| File name: | XClient.exe |
| Full analysis: | https://app.any.run/tasks/1ed0d1c9-fe4e-466b-8bd2-c6a799f0aa1a |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | January 28, 2025, 09:32:16 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | EE7BDCD5297B596C840E9B9CDFF9E224 |
| SHA1: | B8A519821049D8CD592E77EB43C6EB571B61F42E |
| SHA256: | 92C2BA7B293F6F0E9F54B5C257C4F44CE516D94E6A5F2BDA9CE71BE843C7E450 |
| SSDEEP: | 768:ihSBJCcJNCelkLakuumwhh29vzid9Fg9uTO0h4k+:XmcJN+YbvzyFg9uTO0Ob |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (56.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (21.3) |
| .scr | | | Windows screen saver (10.1) |
| .dll | | | Win32 Dynamic Link Library (generic) (5) |
| .exe | | | Win32 Executable (generic) (3.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:01:28 09:31:39+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 32256 |
| InitializedDataSize: | 2048 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9d5e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileDescription: | |
| FileVersion: | 1.0.0.0 |
| InternalName: | XClient.exe |
| LegalCopyright: | |
| OriginalFileName: | XClient.exe |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 512 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 1920 | C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -Embedding | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Modules Installer Worker Version: 10.0.19041.3989 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2192 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2788 | "C:\Windows\System32\schtasks.exe" /create /f /sc minute /mo 1 /tn "Microsoft Edge" /tr "C:\Users\admin\AppData\Roaming\Microsoft Edge" | C:\Windows\System32\schtasks.exe | — | XClient.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3780 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | schtasks.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4876 | "C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca | C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 5252 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Manager Exit code: 3221226540 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5488 | "C:\Users\admin\AppData\Local\Temp\XClient.exe" | C:\Users\admin\AppData\Local\Temp\XClient.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Version: 1.0.0.0 Modules
XWorm(PID) Process(5488) XClient.exe C2127.0.0.1,results-personally.gl.at.ply.gg:12278 Keys AES<123456789> Options Splitter<Xwormmm> Sleep time3 USB drop nameXWorm V5.8 MutexIUv1WDWRBa6Y71IZ | |||||||||||||||
| 5704 | C:\WINDOWS\System32\mobsync.exe -Embedding | C:\Windows\System32\mobsync.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Sync Center Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5880 | "C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca | C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Search application Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6004) Taskmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager |
| Operation: | delete value | Name: | Preferences |
Value: | |||
| (PID) Process: | (6004) Taskmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager |
| Operation: | write | Name: | Preferences |
