| File name: | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil |
| Full analysis: | https://app.any.run/tasks/5435c04d-5de6-4380-9ebe-aa23e1f22540 |
| Verdict: | Malicious activity |
| Analysis date: | May 19, 2025, 08:29:07 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections |
| MD5: | 14FBEDED3CAA1A5605E8C38F4B2797C6 |
| SHA1: | EC05441D83540FED97F34DC59780CA1AEE53734A |
| SHA256: | DBD6A6861C9ED2887648937B746532BE093A20915F3B34ABEF588A7EC7C64613 |
| SSDEEP: | 98304:3/NlZ50ywanr0y+ck0u+QG3g1SHAaN0/xjGS6w6KxLQyUg5sAO4Xm6NevZMKKVju:r8h4Co |
| .exe | | | Win32 EXE PECompact compressed (generic) (24) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (3.7) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Generic Win/DOS Executable (1.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:01:17 07:12:12+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 8433664 |
| InitializedDataSize: | 5752320 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x451f3f |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.45.1.17 |
| ProductVersionNumber: | 1.45.1.17 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | www.BitComet.com |
| FileDescription: | BitComet - a BitTorrent Client |
| FileVersion: | 1.45 |
| InternalName: | BitComet.exe |
| LegalCopyright: | Copyright(C) 2003-2016 All Rights Reserved. |
| ProductName: | BitComet |
| ProductVersion: | 1.45 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 472 | "C:\WINDOWS\System32\OpenWith.exe" C:\Users\admin\Desktop\untitled_attachment_0 | C:\Windows\System32\OpenWith.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Pick an app Exit code: 2147943623 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 920 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=3680 --field-trial-handle=2440,i,14123274991439134233,14774706477078454781,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1132 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2768 --field-trial-handle=2440,i,14123274991439134233,14774706477078454781,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2340 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=2584 --field-trial-handle=2440,i,14123274991439134233,14774706477078454781,262144 --variations-seed-version /prefetch:3 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2516 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16514043 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | Acrobat.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Version: 23.1.20093.0 Modules
| |||||||||||||||
| 2644 | "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=2904 --field-trial-handle=1616,i,6948450287174761107,5934598072214693527,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1 | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe | — | AcroCEF.exe | |||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: LOW Description: Adobe AcroCEF Version: 23.1.20093.0 Modules
| |||||||||||||||
| 2904 | "C:\Users\admin\Desktop\2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe" | C:\Users\admin\Desktop\2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | explorer.exe | ||||||||||||
User: admin Company: www.BitComet.com Integrity Level: MEDIUM Description: BitComet - a BitTorrent Client Version: 1.45 Modules
| |||||||||||||||
| 3020 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=1372 --field-trial-handle=2440,i,14123274991439134233,14774706477078454781,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 3268 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6772 --field-trial-handle=2440,i,14123274991439134233,14774706477078454781,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\BitComet\BitComet |
| Operation: | write | Name: | CaptureIEDownload |
Value: 1 | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\BitComet\BitComet |
| Operation: | write | Name: | IEMoniterFileExt |
Value: .zip;.rar;.iso;.exe;.asf;.avi;.mp3;.mpg;.rm;.rmvb;.wmv;.wma;.msi | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet |
| Operation: | write | Name: | contexts |
Value: 34 | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet |
| Operation: | write | Name: | BitCometCreated |
Value: 1 | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet |
| Operation: | write | Name: | MenuID |
Value: ID_DOWNLOAD_LINK | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&D&ownload all with BitComet |
| Operation: | write | Name: | contexts |
Value: 243 | |||
| (PID) Process: | (2904) 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&D&ownload all with BitComet |
| Operation: | write | Name: | BitCometCreated |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Temp\conres.dll | executable | |
MD5:7574CF2C64F35161AB1292E2F532AABF | SHA256:DE055A89DE246E629A8694BDE18AF2B1605E4B9B493C7E4AEF669DD67ACF5085 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\wbkDBEC.tmp | html | |
