File name:

Xidrf.exe

Full analysis: https://app.any.run/tasks/9d63eb5a-23ce-4253-a7a0-9f28a757c9b7
Verdict: Malicious activity
Threats:

Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.

Analysis date: January 29, 2025, 16:02:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
netreactor
evasion
rat
quasar
remote
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

A7D4BB5FA829622026094DD2D4217579

SHA1:

0510C72C7929D2D5BE7C3999358A8D71172A9501

SHA256:

7451922CA940D1D53D6B5BE1233E5EE62168C96EAFEAD056A4EDEC77F3B9D5AF

SSDEEP:

12288:O0Dx58EKUgQDp1D/8IPBi5MKm3zrCfOmX0UiNc0Dx58ESuZUNnChsjQV:OUxb1pR8IPBi5MKm3zr0JoNcUxw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • QUASAR has been detected (SURICATA)

      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 7748)
      • CLIENT-BUILT.EXE (PID: 4872)
      • CLIENT-BUILT.EXE (PID: 6172)
      • CLIENT-BUILT.EXE (PID: 6032)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Xidrf.exe (PID: 6304)
      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 7516)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 8032)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6820)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7964)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 6280)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 2380)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 8024)
      • CLIENT-BUILT.EXE (PID: 7748)
      • CLIENT-BUILT.EXE (PID: 4872)
      • CLIENT-BUILT.EXE (PID: 6172)
      • CLIENT-BUILT.EXE (PID: 5212)
      • CLIENT-BUILT.EXE (PID: 2120)
      • CLIENT-BUILT.EXE (PID: 5400)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 7904)
      • CLIENT-BUILT.EXE (PID: 7536)
      • CLIENT-BUILT.EXE (PID: 7952)
      • CLIENT-BUILT.EXE (PID: 8112)
      • CLIENT-BUILT.EXE (PID: 7268)
      • CLIENT-BUILT.EXE (PID: 3032)
      • CLIENT-BUILT.EXE (PID: 1064)
      • CLIENT-BUILT.EXE (PID: 3172)
      • CLIENT-BUILT.EXE (PID: 6032)
    • Reads security settings of Internet Explorer

      • Xidrf.exe (PID: 6304)
      • Xidrf.exe (PID: 6356)
      • Xidrf.exe (PID: 6436)
      • Xidrf.exe (PID: 6500)
      • Xidrf.exe (PID: 6568)
      • Xidrf.exe (PID: 6756)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 6672)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 6984)
      • Xidrf.exe (PID: 6276)
      • Xidrf.exe (PID: 7064)
      • Xidrf.exe (PID: 7144)
      • Xidrf.exe (PID: 6400)
      • Xidrf.exe (PID: 6532)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6884)
      • Xidrf.exe (PID: 6788)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 6964)
      • Xidrf.exe (PID: 6472)
      • Xidrf.exe (PID: 6324)
      • Xidrf.exe (PID: 6676)
      • Xidrf.exe (PID: 2448)
      • Xidrf.exe (PID: 5432)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 7516)
      • Xidrf.exe (PID: 7712)
      • Xidrf.exe (PID: 7808)
      • Xidrf.exe (PID: 7928)
      • Xidrf.exe (PID: 5576)
      • Xidrf.exe (PID: 7784)
      • Xidrf.exe (PID: 4592)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 7060)
      • Xidrf.exe (PID: 6164)
      • Xidrf.exe (PID: 5888)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 6796)
      • Xidrf.exe (PID: 128)
      • Xidrf.exe (PID: 1852)
      • Xidrf.exe (PID: 6896)
      • Xidrf.exe (PID: 7704)
      • Xidrf.exe (PID: 7356)
      • Xidrf.exe (PID: 7860)
      • Xidrf.exe (PID: 7844)
      • Xidrf.exe (PID: 8044)
      • Xidrf.exe (PID: 6724)
      • Xidrf.exe (PID: 6492)
      • Xidrf.exe (PID: 8020)
      • Xidrf.exe (PID: 7144)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 1416)
      • Xidrf.exe (PID: 6956)
      • Xidrf.exe (PID: 5572)
      • Xidrf.exe (PID: 8124)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 1016)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 5876)
      • Xidrf.exe (PID: 7100)
      • Xidrf.exe (PID: 236)
      • Xidrf.exe (PID: 6888)
      • Xidrf.exe (PID: 6672)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6736)
      • Xidrf.exe (PID: 540)
      • Xidrf.exe (PID: 6812)
      • Xidrf.exe (PID: 7728)
      • Xidrf.exe (PID: 7188)
      • Xidrf.exe (PID: 7876)
      • Xidrf.exe (PID: 7364)
      • Xidrf.exe (PID: 4764)
      • Xidrf.exe (PID: 4144)
      • Xidrf.exe (PID: 7948)
      • Xidrf.exe (PID: 6096)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 6384)
      • Xidrf.exe (PID: 6664)
      • Xidrf.exe (PID: 6544)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 6516)
      • Xidrf.exe (PID: 6692)
      • Xidrf.exe (PID: 2100)
      • Xidrf.exe (PID: 6676)
      • Xidrf.exe (PID: 7300)
      • Xidrf.exe (PID: 7680)
      • Xidrf.exe (PID: 8104)
      • Xidrf.exe (PID: 4160)
      • Xidrf.exe (PID: 6032)
      • Xidrf.exe (PID: 5712)
      • Xidrf.exe (PID: 5788)
      • Xidrf.exe (PID: 7604)
      • Xidrf.exe (PID: 2792)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 7500)
      • Xidrf.exe (PID: 6656)
      • Xidrf.exe (PID: 6452)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 7788)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 6212)
      • Xidrf.exe (PID: 7736)
      • Xidrf.exe (PID: 236)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 8092)
      • Xidrf.exe (PID: 5536)
      • Xidrf.exe (PID: 6520)
      • Xidrf.exe (PID: 7236)
      • Xidrf.exe (PID: 7056)
      • Xidrf.exe (PID: 6540)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 8052)
      • Xidrf.exe (PID: 6340)
      • Xidrf.exe (PID: 2232)
      • Xidrf.exe (PID: 3188)
      • Xidrf.exe (PID: 880)
      • Xidrf.exe (PID: 720)
      • Xidrf.exe (PID: 7868)
      • Xidrf.exe (PID: 6616)
      • Xidrf.exe (PID: 6556)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 4968)
      • Xidrf.exe (PID: 6940)
      • Xidrf.exe (PID: 308)
      • Xidrf.exe (PID: 6488)
      • Xidrf.exe (PID: 6876)
      • Xidrf.exe (PID: 6368)
      • Xidrf.exe (PID: 7304)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 3560)
      • Xidrf.exe (PID: 7336)
      • Xidrf.exe (PID: 7836)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 6740)
      • Xidrf.exe (PID: 4980)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 8084)
      • Xidrf.exe (PID: 5464)
      • Xidrf.exe (PID: 8184)
      • Xidrf.exe (PID: 7744)
      • Xidrf.exe (PID: 6856)
      • Xidrf.exe (PID: 2232)
      • Xidrf.exe (PID: 5892)
      • Xidrf.exe (PID: 7108)
      • Xidrf.exe (PID: 7528)
      • Xidrf.exe (PID: 7400)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 6328)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 6768)
      • Xidrf.exe (PID: 4012)
      • Xidrf.exe (PID: 6224)
      • Xidrf.exe (PID: 7248)
      • Xidrf.exe (PID: 6912)
      • Xidrf.exe (PID: 4020)
      • Xidrf.exe (PID: 1200)
      • Xidrf.exe (PID: 7968)
      • Xidrf.exe (PID: 7868)
      • Xidrf.exe (PID: 7688)
      • Xidrf.exe (PID: 7236)
    • Application launched itself

