PID: 3524)
      • Extreme Injector.exe (PID: 3108)
      • Extreme Injector.exe (PID: 744)
      • Extreme Injector.exe (PID: 3552)
      • Extreme Injector.exe (PID: 3772)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector.exe (PID: 3932)
      • Extreme Injector.exe (PID: 3960)
      • Extreme Injector.exe (PID: 2984)
      • Extreme Injector v3.exe (PID: 2680)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector.exe (PID: 3192)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector.exe (PID: 2880)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector.exe (PID: 3256)
      • Extreme Injector.exe (PID: 3908)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector.exe (PID: 3932)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector.exe (PID: 1836)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 908)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector.exe (PID: 3316)
      • Extreme Injector.exe (PID: 240)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector.exe (PID: 3764)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector.exe (PID: 2936)
      • Extreme Injector.exe (PID: 2792)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 1100)
      • Extreme Injector.exe (PID: 3400)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector.exe (PID: 3556)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector.exe (PID: 1048)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector.exe (PID: 3224)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector.exe (PID: 2056)
      • Extreme Injector.exe (PID: 3236)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector.exe (PID: 3752)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector.exe (PID: 2616)
      • Extreme Injector.exe (PID: 2180)
      • Extreme Injector.exe (PID: 3800)
      • Extreme Injector.exe (PID: 3132)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector.exe (PID: 2636)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector.exe (PID: 3492)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 2872)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector.exe (PID: 3984)
      • Extreme Injector.exe (PID: 3876)
      • Extreme Injector.exe (PID: 3676)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector.exe (PID: 3092)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector.exe (PID: 3572)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector.exe (PID: 2576)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector.exe (PID: 2300)
      • Extreme Injector.exe (PID: 1388)
      • Extreme Injector.exe (PID: 448)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 3340)
      • Extreme Injector.exe (PID: 3860)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector.exe (PID: 3024)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector.exe (PID: 1212)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3292)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector v3.exe (PID: 3992)
      • Extreme Injector v3.exe (PID: 2636)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector.exe (PID: 3588)
      • Extreme Injector.exe (PID: 3956)
      • Extreme Injector v3.exe (PID: 1680)
      • Extreme Injector.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 2696)
      • Extreme Injector.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 3296)
      • Extreme Injector.exe (PID: 3980)
      • Extreme Injector v3.exe (PID: 2300)
      • Extreme Injector.exe (PID: 3700)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3204)
      • Extreme Injector.exe (PID: 1012)
      • Extreme Injector.exe (PID: 2988)
      • Extreme Injector v3.exe (PID: 3944)
      • Extreme Injector v3.exe (PID: 3616)
      • Extreme Injector.exe (PID: 3032)
      • Extreme Injector v3.exe (PID: 3600)
      • Extreme Injector.exe (PID: 3804)
      • Extreme Injector v3.exe (PID: 1232)
      • Extreme Injector v3.exe (PID: 2520)
      • Extreme Injector.exe (PID: 3492)
      • Extreme Injector v3.exe (PID: 2512)
      • Extreme Injector.exe (PID: 1956)
      • Extreme Injector v3.exe (PID: 3264)
      • Extreme Injector.exe (PID: 3120)
      • Extreme Injector.exe (PID: 3316)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 2816)
      • Extreme Injector.exe (PID: 1212)
      • Extreme Injector v3.exe (PID: 3116)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector.exe (PID: 868)
      • Extreme Injector.exe (PID: 2708)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector.exe (PID: 3552)
      • Extreme Injector v3.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 1232)
      • Extreme Injector v3.exe (PID: 3068)
      • Extreme Injector v3.exe (PID: 4092)
      • Extreme Injector.exe (PID: 2628)
      • Extreme Injector.exe (PID: 3900)
      • Extreme Injector.exe (PID: 4064)
      • Extreme Injector.exe (PID: 2120)
      • Extreme Injector.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector.exe (PID: 3312)
      • Extreme Injector v3.exe (PID: 1364)
      • Extreme Injector.exe (PID: 452)
      • Extreme Injector v3.exe (PID: 3344)
      • Extreme Injector v3.exe (PID: 752)
      • Extreme Injector.exe (PID: 3740)
    • Checks for external IP