Value: 0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AA6C15F77F00000000000000000000000000002E0100001E0000008990000000000000FF00000001015002000000000D0000000000000098AA6C15F77F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AA6C15F77F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AA6C15F77F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000AB6C15F77F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028AB6C15F77F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050AB6C15F77F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AA6C15F77F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070AB6C15F77F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088AB6C15F77F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8AB6C15F77F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8AB6C15F77F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0AB6C15F77F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010AC6C15F77F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AA6C15F77F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AA6C15F77F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040AC6C15F77F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068AC6C15F77F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090AC6C15F77F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8AC6C15F77F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8AC6C15F77F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8AC6C15F77F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028AB6C15F77F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AA6C15F77F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020AD6C15F77F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040AD6C15F77F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068AD6C15F77F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AA6C15F77F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050AB6C15F77F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AA6C15F77F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070AB6C15F77F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088AB6C15F77F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8AB6C15F77F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8AB6C15F77F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AA6C15F77F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0AD6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AE6C15F77F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AE6C15F77F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AE6C15F77F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AE6C15F77F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000 | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\3C54740F7CC0F23B53E5 |
| Operation: | write | Name: | F5A5C078C378D6CEA2E1F6D32D55A253354C73432AD19354A87149B64F2A86F9 |
Value: 004A00001F8B0800000000000400ED7C7B781CD5916F754F4F77CF8C664633B246B291CC186318DBB290FCC016C66059926D01B28565639B90C8A3515B1A3C9A163D23DB0A60A4B0497078242C2CE1918457C85D6E36AF25B940B249800DD990BB099010121E31784936211B36218F2F0BDF17737F55DDF3902D12B2DF7EFBDD3F7624559F7A9C3A5575EAD439DDD376DFC51F211F1169F87BEB2DA287C8FDACA73FFF99C25FE4E42F47E88B81EF2C7848B9E03B0BB68F660BC971C71E71D263C94C3A9FB78BC9212BE94CE493D97CB27BEB4072CC1EB65AC3E1E0A99E8EFE1EA20B141F7DE2A59F5B25BD2FD329C990D24FB40188EED2BEB60720E90D4A542B6DD5B59BA872A5475C3A7F7CB4FEFD2CCABF956BF9229F71E83DDF73E666DF2C4EDE4554F30E6271C207F69955A8097C7315DE5AB40E1671FDC67A57567C554F50B1A7D5293819F26C838DE268F74C39A858DFEA58393BE3D97A97A76BF309721B8E37F3AE3DEE75B374F153DB99905B42A478FC83AB2A39F14E3EF3D554035170C969A4A61AD1A0259F2ACCC5750A0AB5C23C6EF1AC154EE2968F5B4DDC82571AFAF88ED5FB894E92DEA74BEF6DA5965A588ACB9529567E0AA95306F7B8A8508F0C499D016211D156A74CA6C2863616FB3F738EE9F3C12FB4032B2CE77102E083BA702635E8F5E281960C25A690205AE2D2A9