MD5:02368780C159221528A906101BBF7A85 | SHA256:CB0EC4B07C8EA3719D51B4AAF126DAB33D0EBC516F09AF9002133B1BD78DB585 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Temp\A1D26E2\D4594CCB58.tmp | executable | |
MD5:3A081EF04B92D90D621E9E7F1288A412 | SHA256:7828AD15CEDFB8431EC377730F16CAF4CB13E4272ED9C91860423B9AD7F77A9B | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\login_17.gif | image | |
MD5:786A136A95B93D4B7B9298D4518200EF | SHA256:0F01DB9B6697689B0E3D5EEF62F98F5D50708E5B1DA7AA3943A1B65026BAB604 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\private-photo-safe[1].htm | html | |
MD5:351AE892E317DFF66D97D14AE817BCAF | SHA256:B115559FB0DCDD37E508F555ACD90D063108AF9AC2BB100FAB64AB61524CFBE1 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Roaming\BitComet\fav\passport_info_en_US.mht | binary | |
MD5:1522A605F1EF6AB932AA62825D55A42D | SHA256:7874727953375A578EC58B9B02A56C4C1D6A191CCF38B4B1F22B6F8F9671E64C | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7LFXWVHVYCC6R9JFTDFF.temp | binary | |
MD5:43AE50921DD3891F73B534BB06453AE3 | SHA256:A210BAF1553AA73FE3FC4E139962E47CADDAD5E96A0CDE5C6648B3192A6B2437 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\login_7.gif | image | |
MD5:D3D7E9F65FB43D0496AD19E4CB275B7A | SHA256:50207EFA8ACEC9A590F7B9D8727DDB586DE9E770DA13D092DA38D1E33EE73CB0 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Roaming\BitComet\fav\passport_login_zh_CN.mht | binary | |
MD5:6E99A0B0A9C54E9653B3A467D43C190D | SHA256:013815C6EBF911C7B4B5645659685F36BBD1BECE26DD701C2A33BB4F3AF5EC63 | |||
| 2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\login_11.gif | image | |
MD5:E306571097798B916E1C9139288D9BE7 | SHA256:971F7CF646D424C18F50C31B1EA41C2EE372A1D80E7F1A7874241C366FCDBD8F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 200 | 138.199.168.42:80 | http://inside.bitcomet.com/start/en_us/1.45/ | unknown | — | — | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 200 | 138.199.168.42:80 | http://update.bitcomet.com/client/bitcomet/?ver=1.45&intl=en_us&osintl=en_us&cid=5ff00f6c9607d73131b97d4810f09606&btcnt=0&httpcnt=0&p=x86 | unknown | — | — | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 200 | 138.199.168.42:80 | http://update.bitcomet.com/client/bitcomet/fav/v1.05-v1.40/fav_en_us.xml | unknown | — | — | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 200 | 138.199.168.42:80 | http://update.bitcomet.com/client/bitcomet/passport/v0.89-v1.52/passport_info_en_us.mht | unknown | — | — | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 200 | 138.199.168.42:80 | http://update.bitcomet.com/client/bitcomet/passport/v0.89-v1.52/passport_login_en_us.mht | unknown | — | — | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 404 | 34.89.91.10:80 | http://tracker.p2pcache.org/issupported | unknown | — | — | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | 72.14.178.174:80 | www.aieov.com | Linode, LLC | US | malicious |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | 67.215.246.10:6881 | router.bittorrent.com | — | — | whitelisted |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | 138.199.168.42:80 | inside.bitcomet.com | — | DE | suspicious |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | 142.250.185.72:443 | www.googletagmanager.com | GOOGLE | US | whitelisted |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | 95.111.225.211:443 | apphit.com | Contabo GmbH | DE | unknown |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | 34.89.91.10:80 | tracker.p2pcache.org | GOOGLE-CLOUD-PLATFORM | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
5isohu.com |
| whitelisted |
www.aieov.com |
| malicious |
router.bittorrent.com |
| whitelisted |
router.bitcomet.net |
| unknown |
inside.bitcomet.com |
| unknown |
www.googletagmanager.com |
| whitelisted |
apphit.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Malware Command and Control Activity Detected | MALWARE [ANY.RUN] Possible Floxif CnC Communication |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Misc activity | INFO [ANY.RUN] P2P BitTorrent Protocol |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Malware Command and Control Activity Detected | MALWARE [ANY.RUN] Possible Floxif CnC Communication |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Potential Corporate Privacy Violation | ET INFO Unsupported/Fake Windows NT Version 5.0 |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Potential Corporate Privacy Violation | ET INFO Unsupported/Fake Windows NT Version 5.0 |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Malware Command and Control Activity Detected | MALWARE [ANY.RUN] Possible Floxif CnC Communication |
2340 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2340 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2904 | 2025-05-19_14fbeded3caa1a5605e8c38f4b2797c6_black-basta_darkgate_elex_floxif_luca-stealer_poet-rat_remcos_revil.exe | Malware Command and Control Activity Detected | MALWARE [ANY.RUN] Possible Floxif CnC Communication |