Program did not start
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Application was injected by another process
|
Starts application with an unusual extension
|
Application was crashed
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00074031 | 0x00074200 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.49948 |
.rdata | 0x00076000 | 0x00030FB0 | 0x00031000 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 4.40255 |
.data | 0x000A7000 | 0x000046D4 | 0x00003400 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 5.28058 |
.gfids | 0x000AC000 | 0x000001B8 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 3.5648 |
.tls | 0x000AD000 | 0x00000009 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 0.0203931 |
.rsrc | 0x000AE000 | 0x0011E765 | 0x0011E800 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 6.36252 |
.reloc | 0x001CD000 | 0x0008BBB0 | 0x0008B9B0 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 1.17468 |
No exports.
Click at the process to see the details.
Image |
---|
c:\windows\system32\wininit.exe |
c:\windows\system32\kernel32.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\secur32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\credssp.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\ntdll.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\mswsock.dll |
Image |
---|
c:\windows\system32\gdi32.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\winlogon.exe |
c:\windows\system32\user32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\uxinit.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\windowscodecs.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\netjoin.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\slc.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\winsta.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\wsock32.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\iertutil.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\winrnr.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\temp\crta1b.tmp |
c:\windows\system32\wship6.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\netprofm.dll |
c:\windows\system32\npmproxy.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\temp\crt6d99.tmp |
Image |
---|
c:\windows\explorer.exe |
c:\windows\system32\advapi32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\explorerframe.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\cscdll.dll |
c:\windows\system32\iconcodecservice.dll |
c:\windows\system32\linkinfo.dll |
c:\windows\system32\netutils.dll |
c:\program files\common files\microsoft shared\ink\tiptsf.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\wer.dll |
c:\windows\system32\version.dll |
c:\windows\system32\ksuser.dll |
c:\windows\system32\msacm32.dll |
c:\windows\system32\wtsapi32.dll |
c:\windows\system32\dxp.dll |
c:\windows\system32\syncreg.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\wpdshserviceobj.dll |
c:\windows\system32\mssprxy.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\wlanapi.dll |
c:\windows\system32\qagent.dll |
c:\windows\system32\ieframe.dll |
c:\windows\system32\imapi2.dll |
c:\windows\system32\fxsst.dll |
c:\windows\system32\wscapi.dll |
c:\windows\system32\wercplsupport.dll |
c:\windows\system32\searchfolder.dll |
c:\windows\system32\nlslexicons0009.dll |
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742\msvcr90.dll |
c:\windows\system32\cryptnet.dll |
c:\windows\system32\cabinet.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\dsrole.dll |
c:\program files\windows sidebar\sbdrop.dll |
c:\windows\system32\netprofm.dll |
c:\windows\system32\ntdll.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\duser.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\dwmapi.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\windowscodecs.dll |
c:\windows\system32\ehstorshell.dll |
c:\windows\system32\ntshrui.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\authui.dll |
c:\windows\system32\winsta.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\msi.dll |
c:\windows\system32\avrt.dll |
c:\windows\system32\midimap.dll |
c:\windows\system32\es.dll |
c:\windows\system32\urlmon.dll |
c:\windows\ehome\ehsso.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\portabledevicetypes.dll |
c:\windows\system32\pnidui.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\wlanutil.dll |
c:\windows\system32\srchadmin.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\hgcpl.dll |
c:\windows\system32\fxsapi.dll |
c:\windows\system32\wscui.cpl |
c:\windows\system32\msxml6.dll |
c:\windows\system32\structuredquery.dll |
c:\windows\system32\thumbcache.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\webio.dll |