      • Extreme Injector.exe (PID: 2780)
  • INFO

    • Checks supported languages

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Server.exe (PID: 1836)
      • Extreme Injector v3.exe (PID: 3456)
      • server.exe (PID: 924)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector.exe (PID: 1276)
      • Extreme Injector.exe (PID: 2084)
      • Extreme Injector.exe (PID: 3992)
      • Extreme Injector.exe (PID: 1476)
      • Extreme Injector.exe (PID: 2916)
      • Extreme Injector.exe (PID: 1168)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector.exe (PID: 2644)
      • Extreme Injector.exe (PID: 3020)
      • Extreme Injector.exe (PID: 568)
      • Extreme Injector.exe (PID: 452)
      • Extreme Injector.exe (PID: 3532)
      • Extreme Injector.exe (PID: 3004)
      • Extreme Injector.exe (PID: 1364)
      • Extreme Injector.exe (PID: 744)
      • Extreme Injector.exe (PID: 2236)
      • Extreme Injector.exe (PID: 2508)
      • Extreme Injector.exe (PID: 2620)
      • Extreme Injector.exe (PID: 2096)
      • Extreme Injector.exe (PID: 2608)
      • Extreme Injector.exe (PID: 872)
      • Extreme Injector.exe (PID: 3524)
      • Extreme Injector.exe (PID: 3172)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector.exe (PID: 3108)
      • Extreme Injector.exe (PID: 3552)
      • Extreme Injector.exe (PID: 3772)
      • Extreme Injector.exe (PID: 3192)
      • Extreme Injector.exe (PID: 2640)
      • Extreme Injector.exe (PID: 1680)
      • Extreme Injector.exe (PID: 1756)
      • Extreme Injector.exe (PID: 2708)
      • Extreme Injector.exe (PID: 3724)
      • Extreme Injector.exe (PID: 1628)
      • Extreme Injector.exe (PID: 1712)
      • Extreme Injector.exe (PID: 768)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 3972)
      • Extreme Injector.exe (PID: 3204)
      • Extreme Injector.exe (PID: 1560)
      • Extreme Injector.exe (PID: 596)
      • Extreme Injector.exe (PID: 3236)
      • Extreme Injector.exe (PID: 3776)
      • Extreme Injector.exe (PID: 796)
      • Extreme Injector.exe (PID: 3224)
      • Extreme Injector.exe (PID: 2780)
      • Extreme Injector.exe (PID: 3700)
      • Extreme Injector.exe (PID: 2636)
      • Extreme Injector.exe (PID: 1232)
      • Extreme Injector.exe (PID: 2140)
      • Extreme Injector.exe (PID: 3568)
      • Extreme Injector.exe (PID: 3380)
      • Extreme Injector.exe (PID: 3416)
      • Extreme Injector.exe (PID: 3960)
      • Extreme Injector.exe (PID: 2984)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector.exe (PID: 1016)
      • Extreme Injector.exe (PID: 744)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector.exe (PID: 3192)
      • Extreme Injector.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector.exe (PID: 3908)
      • Extreme Injector.exe (PID: 3256)
      • Extreme Injector.exe (PID: 2988)
      • Extreme Injector.exe (PID: 2432)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector.exe (PID: 3072)
      • Extreme Injector.exe (PID: 3932)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector.exe (PID: 3108)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector.exe (PID: 908)
      • Extreme Injector.exe (PID: 2432)
      • Extreme Injector.exe (PID: 1176)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector.exe (PID: 1388)
      • Extreme Injector.exe (PID: 2140)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector.exe (PID: 1836)
      • Extreme Injector.exe (PID: 240)
      • Extreme Injector.exe (PID: 3316)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector.exe (PID: 3696)
      • Extreme Injector.exe (PID: 3764)
      • Extreme Injector.exe (PID: 1640)
      • Extreme Injector.exe (PID: 2936)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector.exe (PID: 2480)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector.exe (PID: 1944)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 1100)
      • Extreme Injector.exe (PID: 2792)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector.exe (PID: 3248)
      • Extreme Injector.exe (PID: 3564)
      • Extreme Injector.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector.exe (PID: 3532)
      • Extreme Injector.exe (PID: 3400)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector.exe (PID: 3556)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector.exe (PID: 1092)
      • Extreme Injector.exe (PID: 3732)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 2456)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector.exe (PID: 2708)
      • Extreme Injector.exe (PID: 1048)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector.exe (PID: 3224)
      • Extreme Injector.exe (PID: 1228)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector.exe (PID: 148)
      • Extreme Injector.exe (PID: 2056)
      • Extreme Injector.exe (PID: 3120)
      • Extreme Injector.exe (PID: 3236)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector.exe (PID: 2612)
      • Extreme Injector.exe (PID: 3752)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector.exe (PID: 2272)
      • Extreme Injector.exe (PID: 2616)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector.exe (PID: 3800)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector.exe (PID: 4092)
      • Extreme Injector.exe (PID: 3592)
      • Extreme Injector.exe (PID: 1648)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector.exe (PID: 2180)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector.exe (PID: 3132)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector.exe (PID: 3736)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 2636)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector.exe (PID: 2964)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector.exe (PID: 124)
      • Extreme Injector.exe (PID: 2872)
      • Extreme Injector.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 3492)
      • Extreme Injector.exe (PID: 2104)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector.exe (PID: 3876)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 2936)
      • Extreme Injector.exe (PID: 3984)
      • Extreme Injector.exe (PID: 2880)
      • Extreme Injector.exe (PID: 3456)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector.exe (PID: 3704)
      • Extreme Injector.exe (PID: 1644)
      • Extreme Injector.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector.exe (PID: 3092)
      • Extreme Injector.exe (PID: 3676)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector.exe (PID: 3572)
      • Extreme Injector.exe (PID: 372)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector.exe (PID: 2576)
      • Extreme Injector.exe (PID: 844)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector.exe (PID: 3592)
      • Extreme Injector.exe (PID: 1388)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector.exe (PID: 2324)
      • Extreme Injector.exe (PID: 3388)
      • Extreme Injector.exe (PID: 2300)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 3068)
      • Extreme Injector.exe (PID: 448)
      • Extreme Injector.exe (PID: 2028)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector.exe (PID: 3860)
      • Extreme Injector.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector.exe (PID: 3024)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3876)
      • Extreme Injector.exe (PID: 4088)
      • Extreme Injector.exe (PID: 3292)
      • Extreme Injector.exe (PID: 3584)
      • Extreme Injector.exe (PID: 1212)
      • Extreme Injector v3.exe (PID: 3992)
      • Extreme Injector.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 2696)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector.exe (PID: 2884)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector.exe (PID: 940)
    • Reads the machine GUID from the registry

