File name:

BustaGuess.zip

Full analysis: https://app.any.run/tasks/cdadae42-381e-46bb-88a6-a0dcd2866c4e
Verdict: Malicious activity
Analysis date: February 19, 2024, 11:25:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

E6E2ECC3AFC2154E190483793E161556

SHA1:

20FFF3BE33BE155A5E36F5339E8F5523630674C9

SHA256:

54090DC19A8647EA05E020D722AC2D40A6481E7C4ACF07ED7B3EAD70A91A776D

SSDEEP:

98304:WGSN2NknwfciGDNcHmY9IkvxqNHleBj5F20PaDKrlCDEWWAE2+6Z:WRIGwEiGDyGY9pxxjZZWWAEc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 1432)
      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 3964)
    • Changes the autorun value in the registry

      • fontPerfsvcwinsession.exe (PID: 1624)
    • Changes the login/logoff helper path in the registry

      • fontPerfsvcwinsession.exe (PID: 1624)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • BustaGuess.exe (PID: 3956)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 1432)
    • Executable content was dropped or overwritten

      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Reads the Internet Settings

      • WinRAR.exe (PID: 2580)
      • wscript.exe (PID: 3964)
      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 3964)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 3964)
      • fontPerfsvcwinsession.exe (PID: 1624)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 3964)
    • Executed via WMI

      • schtasks.exe (PID: 2760)
      • schtasks.exe (PID: 296)
      • schtasks.exe (PID: 3036)
      • schtasks.exe (PID: 316)
      • schtasks.exe (PID: 1840)
      • schtasks.exe (PID: 764)
      • schtasks.exe (PID: 1124)
      • schtasks.exe (PID: 2584)
      • schtasks.exe (PID: 1216)
      • schtasks.exe (PID: 1020)
      • schtasks.exe (PID: 2748)
      • schtasks.exe (PID: 2956)
      • schtasks.exe (PID: 3256)
      • schtasks.exe (PID: 3292)
      • schtasks.exe (PID: 1956)
      • schtasks.exe (PID: 3192)
      • schtasks.exe (PID: 268)
      • schtasks.exe (PID: 4072)
      • schtasks.exe (PID: 4084)
      • schtasks.exe (PID: 572)
      • schtasks.exe (PID: 2560)
      • schtasks.exe (PID: 2396)
      • schtasks.exe (PID: 952)
      • schtasks.exe (PID: 2344)
      • schtasks.exe (PID: 3456)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 3236)
      • schtasks.exe (PID: 3808)
      • schtasks.exe (PID: 3768)
      • schtasks.exe (PID: 1072)
      • schtasks.exe (PID: 4028)
      • schtasks.exe (PID: 2088)
      • schtasks.exe (PID: 2824)
      • schtasks.exe (PID: 3524)
      • schtasks.exe (PID: 3452)
      • schtasks.exe (PID: 3560)
      • schtasks.exe (PID: 2416)
      • schtasks.exe (PID: 896)
      • schtasks.exe (PID: 3248)
      • schtasks.exe (PID: 3440)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 3028)
    • Probably delay the execution using 'w32tm.exe'

      • cmd.exe (PID: 3548)
  • INFO

    • Reads the computer name

      • WinRAR.exe (PID: 2580)
      • BustaGuess.exe (PID: 3956)
      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Creates files or folders in the user directory

      • BustaGuess.exe (PID: 3956)
    • Manual execution by a user

      • BustaGuess.exe (PID: 3956)
    • Checks supported languages

      • BustaGuess.exe (PID: 3956)
      • WinRAR.exe (PID: 2580)
      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1432)
    • Reads the machine GUID from the registry

      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Reads Environment values

      • fontPerfsvcwinsession.exe (PID: 1624)
      • dwm.exe (PID: 3652)
    • Creates files in the program directory

      • fontPerfsvcwinsession.exe (PID: 1624)
    • Create files in a temporary directory

      • fontPerfsvcwinsession.exe (PID: 1624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2022:03:17 17:20:36
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: BustaGuess/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
93
Monitored processes
50
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe bustaguess.exe winrar.exe wscript.exe no specs cmd.exe no specs fontperfsvcwinsession.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs cmd.exe no specs w32tm.exe no specs reg.exe no specs dwm.exe