389B77160BCC6181D60292569FAAE7F6725F11AA4E4A618AF425756D8AE4145C8CD12176D46E46AFE0D22A9E2A3C76DD9E7F3CCF273C0E867DF2F13C4D781C1E3B59E1A904DB305BE0A9BED4023052A794B844DC97F340177E6AE1F13A0DA63F85DE6AEAD46A1EF731DD3E8BAAC782331410FA753C3B738E2921A3C54CC1D1A5C1A57E52BD618965912E982C96BD9CA7CA5E0C1032AE33DD7E3566CB9C1482B034E4B20D7B89889351ADE36C5C43E2B7CED3956A111D2D0B1C8C38FE9451B2DB5EC613D80A50634EE9122AE950F6073AD827E8314A642AD1C3423767A7A712089E4B3FA94DA32B408F80AE4E4142F34D41A7A64D81A2F9A720AF45B4A9282E0DD7239994450907011FBF27717B30B502B63983C0522BD985C22AB155376C2CB2E091A0D9A29BF66A345F34526B7039ED10A7A7DD81E6A160A9B5F4D8694768CE12A58973682305FB255EF23970807CD0A49CD466D079884D946D6F6C682AACE59C8D4143BD9BC40DD783A24CD5CDC8E7432C90A46F11D967F32454E1EB64528470885D3EC41EA7CEE1989FCBAC065921D498C2ECEAA71D09A7D63335D5C95E11A5506482376483A92EEED0CD3EC7D5540F47E0E440294636C76851C3218EE23D8B1AF5D446F0EF5934D723CC8B2BA94D9CD62EF9248FDC04F2E60AB9D923CF3FC4F1BF27D5CBAC059CF8AEEDEC7042E00DD90496FDC9BCECCFE3F032DB3E9F637EA47E91981F265E427AD90BAE814D1CE57D149CA0F099B2BCCFA3575728F5A598BFA1C85E823C9282714C09EA2DBAABC58B9E6A5F20B99B38A6D6981D5C030FC5655A8E29E140C7C32C2636DE88CE755A4CEBB88E493C3B761FFBD2C6D56D0BCF187773195B39D655D318976285FEFE98BFE54C6FC6DFB9FF3F3E934BBD6869B8F4F9071B9EADE40A2D9DE31AE31969F7BB8B75CD17A964A6CB31EC0B2583C4BE6DAC9FD5C1243DA6B78C1CC26AD25A0CB92C4D1CE2FA794C3F8D4D1980E8A229A617B6A35967C48C8AF3F60ED659F26736D71BAA4D3DC5F5A162C3F327B883BA13F066F948D75F9021093743EACC1929A2708A506793BB16312C7D07913C8A3F38446E8EA8842A8704E15F359592914F72B50549B72FE239DE59BD76962872385190347492ABC34F378112171DAEF34195773C9DCB8B1E326EC8CA6A700E709DD9C51A9959A39B09F386AC3B31BA91304A6D71ACBEC1DE2D0587115DC29DD0256A0F26EC8BC5E91AD25B0C5DCA13BDF8F68BC4AD4B01B2F2A5639242975F41F525FFBFC9359D6D7777557778FB5D654BEC4BB8F9A783E225D6BB2B39B6B5BA53888C593B49317D4FB5640D99B34A064F900C5360B6D981532B4976D0B949777E08BBD5DC1DA5F66514B9AAD4BE8322F757E6F009374762B4E62B6825DB265027072B65D6DEC3DEEB1D5753699243CEE53CA1E589AE31679FE8B01148044A936B544DFA89136DB8136DCC98E8545AFCAE21A3C530BCE9262AE7BC76DC8C53439D7FCDBAB7F856C19BFB2564DF569AFB18DD7A3F254A3EFF103B7DBD97FB2BD90F2E6752B2EB13A92177BA13B7870CD60DFF9247DB9FFEEAAA73CDE417760C1E5A35CF4C46E79DA5AEFD3E2F5B7289AD97ADB1543E4BD73F12F9ECDA9F7A1CEEB6F616AE4B9B8559F3C4BCEF70F75D1B9FFE76EBBEA51E65ED5D2C719A483CF499C79E698D32E7A5677FF7C7D6F63551900DE783086C22854374B0E34E16E6FA6E381FAF50BFCED45784FAB90AF55F98FA1DA1FE5385FA23A63E28D4272BD4DF32F56EA1FEB042D5415873AD505FA950934C9D10EABF55A8AB993AC8353BB594A73F70689853C192C98A692D8D81643DB80D85BD5CC584B7847769F45A5CEEC57B45553F2ED373637EE99898A5E3AF796EDD3C58F3136EEB0DB7A74620A137BAD7C22823733DE23CF79AEA900E0FFCD90EA9753CCE9A0F9504CFF104F95AC8B2C0A552C5E6BAA44422D1905AC6BA975E4C2CB74FF60EEE9993321D3313316399AF71A9923834C6DD5B59FFD2659448E55920100B387F4444B987ED8D35CE72ED9CA497F15808D291666F090429169CB518946A3F87F54164D043F86BF66A7F5D9B8FB0F7F35E80F3A4C30B3A5183221C36EBB400C2AFD5E94B4F3762FAED76013CD59D5C3E05600FC4420423B8344631BDE1599E9D98BFFDFB73CAE771DE081A446F91FBDA13543EFA53896F56F1F757F1F93CCB37DA8DEEBA2C1C60CBE6C9265983EA31CF3EC845C14CA426A50A1A89C27B25B3020DCF7B7B291B1FF32702F6E52C19F3078FCC23E49D19D34AD5A3AA92C8986E9D68A1E65E3E46BBFBC5969D6ECD607BB005D05CB1C7AD7C2A2ADD155CAEC520296664348821E1809A00DBBE928901FB9057BB022D46C01BD12D72C199054DF7CECFA7527D873BAE8A086DDC52B1017948F3D886C2556C42614AB60BC33CC4077C29B4F63448F6FBA4CC36DA57CBD5FE2BB6494578625A22863384FD7E197CBE973A7E8AF967491D44C5DDE7C374D6266A76EBE57FDA860FFCD7D980332