      • Xidrf.exe (PID: 6304)
      • Xidrf.exe (PID: 6356)
      • Xidrf.exe (PID: 6436)
      • Xidrf.exe (PID: 6500)
      • Xidrf.exe (PID: 6568)
      • Xidrf.exe (PID: 6672)
      • Xidrf.exe (PID: 6756)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 6984)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 7064)
      • Xidrf.exe (PID: 7144)
      • Xidrf.exe (PID: 6400)
      • Xidrf.exe (PID: 6276)
      • Xidrf.exe (PID: 6532)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6884)
      • Xidrf.exe (PID: 6788)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 6964)
      • Xidrf.exe (PID: 6324)
      • Xidrf.exe (PID: 6472)
      • Xidrf.exe (PID: 6676)
      • Xidrf.exe (PID: 5432)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 2448)
      • Xidrf.exe (PID: 7308)
      • Xidrf.exe (PID: 7516)
      • Xidrf.exe (PID: 7712)
      • Xidrf.exe (PID: 7928)
      • Xidrf.exe (PID: 7808)
      • Xidrf.exe (PID: 7292)
      • Xidrf.exe (PID: 7784)
      • Xidrf.exe (PID: 5576)
      • Xidrf.exe (PID: 4592)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 6164)
      • Xidrf.exe (PID: 7060)
      • Xidrf.exe (PID: 5888)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6796)
      • Xidrf.exe (PID: 128)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 8056)
      • Xidrf.exe (PID: 1852)
      • Xidrf.exe (PID: 6896)
      • Xidrf.exe (PID: 7704)
      • Xidrf.exe (PID: 7356)
      • Xidrf.exe (PID: 7844)
      • Xidrf.exe (PID: 1228)
      • Xidrf.exe (PID: 7860)
      • Xidrf.exe (PID: 6612)
      • Xidrf.exe (PID: 6576)
      • Xidrf.exe (PID: 6724)
      • Xidrf.exe (PID: 5640)
      • Xidrf.exe (PID: 8044)
      • Xidrf.exe (PID: 6492)
      • Xidrf.exe (PID: 8020)
      • Xidrf.exe (PID: 7128)
      • Xidrf.exe (PID: 7144)
      • Xidrf.exe (PID: 7464)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 8112)
      • Xidrf.exe (PID: 5572)
      • Xidrf.exe (PID: 1416)
      • Xidrf.exe (PID: 8124)
      • Xidrf.exe (PID: 6956)
      • Xidrf.exe (PID: 1016)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 7092)
      • Xidrf.exe (PID: 8160)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 5876)
      • Xidrf.exe (PID: 7100)
      • Xidrf.exe (PID: 236)
      • Xidrf.exe (PID: 8120)
      • Xidrf.exe (PID: 6888)
      • Xidrf.exe (PID: 5788)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 6672)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6736)
      • Xidrf.exe (PID: 8124)
      • Xidrf.exe (PID: 7040)
      • Xidrf.exe (PID: 540)
      • Xidrf.exe (PID: 6812)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 7188)
      • Xidrf.exe (PID: 3620)
      • Xidrf.exe (PID: 7364)
      • Xidrf.exe (PID: 7876)
      • Xidrf.exe (PID: 7728)
      • Xidrf.exe (PID: 7884)
      • Xidrf.exe (PID: 4144)
      • Xidrf.exe (PID: 7948)
      • Xidrf.exe (PID: 4764)
      • Xidrf.exe (PID: 6096)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 6664)
      • Xidrf.exe (PID: 6384)
      • Xidrf.exe (PID: 6544)
      • Xidrf.exe (PID: 6420)
      • Xidrf.exe (PID: 8160)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 6516)
      • Xidrf.exe (PID: 6692)
      • Xidrf.exe (PID: 6676)
      • Xidrf.exe (PID: 2100)
      • Xidrf.exe (PID: 6932)
      • Xidrf.exe (PID: 7300)
      • Xidrf.exe (PID: 8104)
      • Xidrf.exe (PID: 7680)
      • Xidrf.exe (PID: 4160)
      • Xidrf.exe (PID: 6032)
      • Xidrf.exe (PID: 5712)
      • Xidrf.exe (PID: 5788)
      • Xidrf.exe (PID: 7604)
      • Xidrf.exe (PID: 6520)
      • Xidrf.exe (PID: 6236)
      • Xidrf.exe (PID: 7040)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 2792)
      • Xidrf.exe (PID: 6452)
      • Xidrf.exe (PID: 7500)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 6656)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 6208)
      • Xidrf.exe (PID: 7788)
      • Xidrf.exe (PID: 6212)
      • Xidrf.exe (PID: 7736)
      • Xidrf.exe (PID: 7996)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 7432)
      • Xidrf.exe (PID: 236)
      • Xidrf.exe (PID: 8092)
      • Xidrf.exe (PID: 5536)
      • Xidrf.exe (PID: 6520)
      • Xidrf.exe (PID: 6540)
      • Xidrf.exe (PID: 7056)
      • Xidrf.exe (PID: 7236)
      • Xidrf.exe (PID: 6688)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 736)
      • Xidrf.exe (PID: 6340)
      • Xidrf.exe (PID: 8052)
      • Xidrf.exe (PID: 2232)
      • Xidrf.exe (PID: 3188)
      • Xidrf.exe (PID: 8132)
      • Xidrf.exe (PID: 880)
      • Xidrf.exe (PID: 4512)
      • Xidrf.exe (PID: 720)
      • Xidrf.exe (PID: 6584)
      • Xidrf.exe (PID: 6268)
      • Xidrf.exe (PID: 7780)
      • Xidrf.exe (PID: 7816)
      • Xidrf.exe (PID: 1612)
      • Xidrf.exe (PID: 540)
      • Xidrf.exe (PID: 7868)
      • Xidrf.exe (PID: 6616)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 4592)
      • Xidrf.exe (PID: 4968)
      • Xidrf.exe (PID: 6940)
      • Xidrf.exe (PID: 6556)
      • Xidrf.exe (PID: 1868)
      • Xidrf.exe (PID: 3640)
      • Xidrf.exe (PID: 7852)
      • Xidrf.exe (PID: 6876)
      • Xidrf.exe (PID: 6588)
      • Xidrf.exe (PID: 6488)
      • Xidrf.exe (PID: 6368)
      • Xidrf.exe (PID: 7304)
      • Xidrf.exe (PID: 308)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 3560)
      • Xidrf.exe (PID: 1804)
      • Xidrf.exe (PID: 7336)
      • Xidrf.exe (PID: 7836)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 6740)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 8184)
      • Xidrf.exe (PID: 8084)
      • Xidrf.exe (PID: 5464)
      • Xidrf.exe (PID: 4980)
      • Xidrf.exe (PID: 7500)
      • Xidrf.exe (PID: 6884)
      • Xidrf.exe (PID: 6524)
      • Xidrf.exe (PID: 7744)
      • Xidrf.exe (PID: 5892)
      • Xidrf.exe (PID: 6856)
      • Xidrf.exe (PID: 2232)
      • Xidrf.exe (PID: 7108)
      • Xidrf.exe (PID: 7816)
      • Xidrf.exe (PID: 7208)
      • Xidrf.exe (PID: 6932)
      • Xidrf.exe (PID: 7528)
      • Xidrf.exe (PID: 6328)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 7400)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 6768)
      • Xidrf.exe (PID: 836)
      • Xidrf.exe (PID: 4012)
      • Xidrf.exe (PID: 6224)
      • Xidrf.exe (PID: 7248)
      • Xidrf.exe (PID: 7496)
      • Xidrf.exe (PID: 4020)
      • Xidrf.exe (PID: 6912)
      • Xidrf.exe (PID: 1200)
      • Xidrf.exe (PID: 7968)
      • Xidrf.exe (PID: 7696)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 7868)
      • Xidrf.exe (PID: 7844)
      • Xidrf.exe (PID: 7688)
      • Xidrf.exe (PID: 7712)
      • Xidrf.exe (PID: 4504)
      • Xidrf.exe (PID: 7236)
      • Xidrf.exe (PID: 7948)
      • Xidrf.exe (PID: 8012)
      • Xidrf.exe (PID: 4228)
      • Xidrf.exe (PID: 6900)
      • Xidrf.exe (PID: 8148)
      • Xidrf.exe (PID: 7296)
      • Xidrf.exe (PID: 7556)
      • Xidrf.exe (PID: 6984)
      • Xidrf.exe (PID: 8160)
      • Xidrf.exe (PID: 7432)
      • Xidrf.exe (PID: 7052)
      • Xidrf.exe (PID: 7304)
      • Xidrf.exe (PID: 7780)
      • Xidrf.exe (PID: 7336)
      • Xidrf.exe (PID: 2484)
      • Xidrf.exe (PID: 6524)
      • Xidrf.exe (PID: 7288)
      • Xidrf.exe (PID: 6832)
      • Xidrf.exe (PID: 6556)
      • Xidrf.exe (PID: 7116)
      • Xidrf.exe (PID: 7556)
      • Xidrf.exe (PID: 3820)
      • Xidrf.exe (PID: 5268)
      • Xidrf.exe (PID: 3888)
      • Xidrf.exe (PID: 6724)
      • Xidrf.exe (PID: 4640)
      • Xidrf.exe (PID: 6868)
      • Xidrf.exe (PID: 7040)
      • Xidrf.exe (PID: 8048)
      • Xidrf.exe (PID: 7540)
      • Xidrf.exe (PID: 6716)
      • Xidrf.exe (PID: 7024)
      • Xidrf.exe (PID: 6940)
      • Xidrf.exe (PID: 5432)
      • Xidrf.exe (PID: 6452)
      • Xidrf.exe (PID: 7316)
      • Xidrf.exe (PID: 2008)
      • Xidrf.exe (PID: 5000)
      • Xidrf.exe (PID: 2680)
      • Xidrf.exe (PID: 8004)
      • Xidrf.exe (PID: 6944)
      • Xidrf.exe (PID: 7004)
      • Xidrf.exe (PID: 4144)
      • Xidrf.exe (PID: 6096)
      • Xidrf.exe (PID: 3952)
      • Xidrf.exe (PID: 6968)
      • Xidrf.exe (PID: 1380)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 7620)
      • Xidrf.exe (PID: 6928)
      • Xidrf.exe (PID: 6488)
      • Xidrf.exe (PID: 1536)
      • Xidrf.exe (PID: 7660)
      • Xidrf.exe (PID: 7000)
      • Xidrf.exe (PID: 6860)
      • Xidrf.exe (PID: 2448)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 2612)
      • Xidrf.exe (PID: 5888)
      • Xidrf.exe (PID: 7096)
      • Xidrf.exe (PID: 6192)
      • Xidrf.exe (PID: 3552)
      • Xidrf.exe (PID: 3988)
      • Xidrf.exe (PID: 3820)
      • Xidrf.exe (PID: 5684)
      • Xidrf.exe (PID: 3128)
      • Xidrf.exe (PID: 5460)
      • Xidrf.exe (PID: 6180)
      • Xidrf.exe (PID: 7152)
      • Xidrf.exe (PID: 7932)
      • Xidrf.exe (PID: 6628)
      • Xidrf.exe (PID: 4972)
      • Xidrf.exe (PID: 1864)
      • Xidrf.exe (PID: 7964)
      • Xidrf.exe (PID: 3744)
      • Xidrf.exe (PID: 6240)
      • Xidrf.exe (PID: 6952)
      • Xidrf.exe (PID: 3568)
      • Xidrf.exe (PID: 8088)
      • Xidrf.exe (PID: 7800)
      • Xidrf.exe (PID: 7856)
    • Starts itself from another location

