Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Agent Tesla ist eine Spyware, die Informationen über die Aktionen ihrer Opfer sammelt, indem sie Tastatureingaben und Benutzerinteraktionen aufzeichnet. Sie wird auf der speziellen Website, auf der diese Malware verkauft wird, fälschlicherweise als legitime Software vermarktet.
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.
A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.
DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks.
For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common.
FormBook is a data stealer that is being distributed as a MaaS. FormBook differs from a lot of competing malware by its extreme ease of use that allows even the unexperienced
threat actors to use FormBook virus.
GCleaner is a type of malware loader that has the capability to deliver numerous malicious software programs, which differ based on the location of the targeted victim. This malware is commonly spread through fraudulent websites that advertise free PC optimization tools
A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.
Lu0Bot is a Node.js malware that was first discovered in February 2021. It is a type of Trojan that primarily acts as a stealer by responding to commands from a command-and-control (C2) server and transmitting encrypted system data. It can also operate as a DDoS bot. Lu0Bot employs multiple obfuscation techniques to avoid detection and make analysis more difficult.
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Vidar is a dangerous malware that steals information and cryptocurrency from infected users. It derives its name from the ancient Scandinavian god of Vengeance. This stealer has been terrorizing the internet since 2018.
XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails.
XWorm ist ein Remote Access Trojaner (RAT), der als Malware-as-a-Service verkauft wird. Er verfügt über ein umfangreiches Hacking-Toolset und ist in der Lage, private Informationen und Dateien auf dem infizierten Computer zu sammeln, MetaMask- und Telegram-Konten zu kapern und Benutzeraktivitäten zu verfolgen. XWorm wird in der Regel durch mehrstufige Angriffe auf die Computer der Opfer übertragen, die mit Phishing-E-Mails beginnen.
ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
Launch configuration
Task duration:
300 seconds
Heavy Evasion option:
Network geolocation:
off
Additional time used:
240 seconds
MITM proxy:
off
Privacy:
Public submission
Fakenet option:
off
Route via Tor:
off
Autoconfirmation of UAC:
on
Network:
on
Software preset
Internet Explorer 11.0.9600.19596 KB4534251
Adobe Acrobat Reader DC (20.013.20064)
Adobe Acrobat Reader DC (20.013.20064)
Adobe Flash Player 32 ActiveX (32.0.0.453)
Adobe Flash Player 32 ActiveX (32.0.0.453)
Adobe Flash Player 32 NPAPI (32.0.0.453)
Adobe Flash Player 32 NPAPI (32.0.0.453)
Adobe Flash Player 32 PPAPI (32.0.0.453)
Adobe Flash Player 32 PPAPI (32.0.0.453)
Adobe Refresh Manager (1.8.0)
Adobe Refresh Manager (1.8.0)
CCleaner (6.14)
CCleaner (6.14)
FileZilla 3.65.0 (3.65.0)
FileZilla 3.65.0 (3.65.0)
Google Chrome (109.0.5414.120)
Google Chrome (109.0.5414.120)
Google Update Helper (1.3.36.31)
Google Update Helper (1.3.36.31)
Java 8 Update 271 (8.0.2710.9)