Process information

PID
CMD
Path
Indicators
Parent process
268schtasks.exe /create /tn "yGpBconhost" /sc ONSTART /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
296schtasks.exe /create /tn "Gc2yexplorer" /sc ONLOGON /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
316schtasks.exe /create /tn "YwLkexplorer" /sc ONSTART /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\explorer.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
572schtasks.exe /create /tn "conhost" /sc MINUTE /mo 5 /tr "'C:\Windows\Installer\{90140000-006E-0410-0000-0000000FF1CE}\conhost.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
764schtasks.exe /create /tn "7CU2dwm" /sc MINUTE /mo 10 /tr "'C:\Documents and Settings\dwm.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
896schtasks.exe /create /tn "QdIOSearchProtocolHost" /sc ONLOGON /tr "'C:\Windows\ehome\en-US\SearchProtocolHost.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
952schtasks.exe /create /tn "KTPMlsass" /sc MINUTE /mo 5 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1020schtasks.exe /create /tn "lsass" /sc MINUTE /mo 14 /tr "'C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\lsass.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1072schtasks.exe /create /tn "YtnQfontPerfsvcwinsession" /sc MINUTE /mo 14 /tr "'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\fontPerfsvcwinsession.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
1124schtasks.exe /create /tn "ctfmon" /sc MINUTE /mo 12 /tr "'C:\MSOCache\All Users\{90140000-00A1-041F-0000-0000000FF1CE}-C\ctfmon.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
10 463
Read events
10 373
Write events
90
Delete events
0

Modification events

(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1432) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\BustaGuess.zip
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1432) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
33
Suspicious files
1
Text files
20
Unknown types
2

Dropped files

PID
Process
Filename
Type
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_PenSuit.dllexecutable
MD5:1F7FFEA4DD13500622F1C2F8FCD6D173
SHA256:20925E5FC22342EEFD2EC58B81953117BA26E7FC0E076B87BCBF7C80DFB4A52A
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\cc32100mt.dllexecutable
MD5:1EC6FE4798163C9EAB3BC7835FBF4F47
SHA256:D221DA673572C2D0C8EDC23DE7DFEEA3E6CD6E994427AE48565A16751A3871BC
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\borlndmm.dllexecutable
MD5:E3FCF256B4683AB92703842985B5E725
SHA256:CA1F509D6779BC005F332027D50E9BAFA952BCF970953593A9566973B4122759
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\BustaGuess.exeexecutable
MD5:B4FD51350A4AF9FB273ADC47106A579D
SHA256:1465B7FFE8761EE7DB2F6482061F44852145C5D3C05894F40EF1565FB8B40C84
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dbghelp.dllexecutable
MD5:74EDBB03DE3291FCF2094AF1FB363F1D
SHA256:DCA9F45EFED8EAB442B491AEBDA3E3CCE7F5F9FC5DE527D2DBDFD85A5BE85DFA
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_MouseDeviceManager.dllexecutable
MD5:D9E11A2AB50B4FF6AD95EEE5FED3EB48
SHA256:A48D804C0732591B4C891AC2A7B32D0D627602B950FEC30143A5DAFD5AEE103B
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_AnalyzeGesturesInRight.dllexecutable
MD5:03890A9FAA8613F47EF0A1932F1A875D
SHA256:52D5E0A454325462C724038311462BB499096B037560B657B8C02870B929473C
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_ZoomControl.dllexecutable
MD5:ADA979540911494C857A89AB110152EC
SHA256:02E887718CC03263E594C09D12777926A45CA7E82A9D8D9C7B4E4177A107F042
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_ScrollbarControl.dllexecutable
MD5:16AB9BDACDD35134895B8681D25089C0
SHA256:B751E0A0C31F31847948003C094D2F0C6024501048CE87F2C2E9274E1A5CC0FC
1432WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1432.44691\BustaGuess\dll\DLL_Wheel4D.dllexecutable
MD5:9D1E44B28200D8C3F34D00250F97ED9B
SHA256:6C2A2B0C2D005C4D1F434871B494C72D126EC8AF17ED43D34F80E2249078AFFD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
1
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3652
dwm.exe
GET
400
141.8.197.42:80
http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa
unknown
html
154 b
3652
dwm.exe
GET
400
141.8.197.42:80
http://a0646788.xsph.ru/providerjavascriptCpuUpdatewindows.php?aRAcs8leQABmW=um4UDqOTebYRa&1f193d62ec9c62635c7a577ab8036ca6=ab400134a35ae28afb0d0ba5228d6dfd&dc8ff4a64801661ad57705042575a3b4=wNwcTM4EDN1kTM4Q2MjNWNlJDOwUDNlJ2YhBDMyQWY1IGO0MzNlljZ&aRAcs8leQABmW=um4UDqOTebYRa
unknown
html
154 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3652
dwm.exe
141.8.197.42:80
a0646788.xsph.ru
Sprinthost.ru LLC
RU
unknown

DNS requests

Domain
IP
Reputation
a0646788.xsph.ru
  • 141.8.197.42
unknown

Threats

PID
Process
Class
Message
Misc activity
ET INFO Observed DNS Query to xsph .ru Domain
No debug info