File name:

5620163803545600.zip

Full analysis: https://app.any.run/tasks/b186815a-5339-48e7-b828-16f9174ff1ae
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 18, 2019, 11:00:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
loader
rat
nanocore
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

A823C44B69A808A9265380768BB17AE2

SHA1:

55ADB2186788F426751FEAD59383D2CA3BC7DBBD

SHA256:

E76DC192366A1CD06480F7FFA102892E6F8CB08413C816BDA4C3102273DB4BAD

SSDEEP:

3072:3teQvds1KbkeN9o9IbGIc22LLRvWcWQx7f:3teQvy1Kbfsb22LlvSq7f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Requests a remote executable file from MS Office

      • EXCEL.EXE (PID: 972)
      • EXCEL.EXE (PID: 1400)
      • EXCEL.EXE (PID: 1748)
      • EXCEL.EXE (PID: 2600)
    • Executable content was dropped or overwritten

      • EXCEL.EXE (PID: 972)
    • Unusual execution from Microsoft Office

      • EXCEL.EXE (PID: 972)
      • EXCEL.EXE (PID: 1400)
      • EXCEL.EXE (PID: 1748)
      • EXCEL.EXE (PID: 2644)
      • EXCEL.EXE (PID: 2600)
    • Application was dropped or rewritten from another process

      • mpnotifys.exe (PID: 2860)
      • mpnotifys.exe (PID: 2560)
      • mpnotifys.exe (PID: 2956)
      • RegSvcs.exe (PID: 3800)
      • mpnotifys.exe (PID: 2452)
      • RegSvcs.exe (PID: 3780)
      • mpnotifys.exe (PID: 3540)
      • mpnotifys.exe (PID: 3268)
      • mpnotifys.exe (PID: 3736)
      • RegSvcs.exe (PID: 2072)
      • RegSvcs.exe (PID: 1096)
      • mpnotifys.exe (PID: 1576)
      • mpnotifys.exe (PID: 3988)
      • RegSvcs.exe (PID: 2520)
      • RegSvcs.exe (PID: 996)
      • RegSvcs.exe (PID: 1804)
      • RegSvcs.exe (PID: 280)
      • RegSvcs.exe (PID: 4080)
      • RegSvcs.exe (PID: 2284)
      • RegSvcs.exe (PID: 4060)
      • RegSvcs.exe (PID: 572)
      • RegSvcs.exe (PID: 1524)
      • RegSvcs.exe (PID: 3976)
      • RegSvcs.exe (PID: 3096)
      • RegSvcs.exe (PID: 3816)
      • mpnotifys.exe (PID: 3636)
      • RegSvcs.exe (PID: 3820)
      • RegSvcs.exe (PID: 2148)
      • RegSvcs.exe (PID: 1908)
      • RegSvcs.exe (PID: 3256)
      • RegSvcs.exe (PID: 2696)
      • RegSvcs.exe (PID: 4092)
      • RegSvcs.exe (PID: 3624)
      • RegSvcs.exe (PID: 2408)
      • RegSvcs.exe (PID: 3628)
      • RegSvcs.exe (PID: 1540)
      • RegSvcs.exe (PID: 4088)
      • RegSvcs.exe (PID: 3952)
      • RegSvcs.exe (PID: 1772)
      • RegSvcs.exe (PID: 2488)
      • RegSvcs.exe (PID: 3532)
      • RegSvcs.exe (PID: 3072)
      • RegSvcs.exe (PID: 3080)
      • RegSvcs.exe (PID: 2352)
      • RegSvcs.exe (PID: 3284)
      • RegSvcs.exe (PID: 3764)
      • RegSvcs.exe (PID: 2220)
      • RegSvcs.exe (PID: 3700)
      • RegSvcs.exe (PID: 3932)
      • RegSvcs.exe (PID: 3796)
      • RegSvcs.exe (PID: 2636)
      • RegSvcs.exe (PID: 3648)
      • RegSvcs.exe (PID: 3352)
      • RegSvcs.exe (PID: 3652)
      • RegSvcs.exe (PID: 1160)
      • RegSvcs.exe (PID: 3336)
      • RegSvcs.exe (PID: 2172)
      • RegSvcs.exe (PID: 3120)
      • RegSvcs.exe (PID: 2980)
      • RegSvcs.exe (PID: 1356)
      • RegSvcs.exe (PID: 1684)
      • RegSvcs.exe (PID: 2504)
      • RegSvcs.exe (PID: 1816)
      • RegSvcs.exe (PID: 2200)
      • RegSvcs.exe (PID: 1316)
      • RegSvcs.exe (PID: 3004)
      • RegSvcs.exe (PID: 340)
    • Known privilege escalation attack

      • mpnotifys.exe (PID: 2860)
      • mpnotifys.exe (PID: 2956)
      • mpnotifys.exe (PID: 3540)
      • mpnotifys.exe (PID: 3736)
      • mpnotifys.exe (PID: 3988)
    • Changes the autorun value in the registry

      • mpnotifys.exe (PID: 2560)
      • mpnotifys.exe (PID: 2452)
      • RegSvcs.exe (PID: 3800)
      • mpnotifys.exe (PID: 3268)
      • mpnotifys.exe (PID: 1576)
      • mpnotifys.exe (PID: 3636)
    • NanoCore was detected

      • RegSvcs.exe (PID: 3800)
  • SUSPICIOUS

    • Executed via COM

      • EXCEL.EXE (PID: 972)
      • EXCEL.EXE (PID: 1400)
      • EXCEL.EXE (PID: 1748)
      • EXCEL.EXE (PID: 2644)
      • EXCEL.EXE (PID: 2600)
      • excelcnv.exe (PID: 3468)
    • Executable content was dropped or overwritten