Java 8 Update 271 (8.0.2710.9)
Java Auto Updater (2.8.271.9)
Java Auto Updater (2.8.271.9)
Microsoft .NET Framework 4.8 (4.8.03761)
Microsoft .NET Framework 4.8 (4.8.03761)
Microsoft .NET Framework 4.8 (4.8.03761)
Microsoft .NET Framework 4.8 (4.8.03761)
Microsoft Edge (109.0.1518.115)
Microsoft Edge (109.0.1518.115)
Microsoft Edge Update (1.3.175.29)
Microsoft Edge Update (1.3.175.29)
Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Professional 2010 (14.0.6029.1000)
Microsoft Office Professional 2010 (14.0.6029.1000)
Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
Microsoft Office Proof (English) 2010 (14.0.6029.1000)
Microsoft Office Proof (English) 2010 (14.0.6029.1000)
Microsoft Office Proof (French) 2010 (14.0.6029.1000)
Microsoft Office Proof (French) 2010 (14.0.6029.1000)
Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
Microsoft Office Proof (German) 2010 (14.0.4763.1000)
Microsoft Office Proof (German) 2010 (14.0.4763.1000)
Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Single Image 2010 (14.0.6029.1000)
Microsoft Office Single Image 2010 (14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (14.36.32532.0)
Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532 (14.36.32532.0)
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (14.36.32532)
Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532 (14.36.32532)
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (14.36.32532)
Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532 (14.36.32532)
Mozilla Firefox (x86 en-US) (115.0.2)
Mozilla Firefox (x86 en-US) (115.0.2)
Mozilla Maintenance Service (115.0.2)
Mozilla Maintenance Service (115.0.2)
Notepad++ (32-bit x86) (7.9.1)
Notepad++ (32-bit x86) (7.9.1)
PowerShell 7-x86 (7.2.11.0)
PowerShell 7-x86 (7.2.11.0)
Skype version 8.110 (8.110)
Skype version 8.110 (8.110)
Update for Microsoft .NET Framework 4.8 (KB4503575) (1)
Update for Microsoft .NET Framework 4.8 (KB4503575) (1)
VLC media player (3.0.11)
VLC media player (3.0.11)
WinRAR 5.91 (32-bit) (5.91.0)
WinRAR 5.91 (32-bit) (5.91.0)
Hotfixes
Client LanguagePack Package
Client Refresh LanguagePack Package
CodecPack Basic Package
Foundation Package
IE Hyphenation Parent Package English
IE Spelling Parent Package English
IE Troubleshooters Package
InternetExplorer Optional Package
InternetExplorer Package TopLevel
KB2479943
KB2491683
KB2506212
KB2506928
KB2532531
KB2533552
KB2533623
KB2534111
KB2545698
KB2547666
KB2552343
KB2560656
KB2564958
KB2574819
KB2579686
KB2585542
KB2604115
KB2620704
KB2621440
KB2631813
KB2639308
KB2640148
KB2653956
KB2654428
KB2656356
KB2660075
KB2667402
KB2676562
KB2685811
KB2685813
KB2685939
KB2690533
KB2698365
KB2705219
KB2719857
KB2726535
KB2727528
KB2729094
KB2729452
KB2731771
KB2732059
KB2736422
KB2742599
KB2750841
KB2758857
KB2761217
KB2770660
KB2773072
KB2786081
KB2789645
KB2799926
KB2800095
KB2807986
KB2808679
KB2813347
KB2813430
KB2820331
KB2834140
KB2836942
KB2836943
KB2840631
KB2843630
KB2847927
KB2852386
KB2853952
KB2857650
KB2861698
KB2862152
KB2862330
KB2862335
KB2864202
KB2868038
KB2871997
KB2872035
KB2884256
KB2891804
KB2893294
KB2893519
KB2894844
KB2900986
KB2908783
KB2911501
KB2912390
KB2918077
KB2919469
KB2923545
KB2931356
KB2937610
KB2943357
KB2952664