DC74372874FF1EAED727E0F11CEDDA88E415CAEC125194C9E4685C3EE8E9AFA90CC0B58D7BA12D7C91A35EDEB7135ED1B4AAB3D99A47F26FBC36C435C7B2A56BA8B4B7D04E04AA4A316D752677AB5A9A527A65D3E978F78DE217245C0BE1172A0C238ED724CA6566A37BBED791CA3D5BCD003F65F93779364068F2CAB4E0EF74665A633859B385C5E58AAF2B58D6EFF76695F8BD0B79EA505A5797A0F167C13C748E3DB363DA8DB3773AC527F23E186F58B48570BB7C82C347AB3A0632DA73E5A3D01A56C3F742BA0EFD2C26D1C4E4751B0B9B770616F28DCEED574FB0E8EA8798F7756A83312A87146DC4C7D4CF4956FB3EA82F1A0DC67D5055CDD75213D16425AD81F67C1CACDD73FCDBCF98A85DCBB8DE55CFE3E4133EFC302B3DF8705DED97DD89108C542A80DA1D241321233811AA93B658A5EA423B55E806A2AF78F7222299FB5E65168113572EC55BA97DEB748F16AC815F4F02AB70D6FE8D98D4AAD3B3F3E424DE73A1CC3441FABC701445531D5E7726A189727F91C74F97CC0E76B8CCB170876326361B3E1D940C3B3920D38F5C434C96B9E4EC9BC3A5D8DE98D6C2A6E78E1941F5EF83DA762DE33045E4F2AF550FDC56E9DE35C1943AECC9735FD9F9C6C7F020BC01FD74F986C130920936D78931D48ADE509BC8B837F362FA420F6ADAACC0C61264EC75EE6A6665D25376B2856737C6EC682B1C03BC89CC09FC81C63F6CC31DE79E60410E4402573748EF98999133E2E73640D770EBB99718D5438A2BF71F73C72F38888D93897D10A85C84B227964BA8ECF20A07555D1F983A3012D046DBB7BCFEFEDF15C2588903FB1E4E31F6F9A0EAA2D8B12A1A57354C3BE1B96E8E9E44D0A2917078D865D2143B531A7C133D4A5473959F816FABBDFFED5D7F8EC80FCA2DCC064A1688DB56EB30AF68493B10AE5D6362B3D6C392DC9B142C67672D9A196E4459653C8DAF9752B5BDBF8A725D935912B4E38D6BABC355174D2B99664FFC4502E9B39DF9ADC6EEFB3F2EB8656AF4EAFCAAC3AB3BD63C54AAB6D4DC7C213079BC817B3635689306015AB9F45F77776F32FDBBC61E0BC0D8AF774988BE37E366245DB8AF60EA6F8092730FA0902B4105B733F12F8546E0F149D6C7EA4C012454C6E23BA2FDC3140D79DE2C672E1A61DBDFC48FB63C03F6900DF90B3872A73A2EC6CBEA73980FCA03717ADE003158F3EE49EAD6801CF35FEF8B9E33DDE59ACDB9D137E3ECACF2D652FF055B5158FC757C3E3B9EEFECC703DD3699D2F5AA35322F4FD5090DE1569359190C1684D904C1FB79BE94623487707EF04E55381EE4084FA7C670482B44FD9AA47E8A391D323389D98DFC3683F435FACABE8563D4E1F0D64019F09BC00D8A1BFA007E91595B98BFD5741CF2D0249FB526827BD54C396766ABBA1B3C6CFF04A81BD0287045E23DC655A077ADDEF63F88C50EED5A660C33FFBBE128CD01CED2B46840ABEAFC0DA7F80669D7669BBE0D7B8B619A5F341DF97E0CBEB68C312DF97E0E90D3EB6E1EB6186EF13DB7A430C5F89EE868FBBC4C75551F6F177910FC0C76774E6AE31D8D3FD908FD02FC2ACE760A0D58CD367D41720F9CBE8E99108A93E86AFA91C9947FC1CC3ABC36CC90265574D823E6B0E86833462B086FA30CB4411BD08BDA17F2914A1F5D2EB56E25E6784372B3A7D5B61F8323404E93EB1B033CA239E127D414FD086106BFBA4D08F21FEAB157EC20FBF54B6738F3E188DD031E3E7E0BE19E41117A9DC7694C7A2384E0519BEDB64B859E02A17AA8F45E3F477219EBBCE08CFE32E95DB4D019EC7C346474D9C5E0932FDBB618637A08DB1425BE5FBABAC645569DD4402F745FD656C4EE8BE68006DCEF45A1A8ADC170D03F3915FE13339572F3FCEAA8CB5908B452575BF5CF3F99A30323526FDBAC3F74517416E8EF06A6B594B0077093CC6F7CCEF998C350AB631CC5808A73CFE36E0C60863B538CFF8B194FE5D46A8C7399925FFBD86790D74BAE8FC7ED0C5160BEFD5808BADA220506C0BD40BFD6709F680604DC058F2709425E703E375B64946984FE788E44511969CCF2B189823BC5380B5536FB00130193C197065F074C0A1E01958EDFBA2EF87C779F3A3808B7C7700FE41791895601E6C48D0BB056E8F3E03D82BF017C4F06B02EF10F811E587803FA1E701B71947006F091E057C857E8AAAFE797A136D8D8ED1855377D20664594467B838CCB0333402786BF852C07BA34C5950CBF07F4518FE36C0F041695F646E50FA93524B1A07B02214DA35031B122CD6B83BB41A58379731AA338DD05A607B3CEC98B91ED8151EF67CB007D8AD1EF67AE83C605F14EC9BEAAE7006D8331E56AB8E229B7E29D8D5F4A69AE3BB9D535CDEB7F4CB8025058B51449900765DD2CDCE37E94ACCD12D55766A748148FACC9F29D703BB6B06EF23A7B8B67C3C7827B01F7958D8F749605F4ABAD85CDFFDC0BE56E5AD9F9EA9D2E2A75F4BBF84F942E4AB9CE90BDD7EABC38CBD2892377AFD82E2D107BC7E4991