      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 7516)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 8032)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6820)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7964)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 6280)
      • CLIENT-BUILT.EXE (PID: 2380)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 8024)
      • CLIENT-BUILT.EXE (PID: 7748)
      • CLIENT-BUILT.EXE (PID: 4872)
      • CLIENT-BUILT.EXE (PID: 6172)
      • CLIENT-BUILT.EXE (PID: 5212)
      • CLIENT-BUILT.EXE (PID: 2120)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 5400)
      • CLIENT-BUILT.EXE (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 7904)
      • CLIENT-BUILT.EXE (PID: 7952)
      • CLIENT-BUILT.EXE (PID: 7536)
      • CLIENT-BUILT.EXE (PID: 7268)
      • CLIENT-BUILT.EXE (PID: 8112)
      • CLIENT-BUILT.EXE (PID: 3032)
      • CLIENT-BUILT.EXE (PID: 1064)
      • CLIENT-BUILT.EXE (PID: 6032)
      • CLIENT-BUILT.EXE (PID: 3172)
    • Checks for external IP

      • svchost.exe (PID: 2192)
      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 5432)
      • CLIENT-BUILT.EXE (PID: 7516)
      • CLIENT-BUILT.EXE (PID: 7880)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 8032)
      • CLIENT-BUILT.EXE (PID: 8036)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 7556)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6512)
      • CLIENT-BUILT.EXE (PID: 6976)
      • CLIENT-BUILT.EXE (PID: 7964)
      • CLIENT-BUILT.EXE (PID: 5128)
      • CLIENT-BUILT.EXE (PID: 6820)
      • CLIENT-BUILT.EXE (PID: 7900)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 7272)
      • CLIENT-BUILT.EXE (PID: 2100)
      • CLIENT-BUILT.EXE (PID: 6280)
      • CLIENT-BUILT.EXE (PID: 6760)
      • CLIENT-BUILT.EXE (PID: 2380)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 7592)
      • CLIENT-BUILT.EXE (PID: 7488)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 7044)
      • CLIENT-BUILT.EXE (PID: 8024)
      • CLIENT-BUILT.EXE (PID: 7748)
      • CLIENT-BUILT.EXE (PID: 4872)
      • CLIENT-BUILT.EXE (PID: 6172)
      • CLIENT-BUILT.EXE (PID: 7912)
      • CLIENT-BUILT.EXE (PID: 5212)
      • CLIENT-BUILT.EXE (PID: 2120)
      • CLIENT-BUILT.EXE (PID: 128)
      • CLIENT-BUILT.EXE (PID: 7348)
      • CLIENT-BUILT.EXE (PID: 5004)
      • CLIENT-BUILT.EXE (PID: 6332)
      • CLIENT-BUILT.EXE (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 768)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 2408)
      • CLIENT-BUILT.EXE (PID: 7952)
      • CLIENT-BUILT.EXE (PID: 4392)
      • CLIENT-BUILT.EXE (PID: 8120)
      • CLIENT-BUILT.EXE (PID: 7268)
      • CLIENT-BUILT.EXE (PID: 7904)
      • CLIENT-BUILT.EXE (PID: 7536)
      • CLIENT-BUILT.EXE (PID: 8112)
      • CLIENT-BUILT.EXE (PID: 3208)
      • CLIENT-BUILT.EXE (PID: 3032)
      • CLIENT-BUILT.EXE (PID: 7496)
      • CLIENT-BUILT.EXE (PID: 1064)
      • CLIENT-BUILT.EXE (PID: 7980)
      • CLIENT-BUILT.EXE (PID: 6032)
      • CLIENT-BUILT.EXE (PID: 4872)
      • CLIENT-BUILT.EXE (PID: 6756)
  • INFO