KB2968294
KB2970228
KB2972100
KB2972211
KB2973112
KB2973201
KB2977292
KB2978120
KB2978742
KB2984972
KB2984976
KB2984976 SP1
KB2985461
KB2991963
KB2992611
KB2999226
KB3004375
KB3006121
KB3006137
KB3010788
KB3011780
KB3013531
KB3019978
KB3020370
KB3020388
KB3021674
KB3021917
KB3022777
KB3023215
KB3030377
KB3031432
KB3035126
KB3037574
KB3042058
KB3045685
KB3046017
KB3046269
KB3054476
KB3055642
KB3059317
KB3060716
KB3061518
KB3067903
KB3068708
KB3071756
KB3072305
KB3074543
KB3075226
KB3078667
KB3080149
KB3086255
KB3092601
KB3093513
KB3097989
KB3101722
KB3102429
KB3102810
KB3107998
KB3108371
KB3108664
KB3109103
KB3109560
KB3110329
KB3115858
KB3118401
KB3122648
KB3123479
KB3126587
KB3127220
KB3133977
KB3137061
KB3138378
KB3138612
KB3138910
KB3139398
KB3139914
KB3140245
KB3147071
KB3150220
KB3150513
KB3155178
KB3156016
KB3159398
KB3161102
KB3161949
KB3170735
KB3172605
KB3179573
KB3184143
KB3185319
KB4019990
KB4040980
KB4474419
KB4490628
KB4524752
KB4532945
KB4536952
KB4567409
KB958488
KB976902
KB982018
LocalPack AU Package
LocalPack CA Package
LocalPack GB Package
LocalPack US Package
LocalPack ZA Package
Package 21 for KB2984976
Package 38 for KB2984976
Package 45 for KB2984976
Package 59 for KB2984976
Package 7 for KB2984976
Package 76 for KB2984976
PlatformUpdate Win7 SRV08R2 Package TopLevel
ProfessionalEdition
RDP BlueIP Package TopLevel
RDP WinIP Package TopLevel
RollupFix
UltimateEdition
WUClient SelfUpdate ActiveX
WUClient SelfUpdate Aux TopLevel
WUClient SelfUpdate Core TopLevel
WinMan WinIP Package TopLevel
MALICIOUS
Drops the executable file immediately after the start
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
rtx.exe (PID: 1520)
Bypass3_Pure_Mode.exe (PID: 2804)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
SrbijaSetupHokej.exe (PID: 3104)
SrbijaSetupHokej.exe (PID: 3532)
7zipsilentinstaller.exe (PID: 3820)
ChromeSetup.exe (PID: 3920)
GoogleUpdateSetup.exe (PID: 4032)
GoogleUpdate.exe (PID: 1036)
svchost.exe (PID: 3592)
crt.exe (PID: 4056)
crt.exe (PID: 3320)
turquoisecdplayer.exe (PID: 928)
crt.tmp (PID: 2844)
conhost.exe (PID: 2836)
sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3188)
o2i3jroi23joj23ikrjokij3oroi.exe (PID: 316)
vpn-1002.exe (PID: 856)
msiexec.exe (PID: 2412)
Pirate_24S.exe (PID: 2828)
222.exe (PID: 2384)
cmd.exe (PID: 3000)
109.0.5414.120_chrome_installer.exe (PID: 3540)
setup.exe (PID: 1368)
Actions looks like stealing of personal data
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 1900)
RegSvcs.exe (PID: 848)
RegSvcs.exe (PID: 2344)
netbtugc.exe (PID: 2896)
gHIvTf22qvmZjum.exe (PID: 3436)
Steals credentials from Web Browsers
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 1900)
RegSvcs.exe (PID: 848)
RegSvcs.exe (PID: 2344)
gHIvTf22qvmZjum.exe (PID: 3436)
DCRAT has been detected (YARA)
New Text Document.exe (PID: 2040)
HAUSBOMBER has been detected (YARA)
New Text Document.exe (PID: 2040)
Changes the autorun value in the registry
rtx.exe (PID: 1520)
setup.exe (PID: 1368)
Connects to the CnC server
RegSvcs.exe (PID: 848)
gHIvTf22qvmZjum.exe (PID: 3436)
New Text Document.exe (PID: 2040)
AGENTTESLA has been detected (SURICATA)
RegSvcs.exe (PID: 848)
gHIvTf22qvmZjum.exe (PID: 3436)
Create files in the Startup directory
