File name:

6568B821F5238D72D6AD4BEA0CC8E78B.exe

Full analysis: https://app.any.run/tasks/1379f2c3-0b00-47ba-b646-a6cbc6466559
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: September 26, 2023, 13:17:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
dcrat
rat
backdoor
remote
stealer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

6568B821F5238D72D6AD4BEA0CC8E78B

SHA1:

0194E4D37D26DCF4A9D1A40030C0F4DA3DFD11AF

SHA256:

FD9398B7FCF235842AC5C82405E5B05077456C0011AA4E9B19B0E8BE6B172F91

SSDEEP:

24576:1RuqB2C+v6LHivwR5aTFG8ctmbqDA990ntXXxiDiWC7G:zuqBJ3/yiWYG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • DCRAT detected by memory dumps

      • 6568B821F5238D72D6AD4BEA0CC8E78B.exe (PID: 3016)
      • AppLaunch.exe (PID: 2528)
    • DCRAT was detected

      • AppLaunch.exe (PID: 2528)
    • Connects to the CnC server

      • AppLaunch.exe (PID: 2528)
    • Steals credentials from Web Browsers

      • AppLaunch.exe (PID: 2528)
    • Steals credentials

      • AppLaunch.exe (PID: 2528)
    • Actions looks like stealing of personal data

      • AppLaunch.exe (PID: 2528)
  • SUSPICIOUS

    • Reads the Internet Settings

      • AppLaunch.exe (PID: 2528)
    • Reads browser cookies

      • AppLaunch.exe (PID: 2528)
    • Probably delay the execution using 'w32tm.exe'

      • w32tm.exe (PID: 2840)
      • cmd.exe (PID: 3312)
    • Starts CMD.EXE for commands execution

      • AppLaunch.exe (PID: 2528)
    • Executing commands from a ".bat" file

      • AppLaunch.exe (PID: 2528)
  • INFO

    • Reads the machine GUID from the registry

      • AppLaunch.exe (PID: 2528)
    • Reads the computer name

      • AppLaunch.exe (PID: 2528)
    • Checks supported languages

      • 6568B821F5238D72D6AD4BEA0CC8E78B.exe (PID: 3016)
      • AppLaunch.exe (PID: 2528)
    • Reads Environment values

      • AppLaunch.exe (PID: 2528)
    • Create files in a temporary directory

      • AppLaunch.exe (PID: 2528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

DcRat

(PID) Process(2528) AppLaunch.exe
C2 (1)http://232161cm.nyashtyan.top/@0J3bwBXdzh2chlnb
Options
TagЛёха
MutexDCR_MUTEX-0SFp0btymkLw3APUPUce
savebrowsersdatatosinglefilefalse
ignorepartiallyemptydatafalse
cookiestrue
passwordstrue
formstrue
cctrue
historyfalse
telegramtrue
steamtrue
discordtrue
filezillatrue
screenshottrue
clipboardtrue
sysinfotrue
searchpath%UsersFolder% - Fast
Targetru
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

Subsystem: Windows command line
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x99a4
UninitializedDataSize: -
InitializedDataSize: 848384
CodeSize: 154624
LinkerVersion: 14.34
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2023:09:15 18:54:18+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #DCRAT 6568b821f5238d72d6ad4bea0cc8e78b.exe no specs #DCRAT applaunch.exe cmd.exe no specs w32tm.exe no specs w32tm.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2148w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2C:\Windows\System32\w32tm.exew32tm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\w32tm.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2528"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
6568B821F5238D72D6AD4BEA0CC8E78B.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Exit code:
0
Version:
4.7.2558.0 built by: NET471REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
DcRat
(PID) Process(2528) AppLaunch.exe
C2 (1)http://232161cm.nyashtyan.top/@0J3bwBXdzh2chlnb
Options
TagЛёха
MutexDCR_MUTEX-0SFp0btymkLw3APUPUce
savebrowsersdatatosinglefilefalse
ignorepartiallyemptydatafalse
cookiestrue
passwordstrue
formstrue
cctrue
historyfalse
telegramtrue
steamtrue
discordtrue
filezillatrue
screenshottrue
clipboardtrue
sysinfotrue
searchpath%UsersFolder% - Fast
Targetru
2840w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 C:\Windows\SysWOW64\w32tm.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Time Service Diagnostic Tool
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\w32tm.exe
c:\windows\syswow64\ntdll.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3016"C:\Users\admin\AppData\Local\Temp\6568B821F5238D72D6AD4BEA0CC8E78B.exe" C:\Users\admin\AppData\Local\Temp\6568B821F5238D72D6AD4BEA0CC8E78B.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\6568b821f5238d72d6ad4bea0cc8e78b.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3312C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\xcTtvCCEHS.bat" "C:\Windows\SysWOW64\cmd.exeAppLaunch.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\wow64.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\system32\wow64cpu.dll
Total events
1 527
Read events
1 519
Write events
8
Delete events
0