    • Reads the computer name

      • Xidrf.exe (PID: 6304)
      • Xidrf.exe (PID: 6356)
      • Xidrf.exe (PID: 6436)
      • Xidrf.exe (PID: 6500)
      • CLIENT-BUILT.EXE (PID: 6652)
      • CLIENT-BUILT.EXE (PID: 6552)
      • CLIENT-BUILT.EXE (PID: 6484)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6420)
      • Xidrf.exe (PID: 6568)
      • CLIENT-BUILT.EXE (PID: 6736)
      • CLIENT-BUILT.EXE (PID: 6812)
      • Xidrf.exe (PID: 6756)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 6672)
      • CLIENT-BUILT.EXE (PID: 6888)
      • CLIENT-BUILT.EXE (PID: 6968)
      • Xidrf.exe (PID: 6984)
      • CLIENT-BUILT.EXE (PID: 7048)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 7144)
      • CLIENT-BUILT.EXE (PID: 6224)
      • Xidrf.exe (PID: 6276)
      • Xidrf.exe (PID: 7064)
      • CLIENT-BUILT.EXE (PID: 7124)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 6480)
      • Xidrf.exe (PID: 6400)
      • Xidrf.exe (PID: 6532)
      • CLIENT-BUILT.EXE (PID: 6588)
      • Xidrf.exe (PID: 6640)
      • CLIENT-BUILT.EXE (PID: 6932)
      • CLIENT-BUILT.EXE (PID: 6708)
      • Xidrf.exe (PID: 6788)
      • CLIENT-BUILT.EXE (PID: 6844)
      • Xidrf.exe (PID: 6884)
      • CLIENT-BUILT.EXE (PID: 6984)
      • Xidrf.exe (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 7164)
      • Xidrf.exe (PID: 6324)
      • Xidrf.exe (PID: 6964)
      • CLIENT-BUILT.EXE (PID: 6460)
      • Xidrf.exe (PID: 6472)
      • CLIENT-BUILT.EXE (PID: 6512)
      • Xidrf.exe (PID: 6676)
      • Xidrf.exe (PID: 2448)
      • CLIENT-BUILT.EXE (PID: 3612)
      • CLIENT-BUILT.EXE (PID: 4120)
      • CLIENT-BUILT.EXE (PID: 6176)
      • Xidrf.exe (PID: 5432)
      • Xidrf.exe (PID: 6272)
      • CLIENT-BUILT.EXE (PID: 7232)
      • Xidrf.exe (PID: 7516)
      • CLIENT-BUILT.EXE (PID: 7676)
      • Xidrf.exe (PID: 7712)
      • CLIENT-BUILT.EXE (PID: 7460)
      • Xidrf.exe (PID: 7808)
      • CLIENT-BUILT.EXE (PID: 7920)
      • Xidrf.exe (PID: 7928)
      • CLIENT-BUILT.EXE (PID: 7796)
      • CLIENT-BUILT.EXE (PID: 5432)
      • Xidrf.exe (PID: 7784)
      • CLIENT-BUILT.EXE (PID: 7256)
      • Xidrf.exe (PID: 5576)
      • CLIENT-BUILT.EXE (PID: 7880)
      • Xidrf.exe (PID: 4592)
      • Xidrf.exe (PID: 1140)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 8036)
      • Xidrf.exe (PID: 7060)
      • Xidrf.exe (PID: 6164)
      • Xidrf.exe (PID: 5888)
      • Xidrf.exe (PID: 6796)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 6436)
      • CLIENT-BUILT.EXE (PID: 8080)
      • Client.exe (PID: 6176)
      • Xidrf.exe (PID: 6880)
      • CLIENT-BUILT.EXE (PID: 7500)
      • Client.exe (PID: 6320)
      • CLIENT-BUILT.EXE (PID: 3640)
      • Xidrf.exe (PID: 1852)
      • CLIENT-BUILT.EXE (PID: 8032)
      • Xidrf.exe (PID: 128)
      • CLIENT-BUILT.EXE (PID: 6976)
      • Client.exe (PID: 7044)
      • Xidrf.exe (PID: 7356)
      • CLIENT-BUILT.EXE (PID: 8148)
      • Xidrf.exe (PID: 6896)
      • Client.exe (PID: 7344)
      • CLIENT-BUILT.EXE (PID: 6348)
      • Xidrf.exe (PID: 7860)
      • Xidrf.exe (PID: 7704)
      • Xidrf.exe (PID: 7844)
      • CLIENT-BUILT.EXE (PID: 536)
      • Client.exe (PID: 7408)
      • CLIENT-BUILT.EXE (PID: 7776)
      • CLIENT-BUILT.EXE (PID: 6820)
      • Xidrf.exe (PID: 8044)
      • Xidrf.exe (PID: 6724)
      • Client.exe (PID: 6660)
      • CLIENT-BUILT.EXE (PID: 5528)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7964)
      • Xidrf.exe (PID: 6492)
      • Xidrf.exe (PID: 8020)
      • CLIENT-BUILT.EXE (PID: 7272)
      • Xidrf.exe (PID: 7144)
      • CLIENT-BUILT.EXE (PID: 4912)
      • Client.exe (PID: 2008)
      • CLIENT-BUILT.EXE (PID: 4628)
      • CLIENT-BUILT.EXE (PID: 7696)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 1416)
      • CLIENT-BUILT.EXE (PID: 6096)
      • CLIENT-BUILT.EXE (PID: 5696)
      • Xidrf.exe (PID: 6956)
      • Xidrf.exe (PID: 5572)
      • Xidrf.exe (PID: 8124)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 6760)
      • Client.exe (PID: 6736)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 1016)
      • CLIENT-BUILT.EXE (PID: 7996)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 4472)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 7100)
      • Xidrf.exe (PID: 5876)
      • CLIENT-BUILT.EXE (PID: 6952)
      • CLIENT-BUILT.EXE (PID: 7592)
      • Client.exe (PID: 6804)
      • CLIENT-BUILT.EXE (PID: 7344)
      • CLIENT-BUILT.EXE (PID: 7896)
      • CLIENT-BUILT.EXE (PID: 8100)
      • Xidrf.exe (PID: 6888)
      • CLIENT-BUILT.EXE (PID: 7940)
      • Xidrf.exe (PID: 6672)
      • Client.exe (PID: 7648)
      • CLIENT-BUILT.EXE (PID: 7776)
      • CLIENT-BUILT.EXE (PID: 8052)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6736)
      • CLIENT-BUILT.EXE (PID: 3508)
      • CLIENT-BUILT.EXE (PID: 6396)
      • Xidrf.exe (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 6212)
      • CLIENT-BUILT.EXE (PID: 6436)
      • Xidrf.exe (PID: 540)
      • CLIENT-BUILT.EXE (PID: 6200)
      • Xidrf.exe (PID: 7728)
      • Xidrf.exe (PID: 7188)
      • Xidrf.exe (PID: 7364)
      • Xidrf.exe (PID: 7876)
      • CLIENT-BUILT.EXE (PID: 7104)
      • Xidrf.exe (PID: 4144)
      • Xidrf.exe (PID: 7884)
      • CLIENT-BUILT.EXE (PID: 6600)
      • CLIENT-BUILT.EXE (PID: 4628)
      • Xidrf.exe (PID: 7948)
      • CLIENT-BUILT.EXE (PID: 7944)
      • Xidrf.exe (PID: 6384)
      • CLIENT-BUILT.EXE (PID: 3260)
      • CLIENT-BUILT.EXE (PID: 6496)
      • CLIENT-BUILT.EXE (PID: 5804)
      • Xidrf.exe (PID: 6664)
      • Xidrf.exe (PID: 6420)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 6544)
      • Xidrf.exe (PID: 236)
      • CLIENT-BUILT.EXE (PID: 7088)
      • Xidrf.exe (PID: 8160)
      • CLIENT-BUILT.EXE (PID: 6376)
      • CLIENT-BUILT.EXE (PID: 6408)
      • Xidrf.exe (PID: 1140)
      • CLIENT-BUILT.EXE (PID: 6176)
      • CLIENT-BUILT.EXE (PID: 5920)
      • CLIENT-BUILT.EXE (PID: 5128)
      • Xidrf.exe (PID: 6676)
      • CLIENT-BUILT.EXE (PID: 7044)
      • CLIENT-BUILT.EXE (PID: 7688)
      • CLIENT-BUILT.EXE (PID: 6844)
      • CLIENT-BUILT.EXE (PID: 8024)
      • Xidrf.exe (PID: 4160)
      • Xidrf.exe (PID: 6032)
      • Xidrf.exe (PID: 5788)
      • Client.exe (PID: 6424)
      • CLIENT-BUILT.EXE (PID: 7296)
      • CLIENT-BUILT.EXE (PID: 7056)
      • CLIENT-BUILT.EXE (PID: 6696)
      • Xidrf.exe (PID: 5712)
      • CLIENT-BUILT.EXE (PID: 8184)
      • Xidrf.exe (PID: 7604)
      • CLIENT-BUILT.EXE (PID: 3692)
      • CLIENT-BUILT.EXE (PID: 4592)
      • CLIENT-BUILT.EXE (PID: 6616)
      • Xidrf.exe (PID: 7040)
      • Xidrf.exe (PID: 6236)
      • Xidrf.exe (PID: 6452)
      • CLIENT-BUILT.EXE (PID: 1852)
      • CLIENT-BUILT.EXE (PID: 7196)
      • Xidrf.exe (PID: 6448)
      • CLIENT-BUILT.EXE (PID: 5308)
      • Xidrf.exe (PID: 6656)
      • Xidrf.exe (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 7424)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 6212)
      • CLIENT-BUILT.EXE (PID: 8004)
      • Xidrf.exe (PID: 236)
      • CLIENT-BUILT.EXE (PID: 2624)
      • Xidrf.exe (PID: 7432)
      • CLIENT-BUILT.EXE (PID: 8072)
      • Xidrf.exe (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 7604)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 3540)
      • Xidrf.exe (PID: 7236)
      • Xidrf.exe (PID: 7056)
      • Xidrf.exe (PID: 6540)
      • Xidrf.exe (PID: 6688)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 736)
      • Xidrf.exe (PID: 6340)
      • CLIENT-BUILT.EXE (PID: 2100)
      • Xidrf.exe (PID: 720)
      • CLIENT-BUILT.EXE (PID: 7252)
      • Xidrf.exe (PID: 880)
      • CLIENT-BUILT.EXE (PID: 7400)
      • CLIENT-BUILT.EXE (PID: 7092)
      • Xidrf.exe (PID: 7868)
      • CLIENT-BUILT.EXE (PID: 6312)
      • Xidrf.exe (PID: 6616)
      • Xidrf.exe (PID: 6556)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 4968)
      • Xidrf.exe (PID: 6588)
      • CLIENT-BUILT.EXE (PID: 6700)
      • CLIENT-BUILT.EXE (PID: 3188)
      • Xidrf.exe (PID: 6488)
      • Xidrf.exe (PID: 6368)
      • Xidrf.exe (PID: 7304)
      • Client.exe (PID: 2736)
      • Xidrf.exe (PID: 7336)
      • Xidrf.exe (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 7248)
      • Xidrf.exe (PID: 4980)
      • Xidrf.exe (PID: 6828)
      • CLIENT-BUILT.EXE (PID: 6184)
      • Xidrf.exe (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 8040)
      • Xidrf.exe (PID: 2232)
      • Xidrf.exe (PID: 7816)
      • Xidrf.exe (PID: 7528)
      • Xidrf.exe (PID: 7108)
      • Xidrf.exe (PID: 7400)
      • Xidrf.exe (PID: 836)
      • CLIENT-BUILT.EXE (PID: 3988)
      • CLIENT-BUILT.EXE (PID: 7912)
      • Client.exe (PID: 6308)
      • Xidrf.exe (PID: 7496)
      • Xidrf.exe (PID: 6224)
      • CLIENT-BUILT.EXE (PID: 128)
      • Xidrf.exe (PID: 4020)
      • Xidrf.exe (PID: 1200)
      • CLIENT-BUILT.EXE (PID: 5004)
      • Xidrf.exe (PID: 7868)
      • CLIENT-BUILT.EXE (PID: 6744)
      • CLIENT-BUILT.EXE (PID: 3560)
      • Xidrf.exe (PID: 7688)
      • Xidrf.exe (PID: 7948)
      • CLIENT-BUILT.EXE (PID: 7952)
    • Checks supported languages