XClient.exe (PID: 2924)
svchost.exe (PID: 3592)
AGENTTESLA has been detected (YARA)
RegSvcs.exe (PID: 848)
RegSvcs.exe (PID: 2344)
gHIvTf22qvmZjum.exe (PID: 3436)
Steals credentials
netbtugc.exe (PID: 2896)
XWORM has been detected (YARA)
csrss.exe (PID: 2860)
svchost.exe (PID: 3592)
XClient.exe (PID: 2924)
Request from PowerShell which ran from CMD.EXE
powershell.exe (PID: 3276)
Starts CMD.EXE for self-deleting
inte.exe (PID: 3344)
ASYNCRAT has been detected (YARA)
vax.exe (PID: 580)
FORMBOOK has been detected (SURICATA)
New Text Document.exe (PID: 2040)
Creates a writable file in the system directory
cmd.exe (PID: 3000)
LU0BOT has been detected (YARA)
fmoixjlhi.exe (PID: 3476)
FORMBOOK has been detected (YARA)
netbtugc.exe (PID: 2896)
REDLINE has been detected (YARA)
crypted.exe (PID: 2660)
VIDAR has been detected (YARA)
kat3466.tmp (PID: 2788)
SUSPICIOUS
Reads the Internet Settings
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 2660)
RegSvcs.exe (PID: 848)
Bypass3_Pure_Mode.exe (PID: 2804)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
7zipsilentinstaller.exe (PID: 3820)
GoogleUpdate.exe (PID: 2844)
netbtugc.exe (PID: 2896)
svchost.exe (PID: 3592)
conhost.exe (PID: 2836)
Setup.exe (PID: 2544)
inte.exe (PID: 3344)
cmd.exe (PID: 3568)
gHIvTf22qvmZjum.exe (PID: 3436)
vpn-1002.exe (PID: 856)
powershell.exe (PID: 3276)
powershell.exe (PID: 3324)
Pirate_24S.exe (PID: 2828)
wscript.exe (PID: 928)
222.exe (PID: 2384)
regedt32.exe (PID: 856)
cmd.exe (PID: 1312)
GoogleUpdate.exe (PID: 1292)
regedt32.exe (PID: 10448)
turquoisecdplayer.exe (PID: 1120)
Reads security settings of Internet Explorer
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
Bypass3_Pure_Mode.exe (PID: 2804)
7zipsilentinstaller.exe (PID: 3820)
Setup.exe (PID: 2544)
conhost.exe (PID: 2836)
inte.exe (PID: 3344)
vpn-1002.exe (PID: 856)
msiexec.exe (PID: 2412)
Pirate_24S.exe (PID: 2828)
222.exe (PID: 2384)
turquoisecdplayer.exe (PID: 1120)
Reads Microsoft Outlook installation path
New Text Document.bin.exe (PID: 3968)
Reads Internet Explorer settings
New Text Document.bin.exe (PID: 3968)
Reads settings of System Certificates
New Text Document.exe (PID: 2040)
RegSvcs.exe (PID: 1900)
7zipsilentinstaller.exe (PID: 3820)
GoogleUpdate.exe (PID: 2844)
RegSvcs.exe (PID: 2344)
Setup.exe (PID: 2544)
vpn-1002.exe (PID: 856)
GoogleUpdate.exe (PID: 1292)
Executable content was dropped or overwritten
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
rtx.exe (PID: 1520)
Bypass3_Pure_Mode.exe (PID: 2804)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
SrbijaSetupHokej.exe (PID: 3104)
SrbijaSetupHokej.exe (PID: 3532)
7zipsilentinstaller.exe (PID: 3820)
GoogleUpdateSetup.exe (PID: 4032)
GoogleUpdate.exe (PID: 1036)
ChromeSetup.exe (PID: 3920)
netbtugc.exe (PID: 2896)
svchost.exe (PID: 3592)
crt.tmp (PID: 2844)
crt.exe (PID: 4056)
crt.exe (PID: 3320)
turquoisecdplayer.exe (PID: 928)
conhost.exe (PID: 2836)
sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3188)
vpn-1002.exe (PID: 856)
o2i3jroi23joj23ikrjokij3oroi.exe (PID: 316)
Pirate_24S.exe (PID: 2828)
222.exe (PID: 2384)
cmd.exe (PID: 3000)
109.0.5414.120_chrome_installer.exe (PID: 3540)
setup.exe (PID: 1368)
Potential Corporate Privacy Violation
New Text Document.exe (PID: 2040)
