File name:

MobaXterm_Personal_20.2.exe

Full analysis: https://app.any.run/tasks/cf145411-45aa-4ed9-b61a-e2b87f6dd6cb
Verdict: Malicious activity
Analysis date: September 08, 2020, 12:51:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

470D8E371CEFFF989C8B2F529E08C0E2

SHA1:

25AFDD7C90DCDF5FED3A1F08BAA7F32C5730B0DA

SHA256:

35CF6B84532443F2E0B5702ACA0158D089A1175C909E4D77FCDCED54ECD14513

SSDEEP:

393216:FEh4nEdzqSTb3LRAd45GdePqlxUkcb/+FWSikqVfjaoZ:ChOT++AifUkC+FWS2VZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • xkbcomp_w32.exe (PID: 3628)
      • XWin_MobaX.exe (PID: 540)
      • XWin_MobaX.exe (PID: 2472)
      • xkbcomp_w32.exe (PID: 2524)
      • cygtermd.exe (PID: 2420)
      • cygtermd.exe (PID: 2072)
      • bash.exe (PID: 2996)
      • svchost.exe (PID: 860)
      • busybox.exe (PID: 2108)
      • bash.exe (PID: 3244)
      • busybox.exe (PID: 3432)
      • bash.exe (PID: 4040)
      • ssh-agent.exe (PID: 2212)
      • ssh-agent.exe (PID: 3172)
      • bash.exe (PID: 2236)
      • bash.exe (PID: 1740)
      • busybox.exe (PID: 2340)
      • bash.exe (PID: 2624)
      • busybox.exe (PID: 3200)
      • bash.exe (PID: 2376)
      • bash.exe (PID: 4020)
      • bash.exe (PID: 2412)
      • bash.exe (PID: 1396)
      • cygstart.exe (PID: 3216)
      • bash.exe (PID: 1760)
      • cygstart.exe (PID: 2036)
      • bash.exe (PID: 2352)
      • bash.exe (PID: 3248)
      • bash.exe (PID: 3556)
      • _rxvt.exe (PID: 2464)
      • bash.exe (PID: 3408)
      • bash.exe (PID: 2564)
      • bash.exe (PID: 2376)
      • xkbcomp_w32.exe (PID: 2348)
      • XWin_MobaX.exe (PID: 3048)
    • Application was dropped or rewritten from another process

      • xkbcomp_w32.exe (PID: 3628)
      • XWin_MobaX.exe (PID: 2472)
      • XWin_MobaX.exe (PID: 540)
      • motty.exe (PID: 4068)
      • xkbcomp_w32.exe (PID: 2524)
      • cygtermd.exe (PID: 2420)
      • ssh-agent.exe (PID: 2212)
      • ssh-agent.exe (PID: 3172)
      • cygtermd.exe (PID: 2072)
      • bash.exe (PID: 2996)
      • bash.exe (PID: 2376)
      • bash.exe (PID: 3244)
      • bash.exe (PID: 4020)
      • bash.exe (PID: 2236)
      • bash.exe (PID: 1740)
      • bash.exe (PID: 2624)
      • bash.exe (PID: 1760)
      • busybox.exe (PID: 3432)
      • busybox.exe (PID: 2108)
      • busybox.exe (PID: 2340)
      • busybox.exe (PID: 3200)
      • bash.exe (PID: 1396)
      • bash.exe (PID: 2412)
      • bash.exe (PID: 4040)
      • bash.exe (PID: 3408)
      • bash.exe (PID: 2564)
      • cygstart.exe (PID: 2036)
      • bash.exe (PID: 2352)
      • bash.exe (PID: 2376)
      • bash.exe (PID: 3248)
      • _rxvt.exe (PID: 2464)
      • bash.exe (PID: 3556)
      • cygstart.exe (PID: 3216)
      • xkbcomp_w32.exe (PID: 2348)
      • XWin_MobaX.exe (PID: 3048)
    • Detects Cygwin installation

      • MobaXterm_Personal_20.2.exe (PID: 4008)
  • SUSPICIOUS

    • Creates or modifies windows services

      • svchost.exe (PID: 860)
    • Application launched itself

      • MobaXterm_Personal_20.2.exe (PID: 2632)
      • cygtermd.exe (PID: 2420)
      • bash.exe (PID: 2996)
      • ssh-agent.exe (PID: 2212)
      • bash.exe (PID: 3248)
      • bash.exe (PID: 2376)
    • Reads Internet Cache Settings