      • Xidrf.exe (PID: 6304)
      • Xidrf.exe (PID: 6356)
      • CLIENT-BUILT.EXE (PID: 6348)
      • Xidrf.exe (PID: 6436)
      • CLIENT-BUILT.EXE (PID: 6484)
      • Xidrf.exe (PID: 6500)
      • CLIENT-BUILT.EXE (PID: 6552)
      • CLIENT-BUILT.EXE (PID: 6420)
      • Xidrf.exe (PID: 6568)
      • CLIENT-BUILT.EXE (PID: 6652)
      • CLIENT-BUILT.EXE (PID: 6736)
      • Xidrf.exe (PID: 6756)
      • CLIENT-BUILT.EXE (PID: 6812)
      • Xidrf.exe (PID: 6828)
      • CLIENT-BUILT.EXE (PID: 6888)
      • Xidrf.exe (PID: 6672)
      • CLIENT-BUILT.EXE (PID: 6968)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 6984)
      • Xidrf.exe (PID: 7064)
      • CLIENT-BUILT.EXE (PID: 7048)
      • CLIENT-BUILT.EXE (PID: 7124)
      • Xidrf.exe (PID: 7144)
      • CLIENT-BUILT.EXE (PID: 6224)
      • Xidrf.exe (PID: 6276)
      • CLIENT-BUILT.EXE (PID: 6480)
      • Xidrf.exe (PID: 6532)
      • Xidrf.exe (PID: 6400)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 6588)
      • Xidrf.exe (PID: 6640)
      • CLIENT-BUILT.EXE (PID: 6708)
      • Xidrf.exe (PID: 6788)
      • CLIENT-BUILT.EXE (PID: 6844)
      • CLIENT-BUILT.EXE (PID: 6932)
      • Xidrf.exe (PID: 6884)
      • Xidrf.exe (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 6984)
      • CLIENT-BUILT.EXE (PID: 7164)
      • Xidrf.exe (PID: 6324)
      • Xidrf.exe (PID: 6964)
      • CLIENT-BUILT.EXE (PID: 6460)
      • Xidrf.exe (PID: 6472)
      • Xidrf.exe (PID: 6676)
      • CLIENT-BUILT.EXE (PID: 6512)
      • CLIENT-BUILT.EXE (PID: 4120)
      • Xidrf.exe (PID: 2448)
      • CLIENT-BUILT.EXE (PID: 3612)
      • Xidrf.exe (PID: 5432)
      • CLIENT-BUILT.EXE (PID: 6176)
      • Xidrf.exe (PID: 6272)
      • CLIENT-BUILT.EXE (PID: 7232)
      • CLIENT-BUILT.EXE (PID: 7676)
      • Xidrf.exe (PID: 7712)
      • CLIENT-BUILT.EXE (PID: 7460)
      • Xidrf.exe (PID: 7516)
      • Xidrf.exe (PID: 7808)
      • CLIENT-BUILT.EXE (PID: 7920)
      • Xidrf.exe (PID: 7928)
      • CLIENT-BUILT.EXE (PID: 5432)
      • Xidrf.exe (PID: 7292)
      • CLIENT-BUILT.EXE (PID: 7796)
      • Xidrf.exe (PID: 7784)
      • Xidrf.exe (PID: 5576)
      • Xidrf.exe (PID: 4592)
      • CLIENT-BUILT.EXE (PID: 7256)
      • Xidrf.exe (PID: 1140)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 7880)
      • Xidrf.exe (PID: 6164)
      • CLIENT-BUILT.EXE (PID: 8036)
      • Xidrf.exe (PID: 7060)
      • CLIENT-BUILT.EXE (PID: 8080)
      • Xidrf.exe (PID: 5888)
      • Client.exe (PID: 6176)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 6436)
      • Xidrf.exe (PID: 6796)
      • CLIENT-BUILT.EXE (PID: 7500)
      • Client.exe (PID: 6320)
      • Xidrf.exe (PID: 128)
      • CLIENT-BUILT.EXE (PID: 3640)
      • CLIENT-BUILT.EXE (PID: 8032)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 8056)
      • CLIENT-BUILT.EXE (PID: 8148)
      • Client.exe (PID: 7044)
      • Xidrf.exe (PID: 1852)
      • CLIENT-BUILT.EXE (PID: 6976)
      • Xidrf.exe (PID: 6896)
      • Xidrf.exe (PID: 7356)
      • Xidrf.exe (PID: 7860)
      • CLIENT-BUILT.EXE (PID: 6348)
      • Xidrf.exe (PID: 7704)
      • Client.exe (PID: 7344)
      • CLIENT-BUILT.EXE (PID: 536)
      • CLIENT-BUILT.EXE (PID: 6820)
      • Xidrf.exe (PID: 7844)
      • CLIENT-BUILT.EXE (PID: 7776)
      • Xidrf.exe (PID: 8044)
      • Client.exe (PID: 7408)
      • Xidrf.exe (PID: 6724)
      • CLIENT-BUILT.EXE (PID: 5528)
      • CLIENT-BUILT.EXE (PID: 5776)
      • Client.exe (PID: 6660)
      • Client.exe (PID: 2008)
      • Xidrf.exe (PID: 6492)
      • CLIENT-BUILT.EXE (PID: 7964)
      • CLIENT-BUILT.EXE (PID: 4912)
      • Xidrf.exe (PID: 8020)
      • CLIENT-BUILT.EXE (PID: 7272)
      • Xidrf.exe (PID: 7144)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 4628)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 1416)
      • CLIENT-BUILT.EXE (PID: 5696)
      • CLIENT-BUILT.EXE (PID: 6096)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 5572)
      • Xidrf.exe (PID: 6956)
      • CLIENT-BUILT.EXE (PID: 6188)
      • Xidrf.exe (PID: 8124)
      • CLIENT-BUILT.EXE (PID: 6760)
      • Client.exe (PID: 6736)
      • CLIENT-BUILT.EXE (PID: 7996)
      • Xidrf.exe (PID: 2624)
      • CLIENT-BUILT.EXE (PID: 4472)
      • Xidrf.exe (PID: 1016)
      • Xidrf.exe (PID: 7092)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 5876)
      • Xidrf.exe (PID: 7100)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 6952)
      • Client.exe (PID: 6804)
      • CLIENT-BUILT.EXE (PID: 7592)
      • Xidrf.exe (PID: 236)
      • CLIENT-BUILT.EXE (PID: 7344)
      • Xidrf.exe (PID: 6272)
      • CLIENT-BUILT.EXE (PID: 8100)
      • Xidrf.exe (PID: 6888)
      • CLIENT-BUILT.EXE (PID: 7896)
      • CLIENT-BUILT.EXE (PID: 7940)
      • Xidrf.exe (PID: 6672)
      • Client.exe (PID: 7648)
      • CLIENT-BUILT.EXE (PID: 7776)
      • CLIENT-BUILT.EXE (PID: 8052)
      • Xidrf.exe (PID: 8124)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6736)
      • CLIENT-BUILT.EXE (PID: 3508)
      • CLIENT-BUILT.EXE (PID: 6436)
      • CLIENT-BUILT.EXE (PID: 6396)
      • Xidrf.exe (PID: 7040)
      • Xidrf.exe (PID: 6812)
      • Xidrf.exe (PID: 540)
      • CLIENT-BUILT.EXE (PID: 6212)
      • Xidrf.exe (PID: 7188)
      • CLIENT-BUILT.EXE (PID: 6200)
      • Xidrf.exe (PID: 7728)
      • Xidrf.exe (PID: 7876)
      • CLIENT-BUILT.EXE (PID: 7104)
      • Xidrf.exe (PID: 7364)
      • CLIENT-BUILT.EXE (PID: 6432)
      • CLIENT-BUILT.EXE (PID: 4628)
      • CLIENT-BUILT.EXE (PID: 6600)
      • Xidrf.exe (PID: 4144)
      • Xidrf.exe (PID: 6096)
      • CLIENT-BUILT.EXE (PID: 7016)
      • CLIENT-BUILT.EXE (PID: 3260)
      • Xidrf.exe (PID: 4764)
      • Xidrf.exe (PID: 7948)
      • Xidrf.exe (PID: 7956)
      • CLIENT-BUILT.EXE (PID: 7944)
      • CLIENT-BUILT.EXE (PID: 6496)
      • Xidrf.exe (PID: 6384)
      • Xidrf.exe (PID: 6664)
      • Xidrf.exe (PID: 6420)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 6544)
      • CLIENT-BUILT.EXE (PID: 7088)
      • CLIENT-BUILT.EXE (PID: 6408)
      • CLIENT-BUILT.EXE (PID: 6376)
      • Xidrf.exe (PID: 8160)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 6692)
      • CLIENT-BUILT.EXE (PID: 5128)
      • Xidrf.exe (PID: 6516)
      • CLIENT-BUILT.EXE (PID: 6176)
      • CLIENT-BUILT.EXE (PID: 5920)
      • CLIENT-BUILT.EXE (PID: 6844)
      • Xidrf.exe (PID: 2100)
      • Xidrf.exe (PID: 6932)
      • CLIENT-BUILT.EXE (PID: 7688)
      • CLIENT-BUILT.EXE (PID: 8024)
      • Xidrf.exe (PID: 7680)
      • Xidrf.exe (PID: 8104)
      • Xidrf.exe (PID: 4160)
      • CLIENT-BUILT.EXE (PID: 7748)
      • Xidrf.exe (PID: 5788)
      • Xidrf.exe (PID: 6032)
      • CLIENT-BUILT.EXE (PID: 7296)
      • CLIENT-BUILT.EXE (PID: 6696)
      • CLIENT-BUILT.EXE (PID: 7056)
      • Xidrf.exe (PID: 5712)
      • Client.exe (PID: 6580)
      • Xidrf.exe (PID: 7604)
      • Xidrf.exe (PID: 6236)
      • CLIENT-BUILT.EXE (PID: 3692)
      • CLIENT-BUILT.EXE (PID: 4592)
      • CLIENT-BUILT.EXE (PID: 6616)
      • Xidrf.exe (PID: 7040)
      • CLIENT-BUILT.EXE (PID: 1852)
      • Xidrf.exe (PID: 2792)
      • CLIENT-BUILT.EXE (PID: 7196)
      • Xidrf.exe (PID: 6448)
      • CLIENT-BUILT.EXE (PID: 5308)
      • Xidrf.exe (PID: 6452)
      • CLIENT-BUILT.EXE (PID: 8172)
      • Xidrf.exe (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 8152)
      • Xidrf.exe (PID: 6656)
      • CLIENT-BUILT.EXE (PID: 7424)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 7788)
      • CLIENT-BUILT.EXE (PID: 8004)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 6208)
      • Xidrf.exe (PID: 6212)
      • Xidrf.exe (PID: 7996)
      • CLIENT-BUILT.EXE (PID: 7260)
      • Xidrf.exe (PID: 7736)
      • CLIENT-BUILT.EXE (PID: 6436)
      • CLIENT-BUILT.EXE (PID: 2624)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 7432)
      • Xidrf.exe (PID: 6520)
      • Xidrf.exe (PID: 236)
      • CLIENT-BUILT.EXE (PID: 8072)
      • Xidrf.exe (PID: 8092)
      • Xidrf.exe (PID: 7056)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 5404)
      • CLIENT-BUILT.EXE (PID: 7604)
      • Xidrf.exe (PID: 6540)
      • CLIENT-BUILT.EXE (PID: 3540)
      • CLIENT-BUILT.EXE (PID: 6696)
      • Xidrf.exe (PID: 7236)
      • Xidrf.exe (PID: 6688)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 736)
      • CLIENT-BUILT.EXE (PID: 7152)
      • Xidrf.exe (PID: 8052)
      • Xidrf.exe (PID: 6340)
      • CLIENT-BUILT.EXE (PID: 3792)
      • CLIENT-BUILT.EXE (PID: 7280)
      • Client.exe (PID: 1200)
      • Xidrf.exe (PID: 3188)
      • CLIENT-BUILT.EXE (PID: 2100)
      • Xidrf.exe (PID: 720)
      • CLIENT-BUILT.EXE (PID: 7884)
      • CLIENT-BUILT.EXE (PID: 7400)
      • CLIENT-BUILT.EXE (PID: 7252)
      • Xidrf.exe (PID: 880)
      • CLIENT-BUILT.EXE (PID: 7092)
      • Xidrf.exe (PID: 7868)
      • Xidrf.exe (PID: 6556)
      • Xidrf.exe (PID: 6880)
      • CLIENT-BUILT.EXE (PID: 6312)
      • Xidrf.exe (PID: 6616)
      • Xidrf.exe (PID: 4968)
      • Xidrf.exe (PID: 6940)
      • Xidrf.exe (PID: 1868)
      • CLIENT-BUILT.EXE (PID: 6700)
      • Xidrf.exe (PID: 308)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 6172)
      • Xidrf.exe (PID: 7304)
      • CLIENT-BUILT.EXE (PID: 1480)
      • Xidrf.exe (PID: 6272)
      • CLIENT-BUILT.EXE (PID: 8016)
      • Xidrf.exe (PID: 3560)
      • Xidrf.exe (PID: 1804)
      • CLIENT-BUILT.EXE (PID: 3564)
      • Xidrf.exe (PID: 6448)
      • CLIENT-BUILT.EXE (PID: 7248)
      • Xidrf.exe (PID: 7836)
      • CLIENT-BUILT.EXE (PID: 7212)
      • Xidrf.exe (PID: 6828)
      • CLIENT-BUILT.EXE (PID: 1868)
      • Xidrf.exe (PID: 6740)
      • Xidrf.exe (PID: 8184)
      • Xidrf.exe (PID: 5464)
      • Xidrf.exe (PID: 4980)
      • Xidrf.exe (PID: 7500)
      • Xidrf.exe (PID: 6884)
      • CLIENT-BUILT.EXE (PID: 7760)
      • Xidrf.exe (PID: 6524)
      • Xidrf.exe (PID: 7744)
      • Xidrf.exe (PID: 5892)
      • CLIENT-BUILT.EXE (PID: 8040)
      • Xidrf.exe (PID: 6856)
      • CLIENT-BUILT.EXE (PID: 7516)
      • Xidrf.exe (PID: 7108)
      • Xidrf.exe (PID: 7208)
      • CLIENT-BUILT.EXE (PID: 3988)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 6328)
      • Xidrf.exe (PID: 440)
      • CLIENT-BUILT.EXE (PID: 7912)
      • Xidrf.exe (PID: 6768)
      • Client.exe (PID: 6308)
      • CLIENT-BUILT.EXE (PID: 7144)
      • Xidrf.exe (PID: 7248)
      • Xidrf.exe (PID: 4012)
      • Xidrf.exe (PID: 6912)
      • CLIENT-BUILT.EXE (PID: 128)
      • CLIENT-BUILT.EXE (PID: 7348)
      • Xidrf.exe (PID: 1200)
      • CLIENT-BUILT.EXE (PID: 5400)
      • Xidrf.exe (PID: 7968)
      • Xidrf.exe (PID: 7696)
      • Xidrf.exe (PID: 4008)
      • CLIENT-BUILT.EXE (PID: 6744)
      • Client.exe (PID: 7000)
      • CLIENT-BUILT.EXE (PID: 3208)
      • Xidrf.exe (PID: 7688)
      • CLIENT-BUILT.EXE (PID: 6332)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 7104)
      • Xidrf.exe (PID: 7236)
    • Create files in a temporary directory