msiexec.exe (PID: 2412)
rtx.exe (PID: 1520)
Process requests binary or script from the Internet
New Text Document.exe (PID: 2040)
Connects to the server without a host name
New Text Document.exe (PID: 2040)
inte.exe (PID: 3344)
Accesses Microsoft Outlook profiles
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 1900)
RegSvcs.exe (PID: 848)
RegSvcs.exe (PID: 2344)
gHIvTf22qvmZjum.exe (PID: 3436)
Connects to FTP
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 848)
gHIvTf22qvmZjum.exe (PID: 3436)
rtx.exe (PID: 1520)
Creates file in the systems drive root
ntvdm.exe (PID: 2232)
Connects to unusual port
RegSvcs.exe (PID: 1864)
example.exe (PID: 1344)
venom.exe (PID: 2708)
RegSvcs.exe (PID: 848)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
vax.exe (PID: 580)
svchost.exe (PID: 3592)
rtx.exe (PID: 1520)
gHIvTf22qvmZjum.exe (PID: 3436)
New Text Document.exe (PID: 2040)
turquoisecdplayer.exe (PID: 1120)
Connects to SMTP port
RegSvcs.exe (PID: 1900)
RegSvcs.exe (PID: 2344)
rtx.exe (PID: 1520)
The process checks if it is being run in the virtual environment
New Text Document.exe (PID: 2040)
Application launched itself
rtx.exe (PID: 2188)
gHIvTf22qvmZjum.exe (PID: 1888)
cmd.exe (PID: 3308)
fmoixjlhi.exe (PID: 2732)
setup.exe (PID: 1368)
setup.exe (PID: 3708)
GoogleUpdate.exe (PID: 1592)
The process creates files with name similar to system file names
rtx.exe (PID: 1520)
New Text Document.exe (PID: 2040)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
svchost.exe (PID: 3592)
Checks for external IP
RegSvcs.exe (PID: 2660)
csrss.exe (PID: 2860)
gHIvTf22qvmZjum.exe (PID: 3436)
Device Retrieving External IP Address Detected
RegSvcs.exe (PID: 2660)
gHIvTf22qvmZjum.exe (PID: 3436)
Adds/modifies Windows certificates
7zipsilentinstaller.exe (PID: 3820)
Drops 7-zip archiver for unpacking
7zipsilentinstaller.exe (PID: 3820)
conhost.exe (PID: 2836)
222.exe (PID: 2384)
Reads the Windows owner or organization settings
SrbijaSetupHokej.tmp (PID: 3836)
crt.tmp (PID: 2844)
msiexec.exe (PID: 2412)
Disables SEHOP
GoogleUpdate.exe (PID: 1036)
Creates/Modifies COM task schedule object
GoogleUpdate.exe (PID: 1792)
Executes as Windows Service
GoogleUpdate.exe (PID: 1592)
Process drops SQLite DLL files
netbtugc.exe (PID: 2896)
Loads DLL from Mozilla Firefox
netbtugc.exe (PID: 2896)
The process drops C-runtime libraries
crt.tmp (PID: 2844)
Process drops legitimate windows executable
crt.tmp (PID: 2844)
msiexec.exe (PID: 2412)
Pirate_24S.exe (PID: 2828)
cmd.exe (PID: 3000)
Checks Windows Trust Settings
Setup.exe (PID: 2544)
vpn-1002.exe (PID: 856)
Uses ATTRIB.EXE to modify file attributes
cmd.exe (PID: 3568)
cmd.exe (PID: 1312)
Executing commands from a ".bat" file
conhost.exe (PID: 2836)
vpn-1002.exe (PID: 856)
cmd.exe (PID: 3308)
222.exe (PID: 2384)
Starts CMD.EXE for commands execution
conhost.exe (PID: 2836)
vpn-1002.exe (PID: 856)
cmd.exe (PID: 3308)
inte.exe (PID: 3344)
wscript.exe (PID: 928)
222.exe (PID: 2384)
Starts application with an unusual extension
sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3188)
o2i3jroi23joj23ikrjokij3oroi.exe (PID: 316)
The Powershell connects to the Internet
powershell.exe (PID: 3324)
powershell.exe (PID: 3276)
Unusual connection from system programs