c:\windows\system32\dfshim.dll |
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\msftedit.dll |
c:\windows\system32\sfc_os.dll |
c:\windows\system32\mlang.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\dui70.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\secur32.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\cscapi.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\sndvolsso.dll |
c:\windows\system32\hid.dll |
c:\windows\system32\mmdevapi.dll |
c:\windows\system32\timedate.cpl |
c:\windows\system32\atl.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\shdocvw.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\msls31.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\gameux.dll |
c:\windows\system32\msiltcfg.dll |
c:\windows\system32\wdmaud.drv |
c:\windows\system32\msacm32.drv |
c:\windows\system32\batmeter.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\iertutil.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\alttab.dll |
c:\windows\system32\wintrust.dll |
c:\windows\system32\wevtapi.dll |
c:\windows\system32\npmproxy.dll |
c:\windows\system32\wwapi.dll |
c:\windows\system32\bthprops.cpl |
c:\windows\system32\actioncenter.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\wscinterop.dll |
c:\windows\system32\framedynos.dll |
c:\program files\internet explorer\ieproxy.dll |
c:\windows\system32\nlsdata0009.dll |
c:\program files\microsoft office\office14\onfilter.dll |
c:\windows\system32\devrtl.dll |
c:\windows\system32\winhttp.dll |
c:\windows\system32\credssp.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\mscoree.dll |
c:\windows\system32\msvcr120_clr0400.dll |
c:\windows\system32\rtutils.dll |
c:\program files\filezilla ftp client\fzshellext.dll |
c:\windows\system32\sfc.dll |
c:\windows\system32\ehstorapi.dll |
c:\windows\system32\winanr.dll |
c:\users\admin\appdata\local\temp\47d0a5c63cb185e28c6c88ec90c9a5207d047ed420808707066da928905bb1bf.exe |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\slc.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\cscui.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\actxprxy.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\cryptui.dll |
c:\windows\system32\xmllite.dll |
c:\windows\system32\networkexplorer.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\audioses.dll |
c:\windows\system32\stobject.dll |
c:\windows\system32\prnfldr.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\netshell.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\portabledeviceapi.dll |
c:\windows\system32\qutil.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\wwanapi.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\synccenter.dll |
c:\windows\system32\provsvc.dll |
c:\windows\system32\fxsresm.dll |
c:\windows\system32\werconcpl.dll |
c:\windows\system32\hcproviders.dll |
c:\windows\system32\naturallanguage6.dll |
c:\windows\system32\tquery.dll |
c:\windows\system32\dsound.dll |
c:\windows\system32\msxml3.dll |
c:\windows\system32\imagehlp.dll |
c:\windows\system32\bcrypt.dll |
c:\windows\system32\bcryptprimitives.dll |
c:\windows\system32\ncrypt.dll |
c:\windows\system32\werfault.exe |
c:\windows\temp\crt6d99.tmp |
c:\windows\system32\gpapi.dll |
c:\users\admin\appdata\local\temp\mia3d5b.tmp |
Image |
---|
c:\users\admin\appdata\local\temp\47d0a5c63cb185e28c6c88ec90c9a5207d047ed420808707066da928905bb1bf.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\comdlg32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\resutils.dll |
c:\windows\system32\clusapi.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\cryptdll.dll |
c:\windows\system32\authz.dll |
c:\windows\system32\snmpapi.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\loadperf.dll |
c:\windows\system32\secur32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\pdh.dll |
c:\windows\system32\p2p.dll |
c:\windows\system32\p2pcollab.dll |
c:\windows\system32\powrprof.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\mprapi.dll |
c:\windows\system32\oledlg.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\version.dll |
c:\windows\system32\rtm.dll |
c:\windows\system32\rtutils.dll |
c:\windows\winsxs\x86_microsoft-windows-u..rsalcrt-apifwd-win7_31bf3856ad364e35_6.1.7601.18972_none_4d8675c06cc24030\api-ms-win-core-synch-l1-2-0.dll |
Image |
---|
c:\windows\system32\ole32.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\msls31.dll |
c:\windows\system32\version.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\mshtml.dll |
c:\windows\system32\psapi.dll |
c:\windows\temp\crta1b.tmp |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\comdlg32.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\winspool.drv |