      • Xidrf.exe (PID: 6304)
    • Process checks computer location settings

      • Xidrf.exe (PID: 6304)
      • Xidrf.exe (PID: 6356)
      • Xidrf.exe (PID: 6436)
      • Xidrf.exe (PID: 6568)
      • Xidrf.exe (PID: 6500)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 6672)
      • Xidrf.exe (PID: 6756)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 6984)
      • Xidrf.exe (PID: 7144)
      • Xidrf.exe (PID: 7064)
      • Xidrf.exe (PID: 6400)
      • Xidrf.exe (PID: 6276)
      • Xidrf.exe (PID: 6532)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6884)
      • Xidrf.exe (PID: 6788)
      • Xidrf.exe (PID: 6964)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 6472)
      • Xidrf.exe (PID: 6324)
      • Xidrf.exe (PID: 6676)
      • Xidrf.exe (PID: 2448)
      • Xidrf.exe (PID: 5432)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 7516)
      • Xidrf.exe (PID: 7712)
      • Xidrf.exe (PID: 7808)
      • Xidrf.exe (PID: 7928)
      • Xidrf.exe (PID: 7784)
      • Xidrf.exe (PID: 5576)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 4592)
      • Xidrf.exe (PID: 6164)
      • Xidrf.exe (PID: 7060)
      • Xidrf.exe (PID: 5888)
      • Xidrf.exe (PID: 6796)
      • Xidrf.exe (PID: 128)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 1852)
      • Xidrf.exe (PID: 6896)
      • Xidrf.exe (PID: 7704)
      • Xidrf.exe (PID: 7356)
      • Xidrf.exe (PID: 7844)
      • Xidrf.exe (PID: 7860)
      • Xidrf.exe (PID: 6724)
      • Xidrf.exe (PID: 8044)
      • Xidrf.exe (PID: 8020)
      • Xidrf.exe (PID: 6492)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 7144)
      • Xidrf.exe (PID: 1416)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 5572)
      • Xidrf.exe (PID: 6956)
      • Xidrf.exe (PID: 8124)
      • Xidrf.exe (PID: 1016)
      • Xidrf.exe (PID: 2624)
      • Xidrf.exe (PID: 6908)
      • Xidrf.exe (PID: 7100)
      • Xidrf.exe (PID: 5876)
      • Xidrf.exe (PID: 236)
      • Xidrf.exe (PID: 6888)
      • Xidrf.exe (PID: 6672)
      • Xidrf.exe (PID: 6640)
      • Xidrf.exe (PID: 6736)
      • Xidrf.exe (PID: 6812)
      • Xidrf.exe (PID: 540)
      • Xidrf.exe (PID: 7188)
      • Xidrf.exe (PID: 7364)
      • Xidrf.exe (PID: 7876)
      • Xidrf.exe (PID: 7728)
      • Xidrf.exe (PID: 4144)
      • Xidrf.exe (PID: 4764)
      • Xidrf.exe (PID: 7948)
      • Xidrf.exe (PID: 6096)
      • Xidrf.exe (PID: 7956)
      • Xidrf.exe (PID: 6384)
      • Xidrf.exe (PID: 6664)
      • Xidrf.exe (PID: 6420)
      • Xidrf.exe (PID: 6544)
      • Xidrf.exe (PID: 1140)
      • Xidrf.exe (PID: 6692)
      • Xidrf.exe (PID: 6516)
      • Xidrf.exe (PID: 2100)
      • Xidrf.exe (PID: 6932)
      • Xidrf.exe (PID: 7680)
      • Xidrf.exe (PID: 8104)
      • Xidrf.exe (PID: 4160)
      • Xidrf.exe (PID: 6032)
      • Xidrf.exe (PID: 5712)
      • Xidrf.exe (PID: 5788)
      • Xidrf.exe (PID: 7604)
      • Xidrf.exe (PID: 7040)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 2792)
      • Xidrf.exe (PID: 7500)
      • Xidrf.exe (PID: 6452)
      • Xidrf.exe (PID: 7544)
      • Xidrf.exe (PID: 7788)
      • Xidrf.exe (PID: 6656)
      • Xidrf.exe (PID: 6212)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 6208)
      • Xidrf.exe (PID: 7996)
      • Xidrf.exe (PID: 236)
      • Xidrf.exe (PID: 7104)
      • Xidrf.exe (PID: 7432)
      • Xidrf.exe (PID: 8092)
      • Xidrf.exe (PID: 6520)
      • Xidrf.exe (PID: 6540)
      • Xidrf.exe (PID: 7056)
      • Xidrf.exe (PID: 7236)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 6340)
      • Xidrf.exe (PID: 8052)
      • Xidrf.exe (PID: 3188)
      • Xidrf.exe (PID: 880)
      • Xidrf.exe (PID: 720)
      • Xidrf.exe (PID: 7868)
      • Xidrf.exe (PID: 6616)
      • Xidrf.exe (PID: 6556)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 4968)
      • Xidrf.exe (PID: 6940)
      • Xidrf.exe (PID: 308)
      • Xidrf.exe (PID: 7304)
      • Xidrf.exe (PID: 6272)
      • Xidrf.exe (PID: 3560)
      • Xidrf.exe (PID: 1804)
      • Xidrf.exe (PID: 6828)
      • Xidrf.exe (PID: 6740)
      • Xidrf.exe (PID: 6448)
      • Xidrf.exe (PID: 4980)
      • Xidrf.exe (PID: 8184)
      • Xidrf.exe (PID: 5464)
      • Xidrf.exe (PID: 6524)
      • Xidrf.exe (PID: 7744)
      • Xidrf.exe (PID: 5892)
      • Xidrf.exe (PID: 6856)
      • Xidrf.exe (PID: 7108)
      • Xidrf.exe (PID: 6328)
      • Xidrf.exe (PID: 6880)
      • Xidrf.exe (PID: 440)
      • Xidrf.exe (PID: 6768)
      • Xidrf.exe (PID: 7248)
      • Xidrf.exe (PID: 6912)
      • Xidrf.exe (PID: 1200)
      • Xidrf.exe (PID: 7968)
      • Xidrf.exe (PID: 4008)
      • Xidrf.exe (PID: 7236)
    • Reads the machine GUID from the registry