powershell.exe (PID: 3324)
powershell.exe (PID: 3276)
Starts POWERSHELL.EXE for commands execution
cmd.exe (PID: 3308)
Probably download files using WebClient
cmd.exe (PID: 3308)
Uses TASKKILL.EXE to kill process
cmd.exe (PID: 600)
Uses REG/REGEDIT.EXE to modify registry
fmoixjlhi.exe (PID: 3476)
regedt32.exe (PID: 856)
regedt32.exe (PID: 10448)
The process executes VB scripts
Pirate_24S.exe (PID: 2828)
Executing commands from ".cmd" file
wscript.exe (PID: 928)
Runs shell command (SCRIPT)
wscript.exe (PID: 928)
Takes ownership (TAKEOWN.EXE)
cmd.exe (PID: 3000)
Uses ICACLS.EXE to modify access control lists
cmd.exe (PID: 3000)
Runs PING.EXE to delay simulation
cmd.exe (PID: 3000)
Contacting a server suspected of hosting an CnC
New Text Document.exe (PID: 2040)
Creates a software uninstall entry
setup.exe (PID: 1368)
Reads the date of Windows installation
setup.exe (PID: 3708)
Searches for installed software
setup.exe (PID: 1368)
Connects to SSH
rtx.exe (PID: 1520)
INFO
Checks supported languages
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
toolspub1.exe (PID: 2316)
wmpnscfg.exe (PID: 764)
wxijgyp.exe (PID: 1856)
RegSvcs.exe (PID: 1864)
zwuivg.exe (PID: 2332)
RegSvcs.exe (PID: 1900)
rtx.exe (PID: 2188)
example.exe (PID: 1344)
backdoor.exe (PID: 2640)
rtx.exe (PID: 1520)
asdf.exe (PID: 560)
venom.exe (PID: 2708)
wsiopohwqsd.exe (PID: 2700)
RegSvcs.exe (PID: 2660)
QEwecfyhj.exe (PID: 2436)
RegSvcs.exe (PID: 2416)
tsaplQyj.exe (PID: 924)
RegSvcs.exe (PID: 848)
Bypass3_Pure_Mode.exe (PID: 2804)
XClient.exe (PID: 2924)
rooma.exe (PID: 2636)
csrss.exe (PID: 2860)
SrbijaSetupHokej.exe (PID: 3104)
SrbijaSetupHokej.tmp (PID: 3060)
SrbijaSetupHokej.exe (PID: 3532)
7zipsilentinstaller.exe (PID: 3820)
ChromeSetup.exe (PID: 3920)
7zipInstaller.exe (PID: 3476)
SrbijaSetupHokej.tmp (PID: 3836)
GoogleUpdate.exe (PID: 3756)
GoogleUpdateSetup.exe (PID: 4032)
GoogleUpdate.exe (PID: 1036)
GoogleUpdate.exe (PID: 2844)
GoogleUpdate.exe (PID: 660)
GoogleUpdate.exe (PID: 1792)
GoogleUpdate.exe (PID: 1768)
GoogleUpdate.exe (PID: 1592)
vax.exe (PID: 580)
gywervcyuj.exe (PID: 956)
xxxz.exe (PID: 3356)
ngown.exe (PID: 2168)
RegSvcs.exe (PID: 3484)
gHIvTf22qvmZjum.exe (PID: 1888)
RegSvcs.exe (PID: 2344)
crypted.exe (PID: 2660)
crt.exe (PID: 4056)
xin.exe (PID: 2800)
Setup.exe (PID: 2544)
svchost.exe (PID: 3592)
crt.tmp (PID: 1024)
crt.tmp (PID: 2844)
crt.exe (PID: 3320)
conhost.exe (PID: 2836)
sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3188)
turquoisecdplayer.exe (PID: 928)
turquoisecdplayer.exe (PID: 1120)
gHIvTf22qvmZjum.exe (PID: 3436)
kat3466.tmp (PID: 2788)
mode.com (PID: 2832)
inte.exe (PID: 3344)
vpn-1002.exe (PID: 856)
o2i3jroi23joj23ikrjokij3oroi.exe (PID: 316)
kat3E1A.tmp (PID: 1548)
msiexec.exe (PID: 2412)
msiexec.exe (PID: 2284)
fmoixjlhi.exe (PID: 3476)
222.exe (PID: 2384)
fmoixjlhi.exe (PID: 2732)
Pirate_24S.exe (PID: 2828)
setup.exe (PID: 1368)
setup.exe (PID: 3600)
mode.com (PID: 2792)
109.0.5414.120_chrome_installer.exe (PID: 3540)
setup.exe (PID: 3708)
setup.exe (PID: 2456)
GoogleUpdateOnDemand.exe (PID: 2364)
GoogleUpdate.exe (PID: 312)
GoogleCrashHandler.exe (PID: 2872)
GoogleUpdate.exe (PID: 1292)
elevation_service.exe (PID: 3524)
Reads the computer name