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Server.exe (PID: 1836)
      • server.exe (PID: 924)
      • Extreme Injector.exe (PID: 452)
      • Extreme Injector.exe (PID: 2236)
      • Extreme Injector.exe (PID: 2916)
      • Extreme Injector.exe (PID: 2084)
      • Extreme Injector.exe (PID: 3992)
      • Extreme Injector.exe (PID: 1276)
      • Extreme Injector.exe (PID: 568)
      • Extreme Injector.exe (PID: 1476)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector.exe (PID: 2620)
      • Extreme Injector.exe (PID: 2508)
      • Extreme Injector.exe (PID: 1168)
      • Extreme Injector.exe (PID: 2644)
      • Extreme Injector.exe (PID: 3020)
      • Extreme Injector.exe (PID: 872)
      • Extreme Injector.exe (PID: 1364)
      • Extreme Injector.exe (PID: 2096)
      • Extreme Injector.exe (PID: 3172)
      • Extreme Injector.exe (PID: 3532)
      • Extreme Injector.exe (PID: 3004)
      • Extreme Injector.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3524)
      • Extreme Injector.exe (PID: 744)
      • Extreme Injector.exe (PID: 3108)
      • Extreme Injector.exe (PID: 2780)
      • Extreme Injector.exe (PID: 3960)
      • Extreme Injector.exe (PID: 3552)
      • Extreme Injector.exe (PID: 3772)
      • Extreme Injector.exe (PID: 3192)
      • Extreme Injector.exe (PID: 2984)
      • Extreme Injector.exe (PID: 2880)
      • Extreme Injector.exe (PID: 3256)
      • Extreme Injector.exe (PID: 3908)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector.exe (PID: 3932)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector.exe (PID: 908)
      • Extreme Injector.exe (PID: 1836)
      • Extreme Injector.exe (PID: 3316)
      • Extreme Injector.exe (PID: 240)
      • Extreme Injector.exe (PID: 2936)
      • Extreme Injector.exe (PID: 3764)
      • Extreme Injector.exe (PID: 2792)
      • Extreme Injector.exe (PID: 1100)
      • Extreme Injector.exe (PID: 3400)
      • Extreme Injector.exe (PID: 2100)
      • Extreme Injector.exe (PID: 3556)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 3224)
      • Extreme Injector.exe (PID: 1048)
      • Extreme Injector.exe (PID: 2056)
      • Extreme Injector.exe (PID: 3752)
      • Extreme Injector.exe (PID: 3236)
      • Extreme Injector.exe (PID: 2616)
      • Extreme Injector.exe (PID: 3800)
      • Extreme Injector.exe (PID: 2180)
      • Extreme Injector.exe (PID: 3132)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 2636)
      • Extreme Injector.exe (PID: 2872)
      • Extreme Injector.exe (PID: 3492)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector.exe (PID: 3984)
      • Extreme Injector.exe (PID: 3876)
      • Extreme Injector.exe (PID: 3676)
      • Extreme Injector.exe (PID: 3092)
      • Extreme Injector.exe (PID: 2576)
      • Extreme Injector.exe (PID: 3572)
      • Extreme Injector.exe (PID: 1388)
      • Extreme Injector.exe (PID: 2300)
      • Extreme Injector.exe (PID: 448)
      • Extreme Injector.exe (PID: 3340)
      • Extreme Injector.exe (PID: 3860)
      • Extreme Injector.exe (PID: 3024)
      • Extreme Injector.exe (PID: 3292)
      • Extreme Injector.exe (PID: 1212)
      • Extreme Injector.exe (PID: 3976)
    • Reads the computer name