Modification events

(PID) Process:(2528) AppLaunch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2528) AppLaunch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2528) AppLaunch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2528) AppLaunch.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
20
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\7IsMUKCWrzsqlite
MD5:C9FF7748D8FCEF4CF84A5501E996A641
SHA256:4D3F3194CB1133437AA69BB880C8CBB55DDF06FF61A88CA6C3F1BBFBFD35D988
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\tyk4mzX7rhbinary
MD5:1AA08FF2105515DE3602F503E87DFF1A
SHA256:D7446E2F307027C9BDA2A92D1DF1C13C376581372F6AE8708F4D5BACCB2E6813
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\0MwEg3U0LQbinary
MD5:C9FF7748D8FCEF4CF84A5501E996A641
SHA256:4D3F3194CB1133437AA69BB880C8CBB55DDF06FF61A88CA6C3F1BBFBFD35D988
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\tpoBlvKnjAtext
MD5:F7F3F240408F04D0033FE5D269334FE4
SHA256:E8983A8E1CBE2D82E6165668A9663ED7871793B594DA368F07BF5E80C2070F8B
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\ZKg81RrBnwbinary
MD5:AE4F400E858ADD6ECF3D2CBBF0E55F9B
SHA256:73C170558B62DD23D381F4AA9BD7B4D7C9613671C5D08D286CFBEB02E6BE300A
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\MIJM4QIAGfbinary
MD5:CEEDD8AE976601F9C9365EBEC5CFD997
SHA256:0B1A7E634F5B8A88211685983E83E7739359ACE5F26CA99746F46BB81507A42E
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\Bsrndcvijabinary
MD5:A37C32F6C48659B21D268A25398F1A5A
SHA256:D4EEA4FD10B2D27CC0BCF17DD0B4A905E73C26721C51D03A809A33A1AF2CE3B2
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\zFpDCSEPm0binary
MD5:CEB39527E05115BBE0227EA14D897374
SHA256:D3406398F5A7D00D94E1F36065ACC5C63DBF27FB4026D75FB09129DDD05C2D20
2528AppLaunch.exeC:\Users\admin\AppData\Local\Temp\BCTEmhs40Ebinary
MD5:0A149D1DB8612AE149B4B3A03204D29F
SHA256:6984F4A4A4CBB11E3B6057314EC765D5210521478FF411F883FC5EC2F31D6768
2528AppLaunch.exeC:\Users\Public\nltxvmn2.default\key4.dbbinary
MD5:2D88BB69E75C2D609BA79F7353DAECC1
SHA256:263ECB9445A828CEC98F7C19B2FF3B4DFAD99EE58C5E394E5F6778FD441415F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
7
DNS requests
1
