Program did not start
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Connects to CnC server
|
No suspicious indicators. |
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000213D5 | 0x00021400 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 6.66064 |
.rdata | 0x00023000 | 0x0000B470 | 0x0000B600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 6.30604 |
.data | 0x0002F000 | 0x000040B4 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE | 2.65429 |
.gfids | 0x00034000 | 0x000000E4 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 2.02137 |
.rsrc | 0x00035000 | 0x000001E0 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 4.7123 |
.reloc | 0x00036000 | 0x00001D5C | 0x00001E00 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 6.68502 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\appdata\local\temp\msbuild.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\nsi.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
c:\windows\system32\rasapi32.dll |
c:\windows\system32\rasman.dll |
c:\windows\system32\rtutils.dll |
c:\windows\system32\sensapi.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\wshtcpip.dll |
c:\windows\system32\wship6.dll |
c:\windows\system32\rasadhlp.dll |
c:\windows\system32\fwpuclnt.dll |
c:\windows\system32\nlaapi.dll |
c:\windows\system32\version.dll |
c:\windows\system32\napinsp.dll |
c:\windows\system32\pnrpnsp.dll |
c:\windows\system32\winrnr.dll |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3876 | MSBuild.exe | POST | 200 | 45.33.66.85:80 | http://node2.feed43.com/0056234178515131.xml | US |
xml
|
|
malicious |
3876 | MSBuild.exe | POST | –– | 139.28.38.231:80 | http://139.28.38.231:80//e3e7e71a0b28b5e96cc492e636722f73//4sVKAOvu3D//ABDYot0NxyG.php | unknown |
text
––
|
––
|
malicious |
PID | Process | IP | ASN | CN | Reputation |
---|---|---|---|---|---|
3876 | MSBuild.exe | 91.198.174.192:443 | Wikimedia Foundation, Inc. | NL | suspicious |
3876 | MSBuild.exe | 45.33.66.85:80 | Linode, LLC | US | malicious |
3876 | MSBuild.exe | 139.28.38.231:80 | –– | malicious |
No debug info.