      • MobaXterm_Personal_20.2.exe (PID: 2632)
    • Executable content was dropped or overwritten

      • MobaXterm_Personal_20.2.exe (PID: 2632)
      • MobaXterm_Personal_20.2.exe (PID: 4008)
  • INFO

    • Reads settings of System Certificates

      • MobaXterm_Personal_20.2.exe (PID: 2632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (53.2)
.exe | Win32 Executable Delphi generic (17.5)
.scr | Windows screen saver (16.1)
.exe | Win32 Executable (generic) (5.5)
.exe | Win16/32 Executable Delphi generic (2.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:03:05 01:00:00+01:00
PEType: PE32
LinkerVersion: 2.25
CodeSize: 6244864
InitializedDataSize: 8472064
UninitializedDataSize: -
EntryPoint: 0x5f3a54
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 20.2.0.4296
ProductVersionNumber: 20.2.0.4296
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Mobatek
FileDescription: MobaXterm
FileVersion: 20.2.0.4296
InternalName: MobaXterm
LegalCopyright: Mobatek - https://mobaxterm.mobatek.net
LegalTrademarks: Mobatek - https://mobaxterm.mobatek.net
OriginalFileName: MobaXterm
ProductName: MobaXterm
ProductVersion: 20.2
Comments: https://mobaxterm.mobatek.net

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 05-Mar-2020 00:00:00
Detected languages:
  • English - United States
  • French - France
  • Russian - Russia
CompanyName: Mobatek
FileDescription: MobaXterm
FileVersion: 20.2.0.4296
InternalName: MobaXterm
LegalCopyright: Mobatek - https://mobaxterm.mobatek.net
LegalTrademarks: Mobatek - https://mobaxterm.mobatek.net
OriginalFilename: MobaXterm
ProductName: MobaXterm
ProductVersion: 20.2
Comments: https://mobaxterm.mobatek.net

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0050
Pages in file: 0x0002
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x000F
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x001A
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000100

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 8
Time date stamp: 05-Mar-2020 00:00:00
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
CODE
0x00001000
0x005F4854
0x005F4A00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.59491
DATA
0x005F6000
0x00086170
0x00086200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.17894
BSS
0x0067D000
0x000288FD
0x00000000
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.idata
0x006A6000
0x00004B70
0x00004C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.03375
.tls
0x006AB000
0x00000040
0x00000000
IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rdata
0x006AC000
0x00000018
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED
0.210826
.reloc
0x006AD000
0x00056924
0x00000000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED
0
.rsrc
0x00704000
0x00732C00
0x00732C00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED
7.96329

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.03446
1738
UNKNOWN
English - United States
RT_MANIFEST
2
3.27987
9640
UNKNOWN
French - France
RT_ICON
3
3.60944
4264
UNKNOWN
French - France
RT_ICON
4
3.77446
2440
UNKNOWN
French - France
RT_ICON
5
4.01242
1128
UNKNOWN
French - France
RT_ICON
6
2.62527
308
UNKNOWN
UNKNOWN
RT_CURSOR
7
2.91604
308
UNKNOWN
UNKNOWN
RT_CURSOR
8
1.0999
4268
UNKNOWN
English - United States
RT_CURSOR
9
1.95679
4268
UNKNOWN
English - United States
RT_CURSOR
10
1.07477
4268
UNKNOWN
English - United States
RT_CURSOR

Imports

Crypt32.dll
IPHLPAPI.DLL
advapi32.dll
comctl32.dll
comdlg32.dll
crypt32.dll
gdi32.dll
gdiplus.dll
imm32.dll
kernel32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
81
Monitored processes
38
Malicious processes
28
Suspicious processes
9

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Users\admin\AppData\Local\Temp\Mxt202\bin\XWin_MobaX.exe" -silent-dup-error -notrayicon -nolisten inet6 -hostintitle +bs -clipboard -nowgl -multiwindow -noreset :0C:\Users\admin\AppData\Local\Temp\Mxt202\bin\XWin_MobaX.exe
MobaXterm_Personal_20.2.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
540
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\bin\xwin_mobax.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
860C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\host.exe
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
1396"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\bash.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1740"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\bash.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1760"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\bash.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2036"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\cygstart.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\cygstart.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
256
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygstart.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygpopt-0.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
2072C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\cygtermd.exe /home/mobaxterm /bin/bash -l -iC:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\cygtermd.execygtermd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygtermd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
2108"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\busybox.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\busybox.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\busybox.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
2212"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\ssh-agent.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\ssh-agent.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\ssh-agent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2236"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exe"C:\Users\admin\AppData\Local\Temp\Mxt202\var\log\xwin\Mxt202\bin\bash.exebash.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\bash.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\mxt202\var\log\xwin\mxt202\bin\cygwin1.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
1 585
Read events
905
Write events
669
Delete events
11