BC853E18F8BF659EAB1327FC0595F182C7F1BE21FD12548C306FCD2217FB0FFFABC02E39DDC5D2CAAFB042EEF2B04794DF63AFBB24E5621F5356234B8717BBD8793A63D523846969D5E8615ABDC08D60885465A6242AEA1257CB5E8CE79E36A62891FC4DD850A265EC52B5C6BD51136C223A479943BB96B9FDFE3ED0A8CC29F312D1F94ABD87D52583D1D39579F4794FF2463A43994F4F79D8CBB44A39997EED614D91B54A92A65A5DAC0ED802D2CE70B10F84D62AA7D0351E360A6CE10C1F4EF5C68B251F0D9CA754B097CC0B954554D3E6E6D96DE66E6531B5B5BB5A56F906952533B42CABF22FAF2CA3A796BB927F0838C02E59E1623BD4834AEB8C7E6DE57E7D91AB940A764BF483CA723A7B95E412858C1B945592E1DF0B3034D40AFC173FC3CF129F005EE479A2C7889F53FF03F119E121AEC1A40519AE94F6EFF5521D2F51B031027E45610DAFEBACE174FE5A919226D31F17C90561E6DE1365EE837CD2A50F8759FFB5624F86BFD2A4F79ACC6549CDA3AF895446D91D3D11AA808306B76F16FB7F2EF6FF52EC7F4E467F9FE8394767EE11E1BE47B47D4A9D492FD93F2D233E2EED67222C1F09BB96DC4603A19B94BB89A37E3FE023A8BA03A1279547053E21F06981CF093C2AF05540BFFABAB4DF10A8280C038087D518E0DFAA0B14D6B95860BBC00E91E9043CA6F60AE5428101193D26B046E01C814DE466A24BE74A35476093C05305EE569EF30F6873892BE55CE20AB9986E56D3A07045CC2A3F52F6A3CD1A56CA1E73363DEEBF1EF049FF9DDAD9429F4B5BC39FD116D34BD107B40E501ED626954F2BDFD47A853B0D0B9FD12E44FB79ED3665A1F12AE077D5D7B4C362F961E541F5B07AB7B2CF87E8296BA3BF85E45A9C2AD2D27737A0EEDF4D29FD266537D5031E55BE805BCFDD341969F4BFAAB487E6039E8C6AF2BA520C2FF2BFAEDC6BB6007E2BB4DCFFB0E2D7D7F88F2ADFD2D7F90FD33A63940ED3DF4546E946E5ACC806FF1B62D56E54B7CDD0F69A7FC49FA6CF45C720FF0BDDF10754B6274D5FF41F00FD1ADF15809B8CBFF25F46255FAEF1B39DAAF205E53DEA651453BFA1FE5E34BF069D6F187741E723CADF025A3EF682B505546E5F485BA20C5F083C05EEFB941FF817A839D4DBC5EA1391D7FC1DEA97F5FFF077AA4F0646944E55AD7D0B6DCEAE5E7507D5C10BE48C7EA1CA70B7BA2F10D27BD529330EF8357F839E46AF263DAB9E619CACB325A7817EBB7E8632A9FEA166993E499F0D6F007C16D64EAB7BA84F9F56FDE101C0A7F5DD3A473B0FB85729EA3762AC2BF4C318E56A4097E20FDF8636C7E1B0DACCE77B55B25DE0C3EA5BFADFEB8FAA5F8EE6019BD487016F0E3DA27F419D30BE89F67EB41F5638FE0F2B1CFF698CF5B2FEB47ABEFA2AE89F8830FD6860948EAA2C73546599A7D50F99BFD15F57BBF4B720D9A9F88DA7D53371169F96081C5579660F935A9B3298D26670FC3B8C80EFCDE839C61BB0AACB507C1C37C59730CF3762BEDF05B71947D59FFB771BBDEAA7F5554ACCF764A4C3E854BF1AB9D9B851F964F813809B30BA4997500FEAF11DF490DA8A7DEE5654D53ABA1BF024FA26E0427A067029D64D2BAD10B856285DF41AE0F9421910F82E0A4243865602EEA34E753DCE1B3DCA7ABA9C3EA77651813E0CC8ED5E8CF5849A114A462859507EAC4E89FCD574ADC09B04B2CC61707FA1DE25DC7B45FE5EBA9774DF2342F947A1FCA3D8F004DAFFDBF7B2D05F113DAF40C3A8EF15FAB4B41F10C89A5F154952B82F292CEF531E1058A0077C3E85B949E12685BB50B956E04D023F2D90E5172B7750445B2F92EB45728FB4F7487B4AE05D02EF15F947A4FD88C8BC2CED574433A9570B145F5491D498B2565BAFF568E7695BB55DDA255A561BD3A6B5FBB447B527B5A3DA9BDA2EFF0DFE9BFD0FF81FF3BFE85FA96FD607F5EBF53BF527F580611945E3364343B5D6B1B31880267E0272D79B086D05AC0D6C073C12DCCD3B41CD7B00FF4DF96BC0BB839F035CE6E3FBFB9722BCFF6D0C3F861D4043FDE777C2FC803A34AAF80B00469133FC2D4398F83DA42846AC0354B143C7001B80BD683C6D6CA193B5D3B465DA4AADA01DD63EA27D547BCEBF5E19A0DF8415DAA8ECA04B5595BA949D3411E5EBBB2811C5FD81F26E0AF29771CA183D1AE0AB4D2F997C3D2072A45C457D11BE4ED32DC0B5A9CA9B6AEEE7D540E9D9AFFB5168B3086855B4082D9B85D66A1E4F53E805FD44B9C170854FF48D1ADEC735C447433C6A10815AC4A4163B501DEEA3F86C560BEABFCA75AE5CF9F9FABF521F5DA1F5D1ED1AA5DBE8D4DE6D6B96B5D3E005E9B1A1E1F4A98383826E6FA72E3BCFAF095E94CE4D587B401975ACF4F0407AAFB575E8522B53EC77ECFDD961CB016B47C172562CA709F7B2DDEECD17F9BA9C46ACE2E08EED1BD7D0D97DF6F044CE3A87CEEE77B2FBD345AB776C3C678D59F962BA98B5F3DD56319DCD15CEA1810D34DADD459BBAA8B7BB9BBA766C1BD8BA6D