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&9d6e5ec8163599a3d65acf9be9ad08a4=0VfiIiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiIkNmZ5IjZjNDZ0QmN5QzYkNjYzQ2MjJmZmlzNzETNwkjYlBjMkFWYyIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIjJDNkhDZ2EGNlRmZykjM4UWOmVTOjRGNhJTOlRzY4UWZ2MTZmVGN5IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=0VfiIiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZisHL9JSOWp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=d1nIiojIlNWN4YjM2MDZhV2YhhTNhljNhlTM2ATZklDZjJjNmJmIsICMlJDNlVTN4UjM1ADMzEmYycjZ0UWY0MWNmBDZwMGM0QjY0YGNlNzNiojIkNjN1IzMyADZyEDMwUTZiFzNjNjY3MTN5IWO4UmN4AjIsICZkJ2MlJDN3IWN0M2MkZWMxkTNmJGN1QmM3gTM0IDMxYTZ4QjM2MWNiojIzQTYyIjM0ATYyUjNxgzM5QWO4kTNmN2Y1I2MjFmM2UmI7xSfiADWmlGOqlkNJNUT0E1VOtmUH1EeBpWTxcGVPxmTXl1akpmW3V1RPxmRX1EaOpnT6lFRP1mWE5UNFRkWzEEVNl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&090c97bad78efc0fcdf01bcacd4efd48=d1nIw4WS1UkeNdXTqx0d0MkTygnRYJnSzI2MWdlYopkbSNGeGZlR1sGTwolMipXOtNmasdFVjhXMjNTOHpVdsJjVjhHbPRkSp9UandEZoJEbJNXSpJ2M50mYyVzVWl2bql0bShVWRJVbjZnTyMGcStWSzlUaJZTSDFGMGdUV0ZUbj5mVHJGbSxWSzlUaJZTS5N2dChVU0Z0VaBjTsl0cJlmYzkTbiJXNXZVavpWSFx2ajxmTYZFdGdlWw4EbJN3dHJWM102TplEWapnVWJGaWdEZUp0QMNHeXRWdwpWSuVzVZ1UMXlFbSNTVpdXaJRnRXpFMONDTwlFRPRDaDlkeWdkYwp1RJRnRtNmb502Y3lTaPpmSp9UandEZoJkVihmVHRGVKNETptWeiBnUXRmQClnT1MWeRJkQ5FGbShkYoZVbV9WQpJmSCNlW1x2RUVHesN2Y5cVYrZFWRd2YU9kbNVVUnN3VaBDeXlFbKZ0SnVVbiZHaHNmdKNTWwFzaJZTS5NGb1IjYvJ0MilnTXFmTKNETplUaPlWTYJGaO1WWsRGbJNXSpJ2YKhEW4tmVR1kQxUlSSVEWjVzQYNGeGhVavpWS6VzVaxmSzkFVKNETpRjMkZXNyEWdWxWS2k0QVpUNVFVTKNETplEMSdWUqlkNJNFVCpEbJNXSpJ2M50mYyVzVWl2bql0c4dVWzYVbjBnWrl0cJlmYzkTbiJXNXZVavpWS6ZlbjBnWYFGM1cVUpdXaJhXQTx0ZBNEVNZVRSl2bqlUd5cVY6pEWadlTxQlSKtWSzlUeVBFbrF1ZwclWw4EWlRlQDR2cWhVWtZ1RSl2bqlEbxcVWP5UMUpkSrl0cJlmYzkTbiJXNXZVavpWSFxWRalnRyIWaKhlWvJ1Mi5kSDxUa0IDZ2VjMhVnVslkNJl2YspEWkBjTXlVbW5mYoFTRalnRyIWaKhlWvJ1Mi5kSDxUa0IDZ2VjMhVnVslkNJNlW0ZUbUtmSYlldK12Ysh2RkZXMrl0cJNVT5Z1RiNXOtNGM1IjYElzVatGbtZVavpWSrxWVapGbtRGbSVlVRR2aJNXSTFld0sWS2k0UaBjRtV1bOhlW5p1VaNFaYllTWZUVIp0QMlWRww0TKl2TpRjMiBnUINGcKNTW6Z1RSxmUyImT5clWrxWbWZlQxIVa3lWSClTaUl2bqlUNKNjY0Z1VUZnVHpFcaZlVRR2aJNXSTFld0sWS2kUajZnTzMGbOJjY5JUMixmUXF2VWZUVIp0QMlWVqlkNJNlW5ZFSkpmVHRGcoJTW5ZEMixmUXF2VWZUVIp0QMlWSYpFMChVWrZURJpnTXF2bChVW5RWRJJEZrZ1ZR12YoJVbihmUzUVavpWSsFzVZ9kVGVFSKNETp1EVSJTQU50dBRUTHp1aRdkSF90MBpWS2k0QapkSzImeOhlWqlTbjFlVGVFRKNETpFEVWFlTrlkNJNkWKZlMZBnWYpVRWZUVEp0QMNzZU5kevpWS1lzVhpHbtRGbKZlVR50aJNXSpVWSxUUSwsGRNpXSp9UaRdlWsJ0MVJnTyI2cOVEZ1ZVbjlnVzElVCFTUpdXaJJUOpRVavpWSrZ1VadnTxEma5ckYEh3VZVnSYpFMohlUWJUMRl2dpl0QsJzUnFkaJZTSTplNsJTVshmMZhmTw0UTWZUVEp0QMlWRww0TKl2TpVVblBnTWp1bOdVWEpERUZlQxEVa3lWS1kUaPlWVtNWMSNTWsJFWh9mTtNmQWZUVEp0QMBzbqlkeKNjY65EWapWOtNWU4dVWqxmMaZHeVZVUOtWSzFlaPlWTYpVe5ITUWJUMRl2dplkeBlnW1x2RjdnVHRGVCNkT4F0QixmUyImTClmTntGSiBXMXl1RCNkTyEVVUJkSp9Ua0IjYwJFSjBnSzkleWdkUWJUMRl2dplkNoBjU3NmaMlXQDF1ZVZUVEJ0QNdXUq5EdVRVYnt2UUVFaTpVe5ITUntWaV92dXpFM1c1Up9maJxWMXl1TWZUVEp0QMlWRqx0M0MkTp9maJVXOXFmeKhlWXRXbjZHZYpFdG12YHpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiIkNmZ5IjZjNDZ0QmN5QzYkNjYzQ2MjJmZmlzNzETNwkjYlBjMkFWYyIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?bLJ8vjAqIS0JN=OYnk&e71f21b0805ee5c005f6f2b09ec77740=770962078e1bcbd114dfa096ab91b8a8&d5482f6c998a081ff9fb48bcf2314cee=QN2kTZ3YzY4UWY4kzNyETMmRDNldTZ0UjNzMGZzkTZ1YTZxMmYiVDM&bLJ8vjAqIS0JN=OYnk
unknown
text
2.07 Kb
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=d1nIiojIlNWN4YjM2MDZhV2YhhTNhljNhlTM2ATZklDZjJjNmJmIsICMlJDNlVTN4UjM1ADMzEmYycjZ0UWY0MWNmBDZwMGM0QjY0YGNlNzNiojIkNjN1IzMyADZyEDMwUTZiFzNjNjY3MTN5IWO4UmN4AjIsICZkJ2MlJDN3IWN0M2MkZWMxkTNmJGN1QmM3gTM0IDMxYTZ4QjM2MWNiojIzQTYyIjM0ATYyUjNxgzM5QWO4kTNmN2Y1I2MjFmM2UmI7xSfiADWmlGOqlkNJNUT0E1VOtmUH1EeBpWTxcGVPxmTXl1akpmW3V1RPxmRX1EaOpnT6lFRP1mWE5UNFRkWzEEVNl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&f880b0002f0d31bf8f02966baf29f836=d1nIwUmM0UWN1gTNyUDMwMTYiJzNmRTZhRzY1YGMkBzYwQDNiRjZ0U2M3IiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W&9d6e5ec8163599a3d65acf9be9ad08a4=d1nIiojIlNWN4YjM2MDZhV2YhhTNhljNhlTM2ATZklDZjJjNmJmIsICMlJDNlVTN4UjM1ADMzEmYycjZ0UWY0MWNmBDZwMGM0QjY0YGNlNzNiojIkNjN1IzMyADZyEDMwUTZiFzNjNjY3MTN5IWO4UmN4AjIsICZkJ2MlJDN3IWN0M2MkZWMxkTNmJGN1QmM3gTM0IDMxYTZ4QjM2MWNiojIzQTYyIjM0ATYyUjNxgzM5QWO4kTNmN2Y1I2MjFmM2UmI7xSfiADWmlGOqlkNJNUT0E1VOtmUH1EeBpWTxcGVPxmTXl1akpmW3V1RPxmRX1EaOpnT6lFRP1mWE5UNFRkWzEEVNl2cu9UaFdEZoJVRkRjVtl0cVp2TpFFWkZnVXJGcSZ0YsZ1RiRlSDxUaV1GZwJ1MZJkSp9UaNhFZwY0RkRFbIRGcahVYw40VRl2dplUavpWSzkzRaVHbyYVVOVVUpdXaJ9kSp9UawcVWqp0VahlTYFWa3lWSapUaPlWVtJmdod0Y2p0MZBXMwMGcKNETptWeNd2YtJGcCh0YsJ1MVdWUU10Z3dlWrlzVUdWWElUN4dVY0ZUbSdWUq5URxUVUvFUallEZF10M0kWTnFURJZlQxE1ZBRUTwkFVMFzaHlEcwUkVvVVbjZnTFlEcJZ0SzZ1RkVHbrlkNJNlW0ZUbUZlQxEVa3lWSwVEMM9EaDlUeWdEZ3Z0RaJkQ5NmasdUY3ZUbjhkQTFFSaZUSrpEWZtWNXlFMOxWS2k0UaRnRtRlVCFjUpdXaJ9kSp9Ua0cVY0J1VRpHbtl0cJN0cRhVWwI1R50WUMl2TpNWVRVlSDxUaRhVYDJ0QOJTQDJGa1IjYw50MjxmWyIWeCZUSzEUejNTOHpVdsJjVp9maJlnVtZVdsJjVpd3UmlGNXF2cKhlWDlzUadXOtNWMWtWS2k0UaVXOtVGbxcVYwo0QMlWQE10dBRUT3lUaPl2dXlFMONjY3p0QMl2auJGax02YsRWRJRXQDpFbs1mWw50VadnTIlEM50GVp9maJ5mSzIWa3lWS6dmeOdHNT1Ee3lnT5VFROV3aE5UavpWSqlzRil2dplkRStWS2k0UllnUuJWM5ITWpdXaJhGbtNGaahVWDpUaPlGNyIGckdlW5p0QMl2YtNGbKdlYspEWk9kSp9UarhEZw5UbJNXST5Ue0kmT6RzQNpHNp1EeJpWS2k0QjBnS5VmNJlnYtVzVTdHbrl0cJlmYwFzRahmSp9UaVdlYoVzajxmTYZVa3lWSEJkVMNlVwUlVKl2TpV1VihWNwEVUKNETplkeNVXVqxEMJl2TplEWadlSYplMKhlWUp0QMlWT5FVavpWSsJEWlVlSYplMKhlWUpUelJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI4YjM4UWMiZzNkBzMmZzM2EWY2MDN4ITNjV2N4QDM5gDNlNDOxQzYzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
GET
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ&9d6e5ec8163599a3d65acf9be9ad08a4=QX9JSUNJiOiU2Y1gjNyYzMkFWZjFGO1EWO2EWOxYDMlRWOkNmM2YmYiwiI2YjZ4czNwEDOmRTYzYGNxUDO4YWYmZjZzIWZ0UTZxQTYiNjYiBDZzIiOiQ2M2UjMzIDMkJTMwATNlJWM3M2MidzM1kjY5gTZ2gDMiwiIkRmYzUmM0cjY1QzYzQmZxETO1YmY0UDZycDOxQjMwEjNlhDNyYzY1IiOiMDNhJjMyQDMhJTN2EDOzkDZ5gTO1Y2YjVjYzMWYyYTZis3W
unknown
text
104 b
unknown
2528
AppLaunch.exe
POST
200
91.103.252.23:80
http://232161cm.nyashtyan.top/nyashsupport.php?XbCBSR8yH2mzUNXYzm6RL6AS9OcNZh=POGTQits&9tVsuCZCGlp4pbuabuCDyuYjoXkO3H=G39SckRh7yaHy2TkwV3zxqpIOUv&ab5fe381e05cacaa8baa42b5bd758fb2=wMyQTO4gDM4ETNxETZ5YmYyIzN5EjMxUjZkBTM1UzMwYGZkdjYjVjNwAzM5EDO5IjMxIjNwczM&d5482f6c998a081ff9fb48bcf2314cee=QMjNmMmRmZygTZhhDO4EmYwYmMkVTZxMzNyMjNwkTNmFTOwIDZiJGZ
unknown
text
104 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1208
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
332
svchost.exe
224.0.0.252:5355
unknown
2528
AppLaunch.exe
91.103.252.23:80
232161cm.nyashtyan.top
Hostglobal.plus Ltd
GB
unknown

DNS requests

Domain
IP
Reputation
232161cm.nyashtyan.top
  • 91.103.252.23
unknown

Threats

PID
Process
Class
Message
332
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
2528
AppLaunch.exe
A Network Trojan was detected
ET MALWARE DCRAT Activity (GET)
2528
AppLaunch.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
2528
AppLaunch.exe
A Network Trojan was detected
ET HUNTING Observed Malicious Filename in Outbound POST Request (Information.txt)
1 ETPRO signatures available at the full report
No debug info