File name:

VsTelemetry.7z

Full analysis: https://app.any.run/tasks/cf64a3b8-fd72-40fd-883f-1d3e63d78cf0
Verdict: Malicious activity
Analysis date: June 27, 2022, 13:01:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
cobalt
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

0EFCEAECE847C3CBD141293AC42A11C9

SHA1:

0DD818A2AC5F9FED7D12317BC57C0B91E664556F

SHA256:

C4A4DC81ABC724D5A8C003746A095DB746CF3F83B64623144AAF2B20DAAF787F

SSDEEP:

6144:Xd5mlPjbXM3jxXIvtcBVMDbqpw8FtaYeu/wYX/+YfFlFZcyVdHEJ0eoHrBWHeW4V:tM4jx4vtcXaY/NlFZdVNEt26pzdo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • safenotes.exe (PID: 4036)
      • safenotes.exe (PID: 3972)
    • Loads dropped or rewritten executable

      • safenotes.exe (PID: 4036)
      • safenotes.exe (PID: 3972)
    • COBALT detected by memory dumps

      • esentutl.exe (PID: 876)
      • esentutl.exe (PID: 1032)
    • Drops executable file immediately after starts

      • WinRAR.exe (PID: 1580)
  • SUSPICIOUS

    • Checks supported languages

      • safenotes.exe (PID: 3972)
      • safenotes.exe (PID: 4036)
      • WinRAR.exe (PID: 1580)
    • Modifies files in Chrome extension folder

      • chrome.exe (PID: 3692)
    • Reads the computer name

      • WinRAR.exe (PID: 1580)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1580)
    • Drops a file with a compile date too recent

      • WinRAR.exe (PID: 1580)
  • INFO

    • Reads the computer name

      • esentutl.exe (PID: 1032)
      • taskmgr.exe (PID: 4076)
      • chrome.exe (PID: 2484)
      • chrome.exe (PID: 3692)
      • chrome.exe (PID: 3548)
      • chrome.exe (PID: 3172)
      • chrome.exe (PID: 3460)
      • chrome.exe (PID: 3700)
      • chrome.exe (PID: 1872)
      • chrome.exe (PID: 2828)
      • chrome.exe (PID: 3248)
      • esentutl.exe (PID: 876)
    • Manual execution by user

      • taskmgr.exe (PID: 4076)
      • safenotes.exe (PID: 3972)
      • chrome.exe (PID: 3692)
      • safenotes.exe (PID: 4036)
    • Checks supported languages

      • taskmgr.exe (PID: 4076)
      • chrome.exe (PID: 3692)
      • chrome.exe (PID: 3772)
      • chrome.exe (PID: 2484)
      • chrome.exe (PID: 3548)
      • chrome.exe (PID: 1408)
      • chrome.exe (PID: 1564)
      • chrome.exe (PID: 3172)
      • chrome.exe (PID: 3860)
      • chrome.exe (PID: 2480)
      • chrome.exe (PID: 2732)
      • chrome.exe (PID: 3248)
      • chrome.exe (PID: 3096)
      • chrome.exe (PID: 2524)
      • chrome.exe (PID: 3700)
      • chrome.exe (PID: 1840)
      • chrome.exe (PID: 3460)
      • chrome.exe (PID: 3748)
      • chrome.exe (PID: 1688)
      • chrome.exe (PID: 3480)
      • chrome.exe (PID: 1872)
      • chrome.exe (PID: 2012)
      • chrome.exe (PID: 2428)
      • chrome.exe (PID: 2576)
      • chrome.exe (PID: 3796)
      • chrome.exe (PID: 2828)
      • chrome.exe (PID: 2844)
      • esentutl.exe (PID: 1032)
      • esentutl.exe (PID: 876)
    • Application launched itself

      • chrome.exe (PID: 3692)
    • Reads the hosts file

      • chrome.exe (PID: 3692)
      • chrome.exe (PID: 3548)
    • Reads settings of System Certificates