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Extreme Injector v3.exe (PID: 3456)
      • Server.exe (PID: 1836)
      • server.exe (PID: 924)
      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector.exe (PID: 1476)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector.exe (PID: 3992)
      • Extreme Injector.exe (PID: 2916)
      • Extreme Injector.exe (PID: 2644)
      • Extreme Injector.exe (PID: 2236)
      • Extreme Injector.exe (PID: 1168)
      • Extreme Injector.exe (PID: 2620)
      • Extreme Injector.exe (PID: 452)
      • Extreme Injector.exe (PID: 1276)
      • Extreme Injector.exe (PID: 568)
      • Extreme Injector.exe (PID: 2084)
      • Extreme Injector.exe (PID: 3532)
      • Extreme Injector.exe (PID: 1364)
      • Extreme Injector.exe (PID: 872)
      • Extreme Injector.exe (PID: 2096)
      • Extreme Injector.exe (PID: 744)
      • Extreme Injector.exe (PID: 3524)
      • Extreme Injector.exe (PID: 3020)
      • Extreme Injector.exe (PID: 2508)
      • Extreme Injector.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3172)
      • Extreme Injector.exe (PID: 3004)
      • Extreme Injector.exe (PID: 3108)
      • Extreme Injector.exe (PID: 3552)
      • Extreme Injector.exe (PID: 2780)
      • Extreme Injector.exe (PID: 3772)
      • Extreme Injector.exe (PID: 3960)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector.exe (PID: 2984)
      • Extreme Injector.exe (PID: 3192)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector.exe (PID: 2880)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector.exe (PID: 3256)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector.exe (PID: 3908)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector.exe (PID: 3932)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector.exe (PID: 908)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 1836)
      • Extreme Injector.exe (PID: 3316)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector.exe (PID: 240)
      • Extreme Injector.exe (PID: 3764)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector.exe (PID: 2936)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector.exe (PID: 2792)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 1100)
      • Extreme Injector.exe (PID: 3400)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector.exe (PID: 3556)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector.exe (PID: 1048)
      • Extreme Injector.exe (PID: 3224)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector.exe (PID: 3236)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector.exe (PID: 3752)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector.exe (PID: 2616)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector.exe (PID: 3800)
      • Extreme Injector.exe (PID: 2180)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector.exe (PID: 3132)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector.exe (PID: 2636)
      • Extreme Injector.exe (PID: 2872)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 3492)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 3984)
      • Extreme Injector.exe (PID: 3876)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector.exe (PID: 3676)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector.exe (PID: 3572)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector.exe (PID: 3092)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector.exe (PID: 2576)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector.exe (PID: 1388)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector.exe (PID: 2300)
      • Extreme Injector.exe (PID: 448)
      • Extreme Injector.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector.exe (PID: 3860)
      • Extreme Injector.exe (PID: 3024)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3292)
      • Extreme Injector.exe (PID: 1212)
      • Extreme Injector v3.exe (PID: 3992)
      • Extreme Injector.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector.exe (PID: 3088)
    • The process checks LSA protection