7060F3D69DBD5B36D166D84AFD5B7BB76CEFECEF452518E8BF80062E8033AE5CEF968D5BC97BB6D4BB95FAB1036C18A0BE01DA4EBBE8FC9EDD34D895B30B138E051FA93B5B18B70BD6E0606FBE504CE7336851171C2CCE24C149F6B53B5D4C53E911186DB37256BA606D1ECED026ABC897BE6CC6B10BF6DE62EB45D9C2443AB7215DC8A2DE6468833592CDF333342F7CB42D7B697E386DE5FAD2F9F488352C1142A0F3180458B650DD868D99323A3099CF8C3A763EFB5EE60DD3E8CE3C8816C0E801802E7B6C3CED587D5671D41EF63C29F92183C0D2323E6CED4D4FE42A78B6D46077D285D12E7BD8A2023AF57183553B56811FFAB978767CD472A4398048648AD2DCE8D863BD63F08995B80D1EB60F1DB9CD9696DABD6EF0D343398BBC477FDB27C7ADCDE9FC704EBA33C6FA3CCAA87BD986A1D2F911B4BAED03F99C9D1EDE9805B2D3C916AD0BB279317488AF32AEA794247DA585B92CDA193B2788370A0DD8997D5E53A6C27D9629CE97DA8EF758B28477A5C7E5DA393E9ECB66247F31DF33F001AB58E4678E42E7ACB34A09473DC3D9A2ED6C70EC031280012C00CF0709343C72365979CB0179B8B35874B24313606D9AC856619BADDCF8F9D6E401DBA91629F5E2D9AB90BBADA1899111CBD962E77999CEC6643B2AB4E30CAC30601EB23B3B83D65928586343B9C9EDD96235195E21CB9D6177D557198E82E1D2B6A4C76653E3A487ADB1B4B3AFC2DA9E7630311B1DC8C3DF7D273A069DC356FE445D9C1CDEB3EA0AB36F7293634F8C77D9394EDC19AC52BF6EAB9071B2E33399EED4C8DC62F5A70F4AAB706267E4D8F044A67822A3CB1E9F74B223A3B3B2B074F3931586B726845ECC0E6573D96215577265C32487C6960BE7AD64B964ADDB427ABB55DA4507D2FB31B1F9612C212B8BA657965C84FB0FA0AC5066482EAC8597EB8689BD7B2DA74CF2C4ABA90CB8B5752FF523DD4BC5D72D754CE8C967ECE12A4EB7933E00B495EB4315D973B8D59B2EE6F0F2E7D573E64AF7F13D3B5B8D7AF5AECCF41AF0DB6BCD1C111217D8B8F4154650C747DCE41125082997BC52DBED2D948DB909402E14D6D8787FBA28ED8D760E7B9E601CB79DD961AF7581951F41D30D8F878C67B23474118EA60514EFAE742E3794CEEC232479BEB0D776C63666F3D82A72A840D497760AA3E9DCEC1B496BDFE480E5ECCFF25725D85A2D07DD4AFEB1D9761EFB2817E19CB705B70EE720B0B9CB762C696EB3C6ECA285C4DE57B4C785D28F05409B2ECE8EC35F2B3D467D9070263D84DDE94F63C551CEBD1C702FEE90B88C8D590853A6333762231947C788E355C186EC62D11EA3DE2E6772BC6897DD2D1752EC7D34349001C4A4DA3636D33CF1FAE0391FC83896959779745B628C93455198F428B37ADE0AEFB22379EACF4D20B368B4173B27F1E44BA37C2A68ADDACC447555D14671A8C6D8A2FEEC412BB7759CEB6AD6AE1A39BF373B323193B829670FA573D9F7CE206EB3F67A75469650BF5DC80AD27330638DBB821927CF0B9E860FF41C2C3AE9DEFC5E9B64FBE44A9D11D4DB78A48DC0C8A2B29C12DA35E1146C17BBD8726CDA902D8EA5C769206759E3E2E2767B7C660654A20B7F29ED505FF72A77AEBC342B1DED688CE333F3B8071AEF232710BDF57322A36F72A73554CADFE3B803E356269BCEB98B8A3CC7BC3524B66FABA40C42E2B8674B8B5BE5B918B6BA6D371B78EF94BDD1EBCC7696944A065B4521304494308DFB2DA7E80997EC4716949B5D484DC73B02F6388E8D51ADE20C7CD48D3E75629271AC45AB35E342B9F4A198F1B5B36760B0DBCA488C1DEF7456C1990B3367702BF80E78DC5F746893931E1FCD660AE5CA964D8FE4ED429149ECC0067B223F5C789B0AD26D49F8DD9A55990E9A31396FD377C6B9C6933CAE704B55B2C7FF8CA2D21CBD9D96B7E597BE28F65637EAE189B4CAB7C94E99E51E1150CFB944C02AF7FC5970B7D0CE5C8EB7CF02AF06B791DF984B8F14BC23A1DB1E3EE05EF7BA1CEF9B64D931BD231E7171F69A58EE9663E120DD73199C2EDBBF339B1FC669AA75238AA0DB1963BB0BB0406E16723D2A5066C3042A271AE3DEFA44C170937314FB43F960EDA574A174507053BE7042AA17C82D5D365AC85A44A4E0253037BBC7B39D07B085E6999C2EB74A0512C1CB949A9E1F5BAC62AB1B1C311B29415220D92FB4619EEB291FD4C95DE9888EB75EC83B73B9670FEF36075B0240453D565C1615DD1DC4DB56F71629C780B1CD161FA1480E52648F0FF61CE4D4CC4205AE45945580D1E1CC869C2BDEEDDEE750AF6CC0C8104690F0EE2888D7FE2CEEA8F82E94F6599343C383D67E6E8FD9D846BD76BF9D65580A29DF7D7937C2C5B453F4668FC5003A87186EC69AC41D152A48F93CC4FFD88E2BA4DC4FBBA708C71A7178C1BA11F3EAB38760BBCB7BA1A4E18395A447F5EB749CF4240D4FCA76825B80D21003566602493DD9EAD6F111AE15936EAA79A74CEA1C1EE6C9DC981ECB02BB