      • chrome.exe (PID: 3548)
    • Reads the date of Windows installation

      • chrome.exe (PID: 3700)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

CobalStrike

(PID) Process(1032) esentutl.exe
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
(PID) Process(876) esentutl.exe
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
BeaconTypeHTTP
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
75
Monitored processes
32
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe safenotes.exe #COBALT esentutl.exe safenotes.exe no specs #COBALT esentutl.exe taskmgr.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
876esentutl.exeC:\Windows\system32\esentutl.exe
safenotes.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Extensible Storage Engine Utilities for Microsoft(R) Windows(R)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\esentutl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
CobalStrike
(PID) Process(876) esentutl.exe
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
(PID) Process(876) esentutl.exe
BeaconTypeHTTP
(PID) Process(876) esentutl.exe
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
1032esentutl.exeC:\Windows\system32\esentutl.exe
safenotes.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Extensible Storage Engine Utilities for Microsoft(R) Windows(R)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\esentutl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
CobalStrike
(PID) Process(1032) esentutl.exe
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
(PID) Process(1032) esentutl.exe
C2 (1)weather.decsal.com/service/weather/overview
BeaconTypeHTTPS
Port443
SleepTime63000
MaxGetSize1398439
Jitter30
PublicKey-----BEGIN PUBLIC KEY----- MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCeEefdtfw8mHFxKGPRAznFoiRj wjokrmfJ1k43jfM1acX58Ct13CMHgM/zk5ow4154dcXo/ZH+h14d3onTCSGzBcLw 8XSbIFQkhGCkxSub4GQt8zYCZZZqSNa3TfIu4uhpdxTSkJiLCdk04ZZkO/ARr24T YcM69oWvdzq7NcSWowIDAQAB -----END PUBLIC KEY-----
DNS_strategyround-robin
DNS_strategy_rotate_seconds-1
DNS_strategy_fail_x-1
DNS_strategy_fail_seconds-1
SpawnTo00000000000000000000000000000000
Spawnto_x86%windir%\syswow64\chkdsk.exe
Spawnto_x64%windir%\sysnative\chkdsk.exe
CryptoScheme0
HttpGet_VerbGET
HttpPost_VerbPOST
HttpPostChunk0
Watermark426352781
bStageCleanupTrue
bCFGCautionFalse
UserAgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.182 Safari/537.36
HttpPostUri/query/weather/location
Malleable_C2_InstructionsRemove 1 bytes at the end, Remove 329 bytes from the beginning, Base64 decode
HttpGet_Metadata
ConstHeaders (7)Content-Type: text/html;charset=UTF-8
Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Content-Encoding: gzip, deflate, br
Access-Control-Allow-Credentials: true
X-AS-SuppressSetCookie: 1
Connection: close
SessionId (2)base64url
parameter: apikey
HttpPost_Metadata
ConstHeaders (3)Cache-Control: private, max-age=0
Content-Type: application/json; charset=utf-8
Connection: close
SessionId (2)base64url
parameter: appid
Output (4)base64
prepend: {"data":{"geoip":{"geo":{"continent":"Europe","country":"Belgium","city":"Brussels","province":"","postal_code":null},"isp":{"isp":"Proximus Pickx","organization":"Proximus Pickx","autonomous_system_organization":"Proximus Pickx"},"ip_hash":null},"userIdentify":{"identity":{"identify":{"idc...
append: "}}}}}
print
bUsesCookies0000
Proxy_BehaviorUse IE settings
tcpFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
smbFrameHeader0004000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
KillDate0-0-0
bProcInject_StartRWXTrue
bProcInject_UseRWXTrue
bProcInject_MinAllocSize0
ProcInject_PrependAppend_x86000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_PrependAppend_x64000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000...
ProcInject_Stuba49f5445f01a9f3240eea9e46ee66c81
ProcInject_AllocationMethodVirtualAllocEx
1408"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1888 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1564"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --lang=en-US --instant-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1980 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1580"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\VsTelemetry.7z"C:\Program Files\WinRAR\WinRAR.exe
Explorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1688"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2472 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2184 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
1872"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=932 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
2012"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=24 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2208 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
2428"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1064,11591444428085578073,4960249371874873104,131072 --enable-features=PasswordImport --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3652 /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
86.0.4240.198
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\google\chrome\application\86.0.4240.198\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\shell32.dll
Total events
13 816
Read events
13 623
Write events
186
Delete events
7

Modification events

(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1580) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\VsTelemetry.7z
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1580) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
2
Suspicious files
30
Text files
80
Unknown types
4