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Extreme Injector v3.exe (PID: 3456)
      • Server.exe (PID: 1836)
      • server.exe (PID: 924)
      • netsh.exe (PID: 2888)
      • netsh.exe (PID: 3220)
      • netsh.exe (PID: 3652)
      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector.exe (PID: 2916)
      • Extreme Injector.exe (PID: 2236)
      • Extreme Injector.exe (PID: 3992)
      • Extreme Injector.exe (PID: 2084)
      • Extreme Injector.exe (PID: 452)
      • Extreme Injector.exe (PID: 1276)
      • Extreme Injector.exe (PID: 568)
      • Extreme Injector.exe (PID: 1476)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector.exe (PID: 2508)
      • Extreme Injector.exe (PID: 2620)
      • Extreme Injector.exe (PID: 3020)
      • Extreme Injector.exe (PID: 2644)
      • Extreme Injector.exe (PID: 1168)
      • Extreme Injector.exe (PID: 1364)
      • Extreme Injector.exe (PID: 872)
      • Extreme Injector.exe (PID: 2096)
      • Extreme Injector.exe (PID: 3172)
      • Extreme Injector.exe (PID: 3004)
      • Extreme Injector.exe (PID: 3532)
      • Extreme Injector.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3524)
      • Extreme Injector.exe (PID: 744)
      • Extreme Injector.exe (PID: 3108)
      • Extreme Injector.exe (PID: 2780)
      • Extreme Injector.exe (PID: 3552)
      • Extreme Injector.exe (PID: 3772)
      • Extreme Injector.exe (PID: 3960)
      • Extreme Injector v3.exe (PID: 2680)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector.exe (PID: 2984)
      • Extreme Injector.exe (PID: 3192)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector.exe (PID: 2880)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector.exe (PID: 3256)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector.exe (PID: 3908)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector.exe (PID: 3088)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector.exe (PID: 3932)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector.exe (PID: 908)
      • Extreme Injector.exe (PID: 1836)
      • Extreme Injector.exe (PID: 3316)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector.exe (PID: 240)
      • Extreme Injector.exe (PID: 2936)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector.exe (PID: 3764)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 2792)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector.exe (PID: 1100)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector.exe (PID: 3400)
      • Extreme Injector.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector.exe (PID: 3556)
      • Extreme Injector.exe (PID: 2444)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector.exe (PID: 1048)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector.exe (PID: 3224)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector.exe (PID: 3236)
      • Extreme Injector.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector.exe (PID: 2616)
      • Extreme Injector.exe (PID: 3752)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector.exe (PID: 3800)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector.exe (PID: 2180)
      • Extreme Injector.exe (PID: 3132)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector.exe (PID: 2148)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector.exe (PID: 2636)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector.exe (PID: 2872)
      • Extreme Injector.exe (PID: 3492)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector.exe (PID: 2912)
      • Extreme Injector.exe (PID: 3984)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector.exe (PID: 3876)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector.exe (PID: 3676)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector.exe (PID: 3092)
      • Extreme Injector.exe (PID: 3572)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector.exe (PID: 2576)
      • Extreme Injector.exe (PID: 1388)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector.exe (PID: 2300)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector.exe (PID: 448)
      • Extreme Injector.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector.exe (PID: 3860)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector.exe (PID: 3292)
      • Extreme Injector.exe (PID: 3024)
      • Extreme Injector v3.exe (PID: 3992)
      • Extreme Injector.exe (PID: 1212)
      • Extreme Injector.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector v3.exe (PID: 2696)
    • Create files in a temporary directory

