File name:

BustaGuess.zip

Full analysis: https://app.any.run/tasks/cdadae42-381e-46bb-88a6-a0dcd2866c4e
Verdict: Malicious activity
Analysis date: February 19, 2024, 11:25:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

E6E2ECC3AFC2154E190483793E161556

SHA1:

20FFF3BE33BE155A5E36F5339E8F5523630674C9

SHA256:

54090DC19A8647EA05E020D722AC2D40A6481E7C4ACF07ED7B3EAD70A91A776D

SSDEEP:

98304:WGSN2NknwfciGDNcHmY9IkvxqNHleBj5F20PaDKrlCDEWWAE2+6Z:WRIGwEiGDyGY9pxxjZZWWAEc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1432)
      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 3964)
    • Changes the autorun value in the registry

      • fontPerfsvcwinsession.exe (PID: 1624)
    • Changes the login/logoff helper path in the registry

      • fontPerfsvcwinsession.exe (PID: 1624)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1432)
    • Executable content was dropped or overwritten

      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • The process creates files with name similar to system file names

      • BustaGuess.exe (PID: 3956)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Reads the Internet Settings

      • WinRAR.exe (PID: 2580)
      • wscript.exe (PID: 3964)
      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 3964)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 3964)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 3964)
    • Executed via WMI

      • schtasks.exe (PID: 296)
      • schtasks.exe (PID: 3036)
      • schtasks.exe (PID: 2760)
      • schtasks.exe (PID: 316)
      • schtasks.exe (PID: 2584)
      • schtasks.exe (PID: 2344)
      • schtasks.exe (PID: 1216)
      • schtasks.exe (PID: 1020)
      • schtasks.exe (PID: 3256)
      • schtasks.exe (PID: 3292)
      • schtasks.exe (PID: 2956)
      • schtasks.exe (PID: 1124)
      • schtasks.exe (PID: 1956)
      • schtasks.exe (PID: 3192)
      • schtasks.exe (PID: 4072)
      • schtasks.exe (PID: 572)
      • schtasks.exe (PID: 4084)
      • schtasks.exe (PID: 268)
      • schtasks.exe (PID: 764)
      • schtasks.exe (PID: 1840)
      • schtasks.exe (PID: 2560)
      • schtasks.exe (PID: 2396)
      • schtasks.exe (PID: 952)
      • schtasks.exe (PID: 2748)
      • schtasks.exe (PID: 896)
      • schtasks.exe (PID: 3808)
      • schtasks.exe (PID: 3456)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 2088)
      • schtasks.exe (PID: 3236)
      • schtasks.exe (PID: 3248)
      • schtasks.exe (PID: 3768)
      • schtasks.exe (PID: 1072)
      • schtasks.exe (PID: 3440)
      • schtasks.exe (PID: 3524)
      • schtasks.exe (PID: 2824)
      • schtasks.exe (PID: 3452)
      • schtasks.exe (PID: 4028)
      • schtasks.exe (PID: 3560)
      • schtasks.exe (PID: 2416)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 3028)
    • Probably delay the execution using 'w32tm.exe'

      • cmd.exe (PID: 3548)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1432)
    • Checks supported languages

      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Reads the computer name

      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Creates files or folders in the user directory

      • BustaGuess.exe (PID: 3956)
    • Manual execution by a user

      • BustaGuess.exe (PID: 3956)
    • Reads the machine GUID from the registry

      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Reads Environment values

      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Creates files in the program directory

      • fontPerfsvcwinsession.exe (PID: 1624)
    • Create files in a temporary directory

      • fontPerfsvcwinsession.exe (PID: 1624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2022:03:17 17:20:36
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BustaGuess/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
93
Monitored processes
50
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe bustaguess.exe winrar.exe wscript.exe no specs cmd.exe no specs fontperfsvcwinsession.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs cmd.exe no specs w32tm.exe no specs reg.exe no specs dwm.exe