Dropped files

PID
Process
Filename
Type
3692chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62B9AAAC-E6C.pma
MD5:
SHA256:
1580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1580.3106\VsTelemetry\Default\Default.manifest.jsontext
MD5:
SHA256:
1580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1580.3106\VsTelemetry\freshmp3binary
MD5:
SHA256:
1580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1580.3106\VsTelemetry\roboform.dllexecutable
MD5:
SHA256:
1580WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1580.3106\VsTelemetry\safenotes.exeexecutable
MD5:
SHA256:
3692chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\9a5ff628-5f73-4927-a197-198dfc3cc425.tmptext
MD5:
SHA256:
3692chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.oldtext
MD5:995C92837E4775CAFFE387D51ADBA520
SHA256:51247C3464FD988B72670002D01A57FBFF1348704D325DC8FF8817ED2459D0D9
3692chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old~RF11e4bf.TMPtext
MD5:936EB7280DA791E6DD28EF3A9B46D39C
SHA256:CBAF2AFD831B32F6D1C12337EE5D2F090D6AE1F4DCB40B08BEF49BF52AD9721F
3692chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.datbinary
MD5:9C016064A1F864C8140915D77CF3389A
SHA256:0E7265D4A8C16223538EDD8CD620B8820611C74538E420A88E333BE7F62AC787
3692chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF11e4ee.TMPtext
MD5:81F483F77EE490F35306A4F94DB2286B
SHA256:82434CE3C9D13F509EBEEBE3A7A1A1DE9AB4557629D9FC855761E0CFA45E8BCE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
45
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3548
chrome.exe
GET
138.201.229.154:80
http://weather.decsal.com/
DE
unknown
3548
chrome.exe
GET
74.125.111.8:80
http://r3---sn-5goeenez.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx?cms_redirect=yes&mh=e_&mip=196.196.52.6&mm=28&mn=sn-5goeenez&ms=nvh&mt=1656334583&mv=m&mvi=3&pl=24&rmhost=r1---sn-5goeenez.gvt1.com&shardbypass=sd&smhost=r1---sn-5goeen76.gvt1.com
US
suspicious
GET
173.194.150.220:80
http://r6---sn-5goeen7r.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3?cms_redirect=yes&mh=VX&mip=196.196.52.6&mm=28&mn=sn-5goeen7r&ms=nvh&mt=1656334583&mv=m&mvi=6&pl=24&rmhost=r3---sn-5goeen7r.gvt1.com&shardbypass=sd&smhost=r1---sn-5goeenez.gvt1.com
US
whitelisted
HEAD
302
142.251.37.110:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3
US
whitelisted
GET
302
142.251.37.110:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3
US
html
610 b
whitelisted
3548
chrome.exe
GET
302
142.251.37.110:80
http://redirector.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx
US
html
591 b
whitelisted
HEAD
200
173.194.150.220:80
http://r6---sn-5goeen7r.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3?cms_redirect=yes&mh=VX&mip=196.196.52.6&mm=28&mn=sn-5goeen7r&ms=nvh&mt=1656334583&mv=m&mvi=6&pl=24&rmhost=r3---sn-5goeen7r.gvt1.com&shardbypass=sd&smhost=r1---sn-5goeenez.gvt1.com
US
whitelisted
GET
302
142.251.37.110:80
http://redirector.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3
US
html
610 b
whitelisted
GET
206
173.194.150.220:80
http://r6---sn-5goeen7r.gvt1.com/edgedl/release2/chrome_component/ac5q25btpqhkjhcekqoslcldvuya_1.3.36.141/ihnlcenocehgdaegdmhbidjhnhdchfmm_1.3.36.141_win_ehzjmd5kjmert7jdgsrj4xqxj4.crx3?cms_redirect=yes&mh=VX&mip=196.196.52.6&mm=28&mn=sn-5goeen7r&ms=nvh&mt=1656334583&mv=m&mvi=6&pl=24&rmhost=r3---sn-5goeen7r.gvt1.com&shardbypass=sd&smhost=r1---sn-5goeenez.gvt1.com
US
binary
5.64 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3548
chrome.exe
142.250.185.234:443
fonts.googleapis.com
Google Inc.
US
whitelisted
3548
chrome.exe
138.201.229.154:80
weather.decsal.com
Hetzner Online GmbH
DE
unknown
3548
chrome.exe
142.251.37.109:443
accounts.google.com
Google Inc.
US
unknown
3548
chrome.exe
74.125.111.8:80
r3---sn-5goeenez.gvt1.com
Google Inc.
US
suspicious
173.194.150.220:80
r6---sn-5goeen7r.gvt1.com
Google Inc.
US
whitelisted
3548
chrome.exe
142.250.185.161:443
clients2.googleusercontent.com
Google Inc.
US
whitelisted
1032
esentutl.exe
138.201.229.154:443
weather.decsal.com
Hetzner Online GmbH
DE
unknown
876
esentutl.exe
138.201.229.154:443
weather.decsal.com
Hetzner Online GmbH
DE
unknown
3548
chrome.exe
142.250.185.163:443
clientservices.googleapis.com
Google Inc.
US
whitelisted
3548
chrome.exe
142.250.184.238:443
clients2.google.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
weather.decsal.com
  • 138.201.229.154
unknown
clientservices.googleapis.com
  • 142.250.185.163
whitelisted
clients2.google.com
  • 142.250.184.238
whitelisted
accounts.google.com
  • 142.251.37.109
shared
www.google.com
  • 142.250.186.100
malicious
clients2.googleusercontent.com
  • 142.250.185.161
whitelisted
fonts.googleapis.com
  • 142.250.185.234
whitelisted
www.gstatic.com
  • 142.251.36.67
whitelisted
apis.google.com
  • 216.58.212.142
whitelisted
fonts.gstatic.com
  • 216.58.212.131
whitelisted

Threats

No threats detected
No debug info