10090A790E626FDEBACCC32AB98C5943EE8044B4A09F70B0A011CA529E5A691BE1E44736280E65A44D6B47A9889F713A8BCEC04F862EA376FCACA2E5D4811E453A00AC15F213E0EE439F7DC02C3AC8EF82468FC38D6DD44DCB48E1AF6B43FDD44B5B68139D4B543F00BD0EC6CDE1A71BD703B08662D5D41DB0801ABAD0B261158EA6C2B3F093F7F42EF5AEBBA09BE5B290D807DAF99081ABB16EF1671F245827B4F92EC1C8591AA334FCB760FDA5A05AF2AEA4F6AE6BBB467EB3B6EFE62D8FBFF9F527BE5720F3F3E70E5E15FB41F02C5F9214F3C1F75E72D1DC952F1F36F4FA78A312AFF1AEA6778D79D739FCD849238AD7303019C418CCD14CA6994C339966322DA9A84DD06E6A498AD7A311316A15653ECD27A34D51945A5CA175AE52C7FF940A2005E0D3E3CDF85BC04A9B192CF093A20037190758006E921949C692C0169BE46F8AF047D5F1AB82B44CD5833EBDD98F66BBF45FC5B0D9AF0146405C89BF0E98A73481629A06698D8D6663239C6B84607C5D84DF2130F90396EAF707E682DCEC8F00469AFD3AB79BFDAA6E6AFC540BA85A1BEB66C946D314059DE8E753623DA6A9EA8D3E3DB6199A4D6134EAA436816190DAD8581BDBAE930F8D00CC0844D820D354BC7F0A3B9FBF39DBAE26766271E06EB87C06C37A467556FC108EED86B4FB160EF78DC4150ACF3C3AC9AB10C83285E2E55BBAE463F72793CBDB962F777BA98B153A7579C7DED5ABD3CBD3CBACCC9ABDCB5666566596ADE9E8C82C5B7E667B7A28BDE6CCE1766B35510D466B77DFA322DAA4D0BCD62D3DDBCBF7BA2DA557ADF83527981E995366F1D3845C7A92EFA26BB94FB2CC49AEF427552512695428D837C9B72EB86DB5CCF6F2303AFB3975BD597A03A456A11036D4F2A187EA148A80507D1616434193135549A0FAE4404652533863D20AAD2C6D7BD6506BF9BEA5F4F0A5801D243DBEB9581C778B70891E3FF1E15BDD6CCFE8883A155A71C21B64DB6D515D44391FC94DF2E39CE11273C344964F9766FB99A508988AF7C2D5C50A9D7FFC5165A038319CB55BDDA72050E9D543F7F6C272CA84812C3F8AE2870CDE8317DB096088766F0C2FAAE5A3017965C0AB025E11F06A806680C3C064106330C767282A92B8A9090D21D71B48F7FAD8D4174088F80D753EA9F8F363A0F9A40551050CC3578705AF8AD23AF22A815AC7DC3AE2F4AE639978B31A6FF6A37353931F6564EA6183F305571E64818941A6BE8A5FC6929C4A4D8D9C31F1A947D13702B9C7B1F4B06E554CB6CEC23F88840CCD8CF5C4A67E1C9F7AAE2689653A753436F5D3D8D4AB5C0B22928EA6CE4563EA399DA8393EF5861FE5063049E8845215EB8164C49462108926F5F8AA66BF69C6A6D1E38F4D1123A09A2A7FE28BA1017E98F155E824C527286BDC6F6054EE8292186447E31D7E83878365F1762E2D68C34D153AC341D4394F7D04ECA9E7CABF614357CBE21C7C8515AA6AB3BFD6083547228146B55155FD88C17341D2408840C95C141C13959223DAD8C8CE9AE26C6C7A3134A811003F8A28C494486CBA03D211899CCA852F6C98F175CDF1755219A102C15987C037FB3940D39D70856B6492452306CA2F5B67C6A77B2090E4F20BBFC517A8E36B00A3C7A7FDB1E93E38EE4A43582AAD1997FED317C6A777C4A7778B8B7A52CAAE1484698B93617AB799F431CD346B0D23DEC973DA199FCEC6BA113BC498A336C629329D8D4F5F5693D4A5A663EEA727308A297B52E37C238C4EEDF1E92BE3EBE2D3D32A466A52DDFC68E77940A080F59862EC6532F7D836F4F8F4FB0D21BD3FA86376D19D83D454AB863030BC126511B16ABB698A598D271B91A6CA4895513A557746A1BA118B470D60C7547C26DDBAA7F25DCA67B99DA4593F7795E5706A73BA73B9BE7436EF7E0160B98F54F8F3D622F4AF9D5DC3FF7CFEF28FFBFF033496FE978D2A3AEF546DB3D0F9C3FF77C42E70CEAEFAFF33CEF6F1CBFB17E1043808D88333EB004E925B71961C9413E546DA2A725FD57E758CBCF769AA759EEB61FCDDDB71FF2D86BCDFAB406B1A67C48D3841E6701EECC50973AFBCF94F74AAF4DA0E6E1AD402F8699C80B3E0E63D0D9FD73E266FC00C80EEC8A97A64164D0745A6ADFCB39286E48DA379128F2EC88CE187CFB6452A789A4FA9E28DCBF893F0362D7215FB2390298DE79E783362C7F80C3BF99C3F06AC5896DA87B69C8A618759A5E322FC39E057FAF269BFADFCC763C621DF2BB6B26C1E36E5AA2C7BFBB15A6958CEF63CCFACE302397D73EF2EE14F8AE523C47720340B2D49F7E32F893B9136FCF18B5D4B2446153DEE4C0D8B053CA7FBCAD12448F1985B3D7D59CFEE92DFF9BFC8FEB325EEFD7267318C3BA10C24AAE7E64FC57BA5C47B66DFE3A37E7CCCD7489F4E481444F310AC984424FE5CBFFFD6CF1EF73DFE47FEDB07FE9FCFFF0F9FFF07F785341A004A0000 | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (5488) XClient.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XClient_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5488 | XClient.exe | C:\Users\admin\AppData\Local\Temp\kek.exe | html | |