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
wmpnscfg.exe (PID: 764)
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 1900)
rtx.exe (PID: 1520)
RegSvcs.exe (PID: 2660)
RegSvcs.exe (PID: 2416)
RegSvcs.exe (PID: 848)
Bypass3_Pure_Mode.exe (PID: 2804)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
SrbijaSetupHokej.tmp (PID: 3060)
7zipsilentinstaller.exe (PID: 3820)
SrbijaSetupHokej.tmp (PID: 3836)
GoogleUpdate.exe (PID: 3756)
GoogleUpdate.exe (PID: 1036)
GoogleUpdate.exe (PID: 660)
GoogleUpdate.exe (PID: 1792)
GoogleUpdate.exe (PID: 2844)
GoogleUpdate.exe (PID: 1768)
vax.exe (PID: 580)
GoogleUpdate.exe (PID: 1592)
RegSvcs.exe (PID: 3484)
gHIvTf22qvmZjum.exe (PID: 1888)
RegSvcs.exe (PID: 2344)
svchost.exe (PID: 3592)
xin.exe (PID: 2800)
crt.tmp (PID: 1024)
crt.tmp (PID: 2844)
turquoisecdplayer.exe (PID: 928)
Setup.exe (PID: 2544)
conhost.exe (PID: 2836)
gHIvTf22qvmZjum.exe (PID: 3436)
kat3466.tmp (PID: 2788)
inte.exe (PID: 3344)
kat3E1A.tmp (PID: 1548)
msiexec.exe (PID: 2412)
msiexec.exe (PID: 2284)
fmoixjlhi.exe (PID: 3476)
fmoixjlhi.exe (PID: 2732)
Pirate_24S.exe (PID: 2828)
222.exe (PID: 2384)
109.0.5414.120_chrome_installer.exe (PID: 3540)
setup.exe (PID: 1368)
GoogleCrashHandler.exe (PID: 2872)
setup.exe (PID: 3708)
GoogleUpdate.exe (PID: 312)
GoogleUpdate.exe (PID: 1292)
elevation_service.exe (PID: 3524)
turquoisecdplayer.exe (PID: 1120)
vpn-1002.exe (PID: 856)
Checks proxy server information
New Text Document.bin.exe (PID: 3968)
netbtugc.exe (PID: 2896)
Setup.exe (PID: 2544)
inte.exe (PID: 3344)
vpn-1002.exe (PID: 856)
turquoisecdplayer.exe (PID: 1120)
Reads the machine GUID from the registry
New Text Document.bin.exe (PID: 3968)
New Text Document.exe (PID: 2040)
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 1900)
rtx.exe (PID: 1520)
RegSvcs.exe (PID: 2660)
RegSvcs.exe (PID: 2416)
RegSvcs.exe (PID: 848)
Bypass3_Pure_Mode.exe (PID: 2804)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
7zipsilentinstaller.exe (PID: 3820)
GoogleUpdate.exe (PID: 3756)
GoogleUpdate.exe (PID: 1036)
GoogleUpdate.exe (PID: 1768)
vax.exe (PID: 580)
GoogleUpdate.exe (PID: 2844)
GoogleUpdate.exe (PID: 1592)
RegSvcs.exe (PID: 3484)
gHIvTf22qvmZjum.exe (PID: 1888)
RegSvcs.exe (PID: 2344)
svchost.exe (PID: 3592)
Setup.exe (PID: 2544)
gHIvTf22qvmZjum.exe (PID: 3436)
inte.exe (PID: 3344)
vpn-1002.exe (PID: 856)
msiexec.exe (PID: 2412)
msiexec.exe (PID: 2284)
fmoixjlhi.exe (PID: 2732)
fmoixjlhi.exe (PID: 3476)
setup.exe (PID: 3708)
setup.exe (PID: 1368)
GoogleUpdate.exe (PID: 312)
GoogleUpdate.exe (PID: 1292)
elevation_service.exe (PID: 3524)
turquoisecdplayer.exe (PID: 1120)
Disables trace logs
New Text Document.exe (PID: 2040)
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 2660)
RegSvcs.exe (PID: 848)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
7zipsilentinstaller.exe (PID: 3820)
svchost.exe (PID: 3592)
gHIvTf22qvmZjum.exe (PID: 3436)
powershell.exe (PID: 3276)
powershell.exe (PID: 3324)
Reads Environment values
New Text Document.exe (PID: 2040)
RegSvcs.exe (PID: 1864)
RegSvcs.exe (PID: 1900)
RegSvcs.exe (PID: 2660)
RegSvcs.exe (PID: 2416)
RegSvcs.exe (PID: 848)
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
7zipsilentinstaller.exe (PID: 3820)
vax.exe (PID: 580)