      • CLIENT-BUILT.EXE (PID: 7048)
      • CLIENT-BUILT.EXE (PID: 6736)
      • CLIENT-BUILT.EXE (PID: 6224)
      • CLIENT-BUILT.EXE (PID: 6420)
      • CLIENT-BUILT.EXE (PID: 6392)
      • CLIENT-BUILT.EXE (PID: 6484)
      • CLIENT-BUILT.EXE (PID: 6932)
      • CLIENT-BUILT.EXE (PID: 6480)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6552)
      • CLIENT-BUILT.EXE (PID: 6588)
      • CLIENT-BUILT.EXE (PID: 6708)
      • CLIENT-BUILT.EXE (PID: 6652)
      • CLIENT-BUILT.EXE (PID: 6968)
      • CLIENT-BUILT.EXE (PID: 6844)
      • CLIENT-BUILT.EXE (PID: 7124)
      • CLIENT-BUILT.EXE (PID: 6984)
      • CLIENT-BUILT.EXE (PID: 7164)
      • CLIENT-BUILT.EXE (PID: 6888)
      • CLIENT-BUILT.EXE (PID: 6512)
      • CLIENT-BUILT.EXE (PID: 3612)
      • CLIENT-BUILT.EXE (PID: 6460)
      • CLIENT-BUILT.EXE (PID: 4120)
      • CLIENT-BUILT.EXE (PID: 6176)
      • CLIENT-BUILT.EXE (PID: 7676)
      • CLIENT-BUILT.EXE (PID: 7232)
      • CLIENT-BUILT.EXE (PID: 7460)
      • CLIENT-BUILT.EXE (PID: 7796)
      • CLIENT-BUILT.EXE (PID: 7920)
      • CLIENT-BUILT.EXE (PID: 5432)
      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 7256)
      • CLIENT-BUILT.EXE (PID: 7880)
      • Client.exe (PID: 6176)
      • CLIENT-BUILT.EXE (PID: 8036)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 8080)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 6436)
      • Client.exe (PID: 6320)
      • CLIENT-BUILT.EXE (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 6976)
      • CLIENT-BUILT.EXE (PID: 3640)
      • CLIENT-BUILT.EXE (PID: 8032)
      • Client.exe (PID: 7044)
      • Client.exe (PID: 7344)
      • CLIENT-BUILT.EXE (PID: 8148)
      • Client.exe (PID: 7408)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 536)
      • CLIENT-BUILT.EXE (PID: 6820)
      • Client.exe (PID: 6660)
      • CLIENT-BUILT.EXE (PID: 7776)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 5528)
      • Client.exe (PID: 2008)
      • CLIENT-BUILT.EXE (PID: 4912)
      • CLIENT-BUILT.EXE (PID: 7964)
      • CLIENT-BUILT.EXE (PID: 4628)
      • CLIENT-BUILT.EXE (PID: 7272)
      • CLIENT-BUILT.EXE (PID: 6096)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 5696)
      • Client.exe (PID: 6736)
      • CLIENT-BUILT.EXE (PID: 6760)
      • CLIENT-BUILT.EXE (PID: 7996)
      • CLIENT-BUILT.EXE (PID: 4472)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 6952)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 7344)
      • Client.exe (PID: 7648)
      • CLIENT-BUILT.EXE (PID: 7940)
      • CLIENT-BUILT.EXE (PID: 7592)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 7896)
      • CLIENT-BUILT.EXE (PID: 8052)
      • CLIENT-BUILT.EXE (PID: 7776)
      • CLIENT-BUILT.EXE (PID: 6396)
      • CLIENT-BUILT.EXE (PID: 6212)
      • CLIENT-BUILT.EXE (PID: 3508)
      • CLIENT-BUILT.EXE (PID: 6436)
      • CLIENT-BUILT.EXE (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 6200)
      • CLIENT-BUILT.EXE (PID: 5972)
      • CLIENT-BUILT.EXE (PID: 6600)
      • CLIENT-BUILT.EXE (PID: 6228)
      • CLIENT-BUILT.EXE (PID: 4628)
      • CLIENT-BUILT.EXE (PID: 3260)
      • CLIENT-BUILT.EXE (PID: 6432)
      • CLIENT-BUILT.EXE (PID: 5804)
      • CLIENT-BUILT.EXE (PID: 7088)
      • CLIENT-BUILT.EXE (PID: 7944)
      • CLIENT-BUILT.EXE (PID: 6376)
      • CLIENT-BUILT.EXE (PID: 8020)
      • CLIENT-BUILT.EXE (PID: 6408)
      • CLIENT-BUILT.EXE (PID: 4504)
      • CLIENT-BUILT.EXE (PID: 6176)
      • CLIENT-BUILT.EXE (PID: 6844)
      • CLIENT-BUILT.EXE (PID: 7044)
      • CLIENT-BUILT.EXE (PID: 5128)
      • CLIENT-BUILT.EXE (PID: 7688)
      • Client.exe (PID: 6424)
      • CLIENT-BUILT.EXE (PID: 6696)
      • CLIENT-BUILT.EXE (PID: 8024)
      • CLIENT-BUILT.EXE (PID: 8184)
      • CLIENT-BUILT.EXE (PID: 7296)
      • Client.exe (PID: 6580)
      • CLIENT-BUILT.EXE (PID: 7748)
      • CLIENT-BUILT.EXE (PID: 3692)
      • CLIENT-BUILT.EXE (PID: 7056)
      • CLIENT-BUILT.EXE (PID: 4592)
      • CLIENT-BUILT.EXE (PID: 7196)
      • CLIENT-BUILT.EXE (PID: 8172)
      • CLIENT-BUILT.EXE (PID: 5308)
      • CLIENT-BUILT.EXE (PID: 7424)
      • CLIENT-BUILT.EXE (PID: 7364)
      • CLIENT-BUILT.EXE (PID: 8004)
      • CLIENT-BUILT.EXE (PID: 5208)
      • CLIENT-BUILT.EXE (PID: 8152)
      • CLIENT-BUILT.EXE (PID: 2996)
      • CLIENT-BUILT.EXE (PID: 8072)
      • CLIENT-BUILT.EXE (PID: 7604)
      • CLIENT-BUILT.EXE (PID: 3540)
      • CLIENT-BUILT.EXE (PID: 5404)
      • CLIENT-BUILT.EXE (PID: 6696)
      • CLIENT-BUILT.EXE (PID: 4392)
      • CLIENT-BUILT.EXE (PID: 1400)
      • CLIENT-BUILT.EXE (PID: 7280)
      • CLIENT-BUILT.EXE (PID: 2100)
      • CLIENT-BUILT.EXE (PID: 7152)
      • CLIENT-BUILT.EXE (PID: 3792)
      • CLIENT-BUILT.EXE (PID: 7884)
      • CLIENT-BUILT.EXE (PID: 7092)
      • CLIENT-BUILT.EXE (PID: 7772)
      • CLIENT-BUILT.EXE (PID: 7400)
      • CLIENT-BUILT.EXE (PID: 7252)
      • CLIENT-BUILT.EXE (PID: 7688)
      • CLIENT-BUILT.EXE (PID: 6312)
      • CLIENT-BUILT.EXE (PID: 5528)
      • CLIENT-BUILT.EXE (PID: 6836)
      • CLIENT-BUILT.EXE (PID: 6700)
      • CLIENT-BUILT.EXE (PID: 1480)
      • CLIENT-BUILT.EXE (PID: 6172)
      • CLIENT-BUILT.EXE (PID: 7832)
      • CLIENT-BUILT.EXE (PID: 8016)
      • CLIENT-BUILT.EXE (PID: 3564)
      • CLIENT-BUILT.EXE (PID: 5640)
      • CLIENT-BUILT.EXE (PID: 7248)
      • CLIENT-BUILT.EXE (PID: 1540)
      • CLIENT-BUILT.EXE (PID: 6184)
      • CLIENT-BUILT.EXE (PID: 1944)
      • CLIENT-BUILT.EXE (PID: 6396)
      • CLIENT-BUILT.EXE (PID: 6596)
      • CLIENT-BUILT.EXE (PID: 7300)
      • CLIENT-BUILT.EXE (PID: 7516)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 8040)
      • CLIENT-BUILT.EXE (PID: 8060)
      • CLIENT-BUILT.EXE (PID: 4972)
      • CLIENT-BUILT.EXE (PID: 3988)
      • CLIENT-BUILT.EXE (PID: 7880)
      • CLIENT-BUILT.EXE (PID: 7896)
      • CLIENT-BUILT.EXE (PID: 7756)
      • CLIENT-BUILT.EXE (PID: 7340)
      • CLIENT-BUILT.EXE (PID: 7144)
      • CLIENT-BUILT.EXE (PID: 7912)
      • CLIENT-BUILT.EXE (PID: 128)
      • CLIENT-BUILT.EXE (PID: 5212)
      • CLIENT-BUILT.EXE (PID: 2120)
      • Client.exe (PID: 7272)
      • CLIENT-BUILT.EXE (PID: 7348)
      • CLIENT-BUILT.EXE (PID: 5004)
      • CLIENT-BUILT.EXE (PID: 3208)
      • CLIENT-BUILT.EXE (PID: 6744)
      • CLIENT-BUILT.EXE (PID: 5400)
      • Client.exe (PID: 6580)
      • CLIENT-BUILT.EXE (PID: 7104)
      • CLIENT-BUILT.EXE (PID: 6332)
    • Disables trace logs