Process information

PID
CMD
Path
Indicators
Parent process
268schtasks.exe /create /tn "yGpBconhost" /sc ONSTART /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
296schtasks.exe /create /tn "Gc2yexplorer" /sc ONLOGON /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
316schtasks.exe /create /tn "YwLkexplorer" /sc ONSTART /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
572schtasks.exe /create /tn "conhost" /sc MINUTE /mo 5 /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
764schtasks.exe /create /tn "7CU2dwm" /sc MINUTE /mo 10 /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
896schtasks.exe /create /tn "QdIOSearchProtocolHost" /sc ONLOGON /tr "'C:\Windows\ehome\en-US\SearchProtocolHost.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
952schtasks.exe /create /tn "KTPMlsass" /sc MINUTE /mo 5 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1020schtasks.exe /create /tn "lsass" /sc MINUTE /mo 14 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1072schtasks.exe /create /tn "YtnQfontPerfsvcwinsession" /sc MINUTE /mo 14 /tr "'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\fontPerfsvcwinsession.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1124schtasks.exe /create /tn "ctfmon" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-00A1-041F-0000-0000000FF1CE}-C\ctfmon.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
10 463
Read events
10 373
Write events
90
Delete events
0

Modification events

(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1432) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BustaGuess.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
33
Suspicious files
1
Text files
20
Unknown types
2

Dropped files

PID
Process
Filename
Type
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_MouseDeviceManager.dllexecutable
MD5:D9E11A2AB50B4FF6AD95EEE5FED3EB48
SHA256:A48D804C0732591B4C891AC2A7B32D0D627602B950FEC30143A5DAFD5AEE103B
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_PenSuit.dllexecutable
MD5:1F7FFEA4DD13500622F1C2F8FCD6D173
SHA256:20925E5FC22342EEFD2EC58B81953117BA26E7FC0E076B87BCBF7C80DFB4A52A
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\borlndmm.dllexecutable
MD5:E3FCF256B4683AB92703842985B5E725
SHA256:CA1F509D6779BC005F332027D50E9BAFA952BCF970953593A9566973B4122759
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dbghelp.dllexecutable
MD5:74EDBB03DE3291FCF2094AF1FB363F1D
SHA256:DCA9F45EFED8EAB442B491AEBDA3E3CCE7F5F9FC5DE527D2DBDFD85A5BE85DFA
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_AnalyzeGesturesInOne.dllexecutable
MD5:06302FA1044CE5F410B4E50B45EE89D0
SHA256:30EA045A8804AEA07D4C10A1B65029459D45075033DB71F91C5DDCE9C35656F1
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\Custom.initext
MD5:7950F22EF1D2EFCF819E58DC16B3F4AD
SHA256:808F089951E81B1F2417A61ECE43AF05F33BCBC31A873420C7BC8FFF63DC638F
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\Inform.initext
MD5:F3B25701FE362EC84616A93A45CE9998
SHA256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\FunctionDefine.initext
MD5:6918B5B988D19B01030F55E97CFC94A2
SHA256:5C47CE7CCC246C7161FCE5E42C66CB7FA4CD5308FAD8933ED66AFA4309088A1F
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\ini\DefaultScript.initext
MD5:27567E1E40A29E492743F21DFCF091C4
SHA256:9E727BE18047F05508543683B69C9085FEF1AB1A01174921B8AE56ECE789EA4E
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\cc32100mt.dllexecutable
MD5:1EC6FE4798163C9EAB3BC7835FBF4F47
SHA256:D221DA673572C2D0C8EDC23DE7DFEEA3E6CD6E994427AE48565A16751A3871BC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3652
dwm.exe
GET
400
141.8.197.42:80
http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa
unknown
html
154 b
unknown
3652
dwm.exe
GET
400
141.8.197.42:80
http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa
unknown
html
154 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3652
dwm.exe
141.8.197.42:80
a0646788.xsph.ru
Sprinthost.ru LLC
RU
unknown

DNS requests

Domain
IP
Reputation
a0646788.xsph.ru
  • 141.8.197.42
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO Observed DNS Query to xsph .ru Domain
No debug info