      • Extreme Injector v3.7.3.exe (PID: 3440)
      • Extreme Injector v3.exe (PID: 3456)
      • Server.exe (PID: 1836)
      • server.exe (PID: 924)
      • Extreme Injector v3.exe (PID: 3268)
      • Extreme Injector v3.exe (PID: 952)
      • Extreme Injector v3.exe (PID: 2244)
      • Extreme Injector v3.exe (PID: 2788)
      • Extreme Injector v3.exe (PID: 2056)
      • Extreme Injector v3.exe (PID: 3340)
      • Extreme Injector v3.exe (PID: 3044)
      • Extreme Injector v3.exe (PID: 2356)
      • Extreme Injector v3.exe (PID: 3444)
      • Extreme Injector v3.exe (PID: 188)
      • Extreme Injector v3.exe (PID: 1852)
      • Extreme Injector v3.exe (PID: 3072)
      • Extreme Injector v3.exe (PID: 3768)
      • Extreme Injector v3.exe (PID: 3472)
      • Extreme Injector v3.exe (PID: 2284)
      • Extreme Injector v3.exe (PID: 4088)
      • Extreme Injector v3.exe (PID: 672)
      • Extreme Injector v3.exe (PID: 3604)
      • Extreme Injector v3.exe (PID: 2900)
      • Extreme Injector v3.exe (PID: 2272)
      • Extreme Injector v3.exe (PID: 3968)
      • Extreme Injector v3.exe (PID: 2100)
      • Extreme Injector v3.exe (PID: 2088)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 2264)
      • Extreme Injector v3.exe (PID: 3384)
      • Extreme Injector v3.exe (PID: 3612)
      • Extreme Injector v3.exe (PID: 2680)
      • Extreme Injector v3.exe (PID: 4060)
      • Extreme Injector v3.exe (PID: 2864)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 2872)
      • Extreme Injector v3.exe (PID: 3972)
      • Extreme Injector v3.exe (PID: 1648)
      • Extreme Injector v3.exe (PID: 1832)
      • Extreme Injector v3.exe (PID: 4064)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 2504)
      • Extreme Injector v3.exe (PID: 2488)
      • Extreme Injector v3.exe (PID: 3032)
      • Extreme Injector v3.exe (PID: 1760)
      • Extreme Injector v3.exe (PID: 3940)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 2988)
      • Extreme Injector v3.exe (PID: 1176)
      • Extreme Injector v3.exe (PID: 3080)
      • Extreme Injector v3.exe (PID: 1492)
      • Extreme Injector v3.exe (PID: 3900)
      • Extreme Injector v3.exe (PID: 3308)
      • Extreme Injector v3.exe (PID: 3628)
      • Extreme Injector v3.exe (PID: 3060)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 2996)
      • Extreme Injector v3.exe (PID: 4084)
      • Extreme Injector v3.exe (PID: 3696)
      • Extreme Injector v3.exe (PID: 1416)
      • Extreme Injector v3.exe (PID: 1172)
      • Extreme Injector v3.exe (PID: 1360)
      • Extreme Injector v3.exe (PID: 3588)
      • Extreme Injector v3.exe (PID: 4020)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 3976)
      • Extreme Injector v3.exe (PID: 268)
      • Extreme Injector v3.exe (PID: 3952)
      • Extreme Injector v3.exe (PID: 1476)
      • Extreme Injector v3.exe (PID: 1772)
      • Extreme Injector v3.exe (PID: 1956)
      • Extreme Injector v3.exe (PID: 116)
      • Extreme Injector v3.exe (PID: 2812)
      • Extreme Injector v3.exe (PID: 2776)
      • Extreme Injector v3.exe (PID: 2628)
      • Extreme Injector v3.exe (PID: 4080)
      • Extreme Injector v3.exe (PID: 1972)
      • Extreme Injector v3.exe (PID: 624)
      • Extreme Injector v3.exe (PID: 2608)
      • Extreme Injector v3.exe (PID: 3992)
      • Extreme Injector v3.exe (PID: 2324)
      • Extreme Injector v3.exe (PID: 2696)
    • Creates files or folders in the user directory