c:\windows\system32\oledlg.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\wbem\wbemprox.dll |
c:\windows\system32\wbemcomn.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\wbem\wbemsvc.dll |
c:\windows\system32\wbem\fastprox.dll |
c:\windows\system32\ntdsapi.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\normaliz.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\netprofm.dll |
c:\windows\system32\npmproxy.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\winrnr.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\fwpuclnt.dll |
Image |
---|
c:\windows\temp\crt6d99.tmp |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\apphelp.dll |
Image |
---|
c:\windows\temp\crt6d99.tmp |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\wshqos.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wship6.dll |
c:\users\admin\appdata\local\temp\mia3d5b.tmp |
Image |
---|
c:\windows\system32\netsh.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\credui.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\rasmontr.dll |
c:\windows\system32\mprapi.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\mfc42u.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\odbcint.dll |
c:\windows\system32\nshwfp.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\slc.dll |
c:\windows\system32\dhcpcmonitor.dll |
c:\windows\system32\dhcpcsvc.dll |
c:\windows\system32\dhcpcsvc6.dll |
c:\windows\system32\dhcpqec.dll |
c:\windows\system32\qutil.dll |
c:\windows\system32\wevtapi.dll |
c:\windows\system32\wshelper.dll |
c:\windows\system32\ws2help.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\nshhttp.dll |
c:\windows\system32\httpapi.dll |
c:\windows\system32\fwcfg.dll |
c:\windows\system32\firewallapi.dll |
c:\windows\system32\version.dll |
c:\windows\system32\authfwcfg.dll |
c:\windows\system32\bcrypt.dll |
c:\windows\system32\winipsec.dll |
c:\windows\system32\ifmon.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\nci.dll |
c:\windows\system32\devrtl.dll |
c:\windows\system32\netiohlp.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\whhelper.dll |
c:\windows\system32\winhttp.dll |
c:\windows\system32\webio.dll |
c:\windows\system32\hnetmon.dll |
c:\windows\system32\netshell.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\rpcnsh.dll |
c:\windows\system32\dot3cfg.dll |
c:\windows\system32\dot3api.dll |
c:\windows\system32\atl.dll |
c:\windows\system32\eappcfg.dll |
c:\windows\system32\onex.dll |
c:\windows\system32\eappprxy.dll |
c:\windows\system32\napmontr.dll |
c:\windows\system32\certcli.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\nshipsec.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\logoncli.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\activeds.dll |
c:\windows\system32\adsldpc.dll |
c:\windows\system32\polstore.dll |
c:\windows\system32\nettrace.dll |
c:\windows\system32\ndfapi.dll |
c:\windows\system32\wdi.dll |
c:\windows\system32\secur32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\tdh.dll |
c:\windows\system32\wcnnetsh.dll |
c:\windows\system32\wlanapi.dll |
c:\windows\system32\wlanutil.dll |
c:\windows\system32\p2pnetsh.dll |
c:\windows\system32\p2p.dll |
c:\windows\system32\p2pcollab.dll |
c:\windows\system32\wlancfg.dll |
c:\windows\system32\wlanhlp.dll |
c:\windows\system32\wwancfg.dll |
c:\windows\system32\wwapi.dll |
c:\windows\system32\peerdistsh.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\qagent.dll |
c:\windows\system32\napipsec.dll |
c:\windows\system32\tsgqec.dll |
c:\windows\system32\eapqec.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\gpapi.dll |
c:\windows\system32\bcryptprimitives.dll |
c:\windows\system32\odbc32.dll |
Image |
---|
c:\windows\system32\kernelbase.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\nsi.dll |
c:\windows\winsxs\x86_microsoft-windows-u..rsalcrt-apifwd-win7_31bf3856ad364e35_6.1.7601.18972_none_4d8675c06cc24030\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\sechost.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\propsys.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\dwmapi.dll |
c:\users\admin\appdata\local\temp\mia3d5b.tmp |
c:\windows\system32\msasn1.dll |
c:\windows\system32\webio.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\xmllite.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\msls31.dll |
c:\windows\system32\msimtf.dll |
c:\windows\system32\sxs.dll |
c:\windows\system32\mlang.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\duser.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\version.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\program files\internet explorer\iexplore.exe |
c:\windows\system32\mswsock.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\jscript.dll |