      • mpnotifys.exe (PID: 2560)
      • RegSvcs.exe (PID: 3800)
    • Modifies the open verb of a shell class

      • mpnotifys.exe (PID: 2860)
      • mpnotifys.exe (PID: 3540)
      • mpnotifys.exe (PID: 2956)
      • mpnotifys.exe (PID: 3736)
      • mpnotifys.exe (PID: 3988)
    • Suspicious files were dropped or overwritten

      • mpnotifys.exe (PID: 2560)
    • Creates files in the user directory

      • RegSvcs.exe (PID: 3800)
    • Creates files in the program directory

      • RegSvcs.exe (PID: 3800)
  • INFO

    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3228)
      • EXCEL.EXE (PID: 972)
      • EXCEL.EXE (PID: 1400)
      • EXCEL.EXE (PID: 1748)
      • EXCEL.EXE (PID: 2644)
      • EXCEL.EXE (PID: 2600)
      • excelcnv.exe (PID: 3468)
    • Creates files in the user directory

      • WINWORD.EXE (PID: 3228)
    • Manual execution by user

      • WINWORD.EXE (PID: 3228)
      • WinRAR.exe (PID: 4000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Unknown (99)
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x00000000
ZipCompressedSize: 132034
ZipUncompressedSize: 132151
ZipFileName: 93ec9f1693fa9d85eaff76bcc01946934e008e73c9f6af474ff9f0378e7ba367
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
86
Malicious processes
21
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs winrar.exe no specs winword.exe no specs excel.exe mpnotifys.exe no specs excel.exe eventvwr.exe no specs eventvwr.exe mpnotifys.exe mpnotifys.exe no specs #NANOCORE regsvcs.exe excel.exe eventvwr.exe no specs eventvwr.exe mpnotifys.exe regsvcs.exe no specs mpnotifys.exe no specs excel.exe no specs eventvwr.exe no specs eventvwr.exe mpnotifys.exe mpnotifys.exe no specs excel.exe regsvcs.exe no specs eventvwr.exe no specs eventvwr.exe mpnotifys.exe regsvcs.exe no specs mpnotifys.exe no specs excelcnv.exe no specs eventvwr.exe no specs eventvwr.exe mpnotifys.exe regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
324"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
mpnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
340"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
572"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
972"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" -EmbeddingC:\Program Files\Microsoft Office\Office14\EXCEL.EXE
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Exit code:
0
Version:
14.0.6024.1000
Modules
Images
c:\program files\microsoft office\office14\excel.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
996"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1096"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1160"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1316"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1356"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exempnotifys.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.7.3062.0 built by: NET472REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
5 848
Read events
5 011
Write events
801
Delete events
36

Modification events

(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3696) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\5620163803545600.zip
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(3696) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
Executable files
4
Suspicious files
2
Text files
4
Unknown types
5

Dropped files

PID
Process
Filename
Type
3228WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR406F.tmp.cvr
MD5:
SHA256:
972EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR4A43.tmp.cvr
MD5:
SHA256:
1400EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR5B88.tmp.cvr
MD5:
SHA256:
1748EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR6397.tmp.cvr
MD5:
SHA256:
2644EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR6C22.tmp.cvr
MD5:
SHA256:
2600EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR73C4.tmp.cvr
MD5:
SHA256:
3468excelcnv.exeC:\Users\admin\AppData\Local\Temp\CVR7CFB.tmp.cvr
MD5:
SHA256:
3468excelcnv.exeC:\Users\admin\AppData\Local\Temp\~DF538817D06DE56AD7.TMP
MD5:
SHA256:
3228WINWORD.EXEC:\Users\admin\AppData\Local\Temp\~DF9026972C1BF32CA4.TMP
MD5:
SHA256:
3468excelcnv.exeC:\Users\admin\AppData\Local\Temp\~DF92CE712B22F8654B.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
28
DNS requests
13
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1400
EXCEL.EXE
GET
304
194.59.164.40:80
http://u700222964.hostingerapp.com/mpnotifys.exe
unknown
suspicious
1748
EXCEL.EXE
GET
304
194.59.164.40:80
http://u700222964.hostingerapp.com/mpnotifys.exe
unknown
suspicious
972
EXCEL.EXE
GET
200
194.59.164.40:80
http://u700222964.hostingerapp.com/mpnotifys.exe
unknown
executable
1.23 Mb
suspicious
2600
EXCEL.EXE
GET
304
194.59.164.40:80
http://u700222964.hostingerapp.com/mpnotifys.exe
unknown
suspicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1400
EXCEL.EXE
194.59.164.40:80
u700222964.hostingerapp.com
suspicious
972
EXCEL.EXE
194.59.164.40:80
u700222964.hostingerapp.com
suspicious
1748
EXCEL.EXE
194.59.164.40:80
u700222964.hostingerapp.com
suspicious
2600
EXCEL.EXE
194.59.164.40:80
u700222964.hostingerapp.com
suspicious
3800
RegSvcs.exe
185.247.228.17:47581
etoiilefiiilante.duckdns.org
malicious
8.8.8.8:53
Google Inc.
US
malicious
3800
RegSvcs.exe
8.8.8.8:53
Google Inc.
US
malicious

DNS requests

Domain
IP
Reputation
u700222964.hostingerapp.com
  • 194.59.164.40
suspicious
etoiilefiiilante.duckdns.org
  • 185.247.228.17
malicious

Threats

PID
Process
Class
Message
972
EXCEL.EXE
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
3800
RegSvcs.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.duckdns. Domain
No debug info