      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 5432)
      • CLIENT-BUILT.EXE (PID: 7880)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 8036)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 8032)
      • CLIENT-BUILT.EXE (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 6976)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6820)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7272)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 6760)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 7592)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 7044)
      • CLIENT-BUILT.EXE (PID: 7912)
      • CLIENT-BUILT.EXE (PID: 128)
      • CLIENT-BUILT.EXE (PID: 7348)
      • CLIENT-BUILT.EXE (PID: 5400)
    • Checks proxy server information

      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 5432)
      • CLIENT-BUILT.EXE (PID: 7880)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 8036)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 7500)
      • CLIENT-BUILT.EXE (PID: 8032)
      • CLIENT-BUILT.EXE (PID: 6976)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6820)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7272)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 6760)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 7592)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 7044)
      • CLIENT-BUILT.EXE (PID: 8024)
      • CLIENT-BUILT.EXE (PID: 7748)
      • CLIENT-BUILT.EXE (PID: 7912)
    • Creates files or folders in the user directory

      • CLIENT-BUILT.EXE (PID: 6812)
      • CLIENT-BUILT.EXE (PID: 7516)
      • CLIENT-BUILT.EXE (PID: 6620)
      • CLIENT-BUILT.EXE (PID: 5588)
      • CLIENT-BUILT.EXE (PID: 8032)
      • CLIENT-BUILT.EXE (PID: 8148)
      • CLIENT-BUILT.EXE (PID: 6348)
      • CLIENT-BUILT.EXE (PID: 6820)
      • CLIENT-BUILT.EXE (PID: 5776)
      • CLIENT-BUILT.EXE (PID: 7964)
      • CLIENT-BUILT.EXE (PID: 7696)
      • CLIENT-BUILT.EXE (PID: 6280)
      • CLIENT-BUILT.EXE (PID: 6188)
      • CLIENT-BUILT.EXE (PID: 2380)
      • CLIENT-BUILT.EXE (PID: 6456)
      • CLIENT-BUILT.EXE (PID: 8100)
      • CLIENT-BUILT.EXE (PID: 8024)
      • CLIENT-BUILT.EXE (PID: 4872)
      • CLIENT-BUILT.EXE (PID: 6172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:07:03 09:05:04+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 31232
InitializedDataSize: 819712
UninitializedDataSize: -
EntryPoint: 0x3248
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
765
Monitored processes
643
Malicious processes
87
Suspicious processes
86

Behavior graph

Click at the process to see the details
start xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe svchost.exe client-built.exe no specs client.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe #QUASAR client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe #QUASAR client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe #QUASAR client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe #QUASAR client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe #QUASAR client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client-built.exe xidrf.exe client-built.exe no specs xidrf.exe client-built.exe xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client.exe no specs client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe client-built.exe no specs xidrf.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
128"C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE" C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\client-built.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
236"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
236"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
308"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
308"C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE" C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXEXidrf.exe
User:
admin
Integrity Level:
MEDIUM
Version:
1.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\client-built.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
440"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
440"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
536"C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE" C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXEXidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.3.0.0
Modules
Images
c:\users\admin\appdata\local\temp\client-built.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
540"C:\Users\admin\AppData\Local\Temp\XIDRF.EXE" C:\Users\admin\AppData\Local\Temp\Xidrf.exe
Xidrf.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\xidrf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
Total events
246 138
Read events
246 124
Write events
14
Delete events
0

Modification events

(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6812) CLIENT-BUILT.EXEKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CLIENT-BUILT_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
35
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7696CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6304Xidrf.exeC:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXEexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6620CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
7516CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6812CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6348CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6280CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
8032CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6456CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
6188CLIENT-BUILT.EXEC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:D2825077C227A56B75F7A35542273379
SHA256:8C1CE151FF00AC0B8203522364F010E0E638D15CCA23CE5EB6D0A5A6131D427D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
77
TCP/UDP connections
95
DNS requests
21
Threats
167

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6812
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
5432
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
7516
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
7880
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
6620
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
5588
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
8036
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
8148
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
7500
CLIENT-BUILT.EXE
GET
200
208.95.112.1:80
http://ip-api.com/json/
unknown
shared
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
92.123.104.11:443
Akamai International B.V.
DE
unknown
1076
svchost.exe
2.23.242.9:443
go.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
6812
CLIENT-BUILT.EXE
208.95.112.1:80
ip-api.com
TUT-AS
US
shared
5432
CLIENT-BUILT.EXE
208.95.112.1:80
ip-api.com
TUT-AS
US
shared
7516
CLIENT-BUILT.EXE
208.95.112.1:80
ip-api.com
TUT-AS
US
shared
7880
CLIENT-BUILT.EXE
208.95.112.1:80
ip-api.com
TUT-AS
US
shared
6620
CLIENT-BUILT.EXE
208.95.112.1:80
ip-api.com
TUT-AS
US
shared

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 23.35.229.160
  • 2.23.246.101
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
ip-api.com
  • 208.95.112.1
shared
www.bing.com
  • 2.21.65.154
  • 2.21.65.153
  • 2.21.65.132
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
freegeoip.net
  • 3.33.130.190
  • 15.197.148.33
shared
api.ipify.org
  • 104.26.12.205
  • 104.26.13.205
  • 172.67.74.152
shared
login.live.com
  • 40.126.32.72
  • 20.190.160.14
  • 20.190.160.17
  • 40.126.32.140
  • 40.126.32.76
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted

Threats

PID
Process
Class
Message
2192
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
2192
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
6812
CLIENT-BUILT.EXE
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
6812
CLIENT-BUILT.EXE
A Network Trojan was detected
ET MALWARE Common RAT Connectivity Check Observed
5432
CLIENT-BUILT.EXE
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
5432
CLIENT-BUILT.EXE
A Network Trojan was detected
ET MALWARE Common RAT Connectivity Check Observed
7516
CLIENT-BUILT.EXE
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
7516
CLIENT-BUILT.EXE
A Network Trojan was detected
ET MALWARE Common RAT Connectivity Check Observed
7880
CLIENT-BUILT.EXE
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
7880
CLIENT-BUILT.EXE
A Network Trojan was detected
ET MALWARE Common RAT Connectivity Check Observed
Process
Message
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\XIDRF.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\XIDRF.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\XIDRF.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\XIDRF.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\CLIENT-BUILT.EXE
Xidrf.exe
C:\Users\admin\AppData\Local\Temp\XIDRF.EXE