MD5:F27982FEE52E9FFCB7B92562C27DDCAC | SHA256:89B3F9E4CFB4141F19704363F13979A303012A5E863D804717280AF09F4785FD | |||
| 6004 | Taskmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 1920 | TiWorker.exe | C:\Windows\Logs\CBS\CBS.log | text | |
MD5:36C4842637A41E3EAB0EF8C5DA33B78D | SHA256:658B9200547020B5815D65F5634ABD1009706F008562300FBF52F9A5267F7686 | |||
| 5880 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\INetCache\Q84V0JUH\6hU_LneafI_NFLeDvM367ebFaKQ[1].js | binary | |
MD5:C6C21B7634D82C53FB86080014D86E66 | SHA256:D39E9BA92B07F4D50B11A49965E9B162452D7B9C9F26D9DCB07825727E31057E | |||
| 5488 | XClient.exe | C:\Users\admin\AppData\Roaming\Microsoft Edge | executable | |
MD5:EE7BDCD5297B596C840E9B9CDFF9E224 | SHA256:92C2BA7B293F6F0E9F54B5C257C4F44CE516D94E6A5F2BDA9CE71BE843C7E450 | |||
| 5880 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\67\0u2b9EXo8LdXut1MFm4AD0phBuM.br[1].js | binary | |
MD5:8C0F73D4C854DC52B555898FEF7EDB54 | SHA256:B652F917E744E7A4EADB5DF108D622FD18C793E80445FAA69B1BFFC97BE2529E | |||
| 5880 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\67\wU-YmSK-j9YaNg2gj_x4wAl_UoI[1].css | text | |
MD5:C1AC4CCA38EA836717738D7CF72B45B9 | SHA256:E4C0BF089E674482FA2FE7D558F64F9D3EBDD414EAED18908E34A6140D09B727 | |||
| 5880 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\fbaf94e759052658216786bfbabcdced1b67a5c2.tbres | binary | |
MD5:383D2C6CDD0CF96755D0377C0447420A | SHA256:F9A166C5342489B8427C2388A60A274F2F7F9CFB0E3DB60FB5D8C1BD7FAB072A | |||
| 5880 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\95d9a2a97a42f02325559b453ba7f8fe839baa18.tbres | binary | |
MD5:8325A25367CF19199E74CB59420E2DBA | SHA256:CEA8072174A9CDDB5DD3B8207DEA350BE6A5C63071287217C8F1541AB8E598AF | |||
| 5880 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\AppCache\5Y734AMR\67\Init[1].htm | html | |
MD5:46484B1853ADF445178D82ED06D9E34F | SHA256:726C1F0969157B62ACB5998DFD998A343850A705FB3F31085EC95EE2E7FF6987 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2224 | svchost.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
2224 | svchost.exe | GET | 200 | 23.48.23.193:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4944 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4944 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
2800 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5488 | XClient.exe | GET | 302 | 94.198.223.74:80 | http://cq11529.tw1.ru/kek.exe | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2224 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4556 | RUXIMICS.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5488 | XClient.exe | 147.185.221.21:12278 | results-personally.gl.at.ply.gg | PLAYIT-GG | US | malicious |
2224 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2224 | svchost.exe | 23.48.23.193:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2224 | svchost.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
results-personally.gl.at.ply.gg |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Misc activity | ET TA_ABUSED_SERVICES Tunneling Service in DNS Lookup (* .ply .gg) |
2192 | svchost.exe | Potentially Bad Traffic | ET INFO playit .gg Tunneling Domain in DNS Lookup |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |
5488 | XClient.exe | Malware Command and Control Activity Detected | REMOTE [ANY.RUN] Xworm TCP Packet |