c:\windows\system32\rpcrtremote.dll |
c:\windows\system32\credssp.dll |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\winhttp.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\shdocvw.dll |
c:\windows\system32\mshtml.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\ieframe.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\wininet.dll |
Image |
---|
c:\windows\system32\kernelbase.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cmd.exe |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\lpk.dll |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\user32.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
460 | winlogon.exe | GET | 200 | 77.73.69.179:9 | http://77.73.69.179:9/mk/ic.jpg | RU |
executable
|
|
suspicious |
460 | winlogon.exe | GET | 200 | 77.73.69.179:9 | http://77.73.69.179:9/mk/p0.php?a=31 | RU |
executable
|
|
suspicious |
2828 | CRTA1B.tmp | POST | 200 | 195.201.249.16:80 | http://static.16.249.201.195.clients.your-server.de/request/autok?user=luxsoft&ver=10&key=a8d588afe11b4f83598303abd1b1afc3 | RU |
text
|
|
malicious |
2828 | CRTA1B.tmp | POST | 200 | 195.201.249.16:80 | http://static.16.249.201.195.clients.your-server.de/request/conditions?user=luxsoft&ver=10&key=5f2dc9d3c25c77251e40d8f22d2d7f65&token=6b0a29d579890187002b9741199066e3 | RU |
text
text
|
|
malicious |
2828 | CRTA1B.tmp | GET | –– | 31.192.108.35:80 | http://31.192.108.35:9/helloworld.exe | RU |
––
|
––
|
suspicious |
3332 | CRT6D99.tmp | GET | –– | 77.73.69.179:9 | http://77.73.69.179:9/mk/p1.php?a=31 | RU |
––
|
––
|
suspicious |
3332 | CRT6D99.tmp | GET | 200 | 77.73.69.179:9 | http://77.73.69.179:9/mk/p2.php?a=31 | RU |
binary
|
|
suspicious |
2396 | mia3D5B.tmp | GET | 200 | 54.230.95.130:80 | http://bin.memoryson.bid/offer.php?affId=3226&trackingId=365799514&instId=4364&ho_trackingid=HO365799514&cc=DE&sb=x86&wv=7sp1&db=InternetExplorer&uac=0&cid=5d979308c3b6ea5ad7e984e628c8cac1&v=3&net=4.6.01055&ie=8%2e0%2e7601%2e17514&res=1280x720&osd=338&kid=hqmrb21akjkou6cksks | US |
binary
|
|
whitelisted |
2396 | mia3D5B.tmp | POST | 403 | 54.230.95.130:80 | http://bin.memoryson.bid/installer.php?affId=3226&instId=4364&ho_trackingid=HO3657995145b93ea5402948&trackingId=365799514&cc=BE&untracked=&uac=0&osd=338&net=4.6.01055&cid=5d979308c3b6ea5ad7e984e628c8cac1&v=3&kid=hqmrb21akjkou6cksks | US |
text
html
|
|
whitelisted |
2396 | mia3D5B.tmp | POST | 200 | 54.88.21.193:80 | http://alt.zincbutter.download/installer.php?affId=3226&instId=4364&ho_trackingid=HO3657995145b93ea5402948&trackingId=365799514&cc=BE&untracked=&uac=0&osd=338&net=4.6.01055&cid=5d979308c3b6ea5ad7e984e628c8cac1&v=3&kid=hqmrb21akjkou6cksks | US |
text
binary
|
|
malicious |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
460 | winlogon.exe | 200.7.111.109:80 | Tele Asia Limited | HK | malicious |
460 | winlogon.exe | 77.73.69.179:9 | OOO Fishnet Communications | RU | suspicious |
2828 | CRTA1B.tmp | 195.201.249.16:80 | Awanti Ltd. | RU | malicious |
2828 | CRTA1B.tmp | 31.192.108.35:80 | Mir Telematiki Ltd | RU | suspicious |
3332 | CRT6D99.tmp | 77.73.69.179:9 | OOO Fishnet Communications | RU | suspicious |
2396 | mia3D5B.tmp | 54.230.95.130:80 | Amazon.com, Inc. | US | unknown |
2396 | mia3D5B.tmp | 54.88.21.193:80 | Amazon.com, Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
lopkey.com | 200.7.111.109
148.251.79.206 |
malicious |
static.16.249.201.195.clients.your-server.de | 195.201.249.16
|
malicious |
bin.memoryson.bid | 54.230.95.130
54.230.95.38 54.230.95.250 54.230.95.208 |
whitelisted |
alt.zincbutter.download | 54.88.21.193
|
malicious |
PID | Process | Class | Message |
---|---|---|---|
460 | winlogon.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
460 | winlogon.exe | Misc activity | POLICY [PTsecurity] PE as Image Content type mismatch |
2828 | CRTA1B.tmp | Misc activity | ADWARE [PTsecurity] Application.Bundler.ICLoader Response |
2828 | CRTA1B.tmp | A Network Trojan was detected | SC ADWARE SoftwareBundler:Win32/ICLoader |
2828 | CRTA1B.tmp | Misc Attack | ET DROP Dshield Block Listed Source group 1 |
460 | winlogon.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
460 | winlogon.exe | Misc activity | ET INFO Packed Executable Download |
2396 | mia3D5B.tmp | A Network Trojan was detected | ET MALWARE PPI User-Agent (InstallCapital) |
2396 | mia3D5B.tmp | Misc activity | ADWARE [PTsecurity] SoftwareBundler:Win32/Prepscram |
2396 | mia3D5B.tmp | A Network Trojan was detected | ET MALWARE PPI User-Agent (InstallCapital) |
2396 | mia3D5B.tmp | A Network Trojan was detected | ET MALWARE PPI User-Agent (InstallCapital) |
2828 | CRTA1B.tmp | A Network Trojan was detected | ET INFO Executable Download from dotted-quad Host |
No debug info.