RegSvcs.exe (PID: 3484)
RegSvcs.exe (PID: 2344)
svchost.exe (PID: 3592)
gHIvTf22qvmZjum.exe (PID: 3436)
Manual execution by a user
New Text Document.exe (PID: 2040)
wmpnscfg.exe (PID: 764)
Reads the software policy settings
New Text Document.exe (PID: 2040)
RegSvcs.exe (PID: 1900)
7zipsilentinstaller.exe (PID: 3820)
GoogleUpdate.exe (PID: 2844)
GoogleUpdate.exe (PID: 1592)
RegSvcs.exe (PID: 2344)
Setup.exe (PID: 2544)
vpn-1002.exe (PID: 856)
GoogleUpdate.exe (PID: 1292)
Reads mouse settings
wxijgyp.exe (PID: 1856)
zwuivg.exe (PID: 2332)
wsiopohwqsd.exe (PID: 2700)
QEwecfyhj.exe (PID: 2436)
tsaplQyj.exe (PID: 924)
gywervcyuj.exe (PID: 956)
ngown.exe (PID: 2168)
Create files in a temporary directory
New Text Document.exe (PID: 2040)
wxijgyp.exe (PID: 1856)
zwuivg.exe (PID: 2332)
rtx.exe (PID: 1520)
wsiopohwqsd.exe (PID: 2700)
QEwecfyhj.exe (PID: 2436)
tsaplQyj.exe (PID: 924)
SrbijaSetupHokej.exe (PID: 3104)
SrbijaSetupHokej.exe (PID: 3532)
7zipsilentinstaller.exe (PID: 3820)
ChromeSetup.exe (PID: 3920)
gywervcyuj.exe (PID: 956)
ngown.exe (PID: 2168)
netbtugc.exe (PID: 2896)
crt.exe (PID: 4056)
crt.exe (PID: 3320)
crt.tmp (PID: 2844)
conhost.exe (PID: 2836)
vpn-1002.exe (PID: 856)
msiexec.exe (PID: 2412)
Pirate_24S.exe (PID: 2828)
222.exe (PID: 2384)
Creates files in the program directory
rtx.exe (PID: 1520)
GoogleUpdateSetup.exe (PID: 4032)
GoogleUpdate.exe (PID: 1036)
GoogleUpdate.exe (PID: 660)
GoogleUpdate.exe (PID: 2844)
GoogleUpdate.exe (PID: 1792)
GoogleUpdate.exe (PID: 1768)
GoogleUpdate.exe (PID: 1592)
turquoisecdplayer.exe (PID: 928)
Setup.exe (PID: 2544)
109.0.5414.120_chrome_installer.exe (PID: 3540)
setup.exe (PID: 1368)
setup.exe (PID: 3708)
turquoisecdplayer.exe (PID: 1120)
GoogleUpdate.exe (PID: 1292)
Creates files or folders in the user directory
XClient.exe (PID: 2924)
csrss.exe (PID: 2860)
vax.exe (PID: 580)
netbtugc.exe (PID: 2896)
svchost.exe (PID: 3592)
crt.tmp (PID: 2844)
vpn-1002.exe (PID: 856)
inte.exe (PID: 3344)
Drops the executable file immediately after the start
netbtugc.exe (PID: 2896)
Reads security settings of Internet Explorer
netbtugc.exe (PID: 2896)
regedt32.exe (PID: 856)
regedt32.exe (PID: 10448)
Creates a software uninstall entry
crt.tmp (PID: 2844)
Executable content was dropped or overwritten
msiexec.exe (PID: 2412)
Application launched itself
msiexec.exe (PID: 2412)
chrome.exe (PID: 3560)
Reads CPU info
fmoixjlhi.exe (PID: 2732)
fmoixjlhi.exe (PID: 3476)
The process uses the downloaded file
chrome.exe (PID: 8332)
chrome.exe (PID: 8340)
Executes as Windows Service
elevation_service.exe (PID: 3524)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
XWorm
(PID) Process(2860) csrss.exe
C245.141.26.119:1996
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep time3
USB drop nameXWorm V5.4
MutexwHK5NlknpAL3Lk1X
(PID) Process(3592) svchost.exe
C285.203.4.146:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep time3
USB drop nameXWorm V5.4
MutexeItTbYBfBYihwkyW
(PID) Process(2924) XClient.exe
C245.141.27.41:7000
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep time3
USB drop nameXWorm V5.4
Mutex9ZF9ZsOZGh1T1r1n
AsyncRat
(PID) Process(580) vax.exe
C2 (1)185.196.10.81
Ports (1)4449
VersionVenom RAT + HVNC + Stealer + Grabber v6.0.3