      • Server.exe (PID: 1836)
      • server.exe (PID: 924)
    • Creates files in the program directory

      • server.exe (PID: 924)
    • Reads Environment values

      • server.exe (PID: 924)
    • Checks proxy server information

      • Extreme Injector.exe (PID: 2780)
    • [YARA] Firewall manipulation strings were found

      • server.exe (PID: 924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

NjRat

(PID) Process(924) server.exe
C2127.0.0.1
Ports2342
BotnetHacKed
Options
Auto-run registry keySoftware\Microsoft\Windows\CurrentVersion\Run\fe12c62687d67faf2b33e4f203c44897
Splitter|'|'|
Version0.7d
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.3)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

OriginalFileName: Extreme Injector v3.exe
LegalCopyright: Copyright © 2019
ProductVersion: 3.7.3.0
FileVersion: 3.7.3.0
ProductName: Extreme Injector v3
FileDescription: Extreme Injector v3
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x0000
ProductVersionNumber: 3.7.3.0
FileVersionNumber: 3.7.3.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 1
EntryPoint: 0x1000
UninitializedDataSize: -
InitializedDataSize: 17408
CodeSize: 3266048
LinkerVersion: 1.73
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
TimeStamp: 2023:07:05 18:20:57+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 05-Jul-2023 18:20:57
Detected languages:
  • English - United States
FileDescription: Extreme Injector v3
ProductName: Extreme Injector v3
FileVersion: 3.7.3.0
ProductVersion: 3.7.3.0
LegalCopyright: Copyright © 2019
OriginalFilename: Extreme Injector v3.exe

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0080
Pages in file: 0x0001
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0010
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x0140
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 05-Jul-2023 18:20:57
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0031D5B6
0x0031D600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.23229
.idata
0x0031F000
0x000001FC
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.15362
.rsrc
0x00320000
0x000041BC
0x00004200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.74305

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.15976
712
UNKNOWN
UNKNOWN
RT_MANIFEST
2
4.74847
4264
UNKNOWN
UNKNOWN
RT_ICON
3
4.48683
9640
UNKNOWN
UNKNOWN
RT_ICON

Imports

Shlwapi.dll
kernel32.dll
msvcrt.dll
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
368
Monitored processes
324
Malicious processes
187
Suspicious processes
5