Modification events

(PID) Process:(860) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IKEEXT
Operation:writeName:CurrentLru
Value:
FB03000000000000
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:WindowClass
Value:
CMoTTY
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:DarkMode
Value:
0
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:LogguerDansMobaXterm
Value:
0
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:utf8linedraw
Value:
1
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:NoRemoteResize
Value:
1
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:ScrollbarOnLeft
Value:
0
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:EraseToScrollback
Value:
1
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:ScrollOnDisp
Value:
0
(PID) Process:(2632) MobaXterm_Personal_20.2.exeKey:HKEY_CURRENT_USER\Software\MobaXterm\MoTTY\Sessions\TERM658561
Operation:writeName:ScrollOnKey
Value:
1
Executable files
96
Suspicious files
123
Text files
944
Unknown types
233

Dropped files

PID
Process
Filename
Type
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\profiletext
MD5:804065C497A7FB1FFC5207D725F3EF60
SHA256:669F1581F66BDC49CB642AC732660DA92B9295A2318242E8B2F7B40DEDD147F2
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\fstabtext
MD5:782B7EC202C67F6034AF8204B71C2F0B
SHA256:97D7669F0900ED71671821447AA7442CD97E6F4B725B4919B3B5F99C5156FCE6
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\baseprofiletext
MD5:A8DC8D25713AC3AB209C966385BB3514
SHA256:0D9FEE0B204B56447362451C34A187E0A4C6E46194D48368A876378DBC13356C
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\zprofiletext
MD5:2CEC732572E500063510D1908041E9A8
SHA256:197DF772735D1DF8F279C476BF808DE89187BFDF0572F442069A370450F53E1C
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\ssh_configtext
MD5:7CEB8529CB9FBE96FA321424D4C2681B
SHA256:8F1265583B3480A2F0D3F2FA6AFE347E26FDD5C975CB3285F4C74FB2335F9C49
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\nsswitch.conftext
MD5:5A76145CB2E0BD7CABAC55C6E941F3F7
SHA256:C83DC30523FEDB6298ABE4A492EC03CE74B3EDF1679A69F23B6B901620925B1B
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\passwdtext
MD5:0AFAAD99A8661920AE386FAB6A88B942
SHA256:74D9E1F2C2F61FF7BC2F9761FA036C1B93F3DF9C62EEB5D8B65D3741E6D7D09C
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\init.d\ftpbinary
MD5:2A2FCE224C91755D043CFD460CB7EBC2
SHA256:CAABB53C134A5727836D7669AB5063AFAECD37E1225F5F3A6810AEF441BAFF20
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\grouptext
MD5:5160399186F824CDD09A395EB0EF0F06
SHA256:9F4817E32AD80887C1D62ABEF44A915FBAA90060726B03A1D548A8359D9A66AD
2632MobaXterm_Personal_20.2.exeC:\Users\admin\AppData\Local\Temp\Mxt202\etc\init.d\sshbinary
MD5:2A2FCE224C91755D043CFD460CB7EBC2
SHA256:CAABB53C134A5727836D7669AB5063AFAECD37E1225F5F3A6810AEF441BAFF20
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2632
MobaXterm_Personal_20.2.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSl4jRO9XY6nOLzHpuYB7AHVyel%2BQQUs5Cn2MmvTs1hPJ98rV1%2FQf1pMOoCEQCN2o%2BDBAA2HpQl45Ey%2BUQk
US
der
472 b
whitelisted
2632
MobaXterm_Personal_20.2.exe
GET
200
151.139.128.14:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEAXk3DuUOKs7hZfLpqGYUOM%3D
US
der
727 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2632
MobaXterm_Personal_20.2.exe
46.105.198.129:443
mobaxterm.mobatek.net
OVH SAS
FR
unknown
2632
MobaXterm_Personal_20.2.exe
151.139.128.14:80
ocsp.usertrust.com
Highwinds Network Group, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
mobaxterm.mobatek.net
  • 46.105.198.129
unknown
ocsp.usertrust.com
  • 151.139.128.14
whitelisted

Threats

No threats detected
No debug info