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start extreme injector v3.7.3.exe server.exe extreme injector v3.exe no specs #NJRAT server.exe netsh.exe no specs netsh.exe no specs netsh.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector.exe no specs extreme injector.exe no specs extreme injector v3.exe no specs extreme injector v3.7.3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exe" C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exeExtreme Injector v3.exe
User:
admin
Integrity Level:
HIGH
Exit code:
10
Modules
Images
c:\users\admin\appdata\local\temp\extreme injector v3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
124"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exe"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exeExtreme Injector.exe
User:
admin
Company:
Helpfeel Inc.
Integrity Level:
HIGH
Description:
Gyazo Setup
Exit code:
0
Version:
4.6.1.0
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\crypt32.dll
148"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exe"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exeExtreme Injector.exe
User:
admin
Company:
Helpfeel Inc.
Integrity Level:
HIGH
Description:
Gyazo Setup
Exit code:
0
Version:
4.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\extreme injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
148"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exe"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exeExtreme Injector.exe
User:
admin
Company:
Helpfeel Inc.
Integrity Level:
HIGH
Description:
Gyazo Setup
Exit code:
0
Version:
4.6.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gdi32.dll
188"C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exe" C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exeExtreme Injector v3.exe
User:
admin
Integrity Level:
HIGH
Exit code:
10
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\extreme injector v3.exe
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
240"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exe" C:\Users\admin\AppData\Local\Temp\Extreme Injector.exeExtreme Injector v3.exe
User:
admin
Company:
Helpfeel Inc.
Integrity Level:
HIGH
Description:
Gyazo Setup
Exit code:
0
Version:
4.6.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\gdi32.dll
268"C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exe" C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exeExtreme Injector v3.exe
User:
admin
Integrity Level:
HIGH
Exit code:
10
Modules
Images
c:\users\admin\appdata\local\temp\extreme injector v3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
268"C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exe" C:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exeExtreme Injector v3.exe
User:
admin
Integrity Level:
HIGH
Exit code:
10
Modules
Images
c:\users\admin\appdata\local\temp\extreme injector v3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msctf.dll
268"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exe" C:\Users\admin\AppData\Local\Temp\Extreme Injector.exeExtreme Injector v3.exe
User:
admin
Company:
Helpfeel Inc.
Integrity Level:
HIGH
Description:
Gyazo Setup
Exit code:
0
Version:
4.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\extreme injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
372"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exe"C:\Users\admin\AppData\Local\Temp\Extreme Injector.exeExtreme Injector.exe
User:
admin
Company:
Helpfeel Inc.
Integrity Level:
HIGH
Description:
Gyazo Setup
Exit code:
0
Version:
4.6.1.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\gdi32.dll
Total events
133 078
Read events
132 047
Write events
1 031
Delete events
0

Modification events

(PID) Process:(3440) Extreme Injector v3.7.3.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3440) Extreme Injector v3.7.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3440) Extreme Injector v3.7.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3440) Extreme Injector v3.7.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3440) Extreme Injector v3.7.3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1836) Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1836) Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1836) Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1836) Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2888) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
16
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3456Extreme Injector v3.exeC:\Users\admin\AppData\Local\Temp\Extreme Injector.exe
MD5:
SHA256:
3440Extreme Injector v3.7.3.exeC:\Users\admin\AppData\Local\Temp\Server.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
3440Extreme Injector v3.7.3.exeC:\Users\admin\AppData\Local\Temp\Extreme Injector v3.exeexecutable
MD5:5542D72132509AD32394BB8322DF27FD
SHA256:2349735F4CECD14C012D456A29C30FB27148527E1C027A6A9EFB6D69C8DE965A
924server.exeC:\Windows\system32\Windows Service.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
1836Server.exeC:\Users\admin\AppData\Roaming\apptext
MD5:C6BDBC9D86009CCF7E8DE878C9603213
SHA256:36A067FDFCEE95EB270F0B72E3B9E40D52C907D749FB9A8490D82F8EE56B29EB
1836Server.exeC:\Users\admin\server.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
924server.exeC:\Umbrella.flv.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
924server.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fe12c62687d67faf2b33e4f203c44897Windows Update.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
924server.exeC:\Program Files\Windows Service.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
924server.exeC:\Users\admin\Desktop\Windows Service.exeexecutable
MD5:114ACAD75CD4D734F7131C851FC7FD5F
SHA256:1A91B7FA1B8348700A8BD99599A7BD4B77509F19C81E01FB3D5414C71719EEC3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
6
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2780
Extreme Injector.exe
GET
200
173.231.16.76:80
http://api.ipify.org/?format=efd
US
text
15 b
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1076
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
820
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2780
Extreme Injector.exe
173.231.16.76:80
api.ipify.org
WEBNX
US
malicious

DNS requests

Domain
IP
Reputation
api.ipify.org
  • 173.231.16.76
  • 64.185.227.156
  • 104.237.62.211
shared

Threats

PID
Process
Class
Message
2780
Extreme Injector.exe
Potential Corporate Privacy Violation
ET POLICY External IP Lookup (ipify .org)
No debug info