Source: Process started | Author: Markus Neis, Sander Wiebing: Data: Command: 'C:\Windows\system32\netsh.exe' advfirewall firewall add rule protocol=TCP name='uTorrent' dir=in action=allow program='C:\Users\user\AppData\Roaming\uTorrent\uTorrent.exe' enable=yes profile=public, CommandLine: 'C:\Windows\system32\netsh.exe' advfirewall firewall add rule protocol=TCP name='uTorrent' dir=in action=allow program='C:\Users\user\AppData\Roaming\uTorrent\uTorrent.exe' enable=yes profile=public, CommandLine|base64offset|contains: ijY, Image: C:\Windows\SysWOW64\netsh.exe, NewProcessName: C:\Windows\SysWOW64\netsh.exe, OriginalFileName: C:\Windows\SysWOW64\netsh.exe, ParentCommandLine: 'C:\Users\user\AppData\Local\Temp\is-CMJUV.tmp\3yYh0IvfZPkSsqrl.tmp' /SL5='$B0076,31402076,326656,C:\Users\user\AppData\Local\Temp\3yYh0IvfZPkSsqrl.exe' , ParentImage: C:\Users\user\AppData\Local\Temp\is-CMJUV.tmp\3yYh0IvfZPkSsqrl.tmp, ParentProcessId: 3008, ProcessCommandLine: 'C:\Windows\system32\netsh.exe' advfirewall firewall add rule protocol=TCP name='uTorrent' dir=in action=allow program='C:\Users\user\AppData\Roaming\uTorrent\uTorrent.exe' enable=yes profile=public, ProcessId: 3292 |
Source: 29.0.uTorrent.exe.400000.0.unpack | Avira: Label: TR/Crypt.ULPM.Gen |
Source: unknown | HTTPS traffic detected: 54.197.251.114:443 -> 192.168.2.3:49751 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 54.197.251.114:443 -> 192.168.2.3:49750 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 178.79.242.16:443 -> 192.168.2.3:49769 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.86.154.93:443 -> 192.168.2.3:49773 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.86.154.93:443 -> 192.168.2.3:49774 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 91.228.74.189:443 -> 192.168.2.3:49783 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 91.228.74.189:443 -> 192.168.2.3:49782 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 178.79.242.16:443 -> 192.168.2.3:49791 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.226.169.128:443 -> 192.168.2.3:49794 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.226.169.128:443 -> 192.168.2.3:49793 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.226.169.128:443 -> 192.168.2.3:49792 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.127.155:443 -> 192.168.2.3:49795 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.127.155:443 -> 192.168.2.3:49796 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.226.169.14:443 -> 192.168.2.3:49797 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.226.169.14:443 -> 192.168.2.3:49798 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 3.214.78.220:443 -> 192.168.2.3:49805 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 3.214.78.220:443 -> 192.168.2.3:49806 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 151.101.12.157:443 -> 192.168.2.3:49809 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 151.101.12.157:443 -> 192.168.2.3:49810 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 31.13.92.14:443 -> 192.168.2.3:49811 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 31.13.92.14:443 -> 192.168.2.3:49812 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.244.42.131:443 -> 192.168.2.3:49819 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.244.42.131:443 -> 192.168.2.3:49820 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 54.208.194.17:443 -> 192.168.2.3:49816 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.244.42.69:443 -> 192.168.2.3:49822 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.244.42.69:443 -> 192.168.2.3:49823 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.86.154.93:443 -> 192.168.2.3:49824 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.16.236.79:443 -> 192.168.2.3:49825 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.86.154.93:443 -> 192.168.2.3:49830 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 185.86.137.113:443 -> 192.168.2.3:49832 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 54.197.251.114:443 -> 192.168.2.3:49831 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 178.79.242.16:443 -> 192.168.2.3:49837 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 178.79.242.16:443 -> 192.168.2.3:49838 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 54.197.251.114:443 -> 192.168.2.3:49836 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 54.197.251.114:443 -> 192.168.2.3:49835 version: TLS 1.2 |
Source: yVn2ywuhEC.exe | Static PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT, HIGH_ENTROPY_VA |
Source: | Binary string: d:\Projects\WinRAR\SFX\build\sfxzip32\Release\sfxzip.pdb source: 3yYh0IvfZPkSsqrl.tmp, 00000005.00000003.454276597.0000000005C5E000.00000004.00000001.sdmp, 0i1CtyGdkmLhJnVs.tmp, 0000000D.00000003.479438192.000000000742E000.00000004.00000001.sdmp |
Source: | Binary string: X:\jenkins-workspace\workspace\token-wallet-pipeline\build\MinSizeRel\helper.pdb source: 3yYh0IvfZPkSsqrl.tmp, 00000005.00000003.455095967.000000000665E000.00000004.00000001.sdmp, 0i1CtyGdkmLhJnVs.tmp, 0000000D.00000003.483016018.0000000007E2E000.00000004.00000001.sdmp |
Source: C:\Users\user\AppData\Local\Temp\3yYh0IvfZPkSsqrl.exe | Code function: 1_2_00405BEC GetModuleHandleW,GetProcAddress,lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW, | 1_2_00405BEC |
Source: C:\Users\user\AppData\Local\Temp\is-CMJUV.tmp\3yYh0IvfZPkSsqrl.tmp | Code function: 5_2_004AD600 FindFirstFileW,GetLastError, | 5_2_004AD600 |
Source: C:\Users\user\AppData\Local\Temp\is-CMJUV.tmp\3yYh0IvfZPkSsqrl.tmp | Code function: 5_2_00408174 GetModuleHandleW,GetProcAddress,lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW, | 5_2_00408174 |
Source: C:\Users\user\AppData\Local\Temp\is-CMJUV.tmp\3yYh0IvfZPkSsqrl.tmp | Code function: 5_2_004FFC74 FindFirstFileW,SetFileAttributesW,DeleteFileW,FindNextFileW,FindClose, | 5_2_004FFC74 |
Source: unknown | Network traffic detected: DNS query count 48 |
Source: unknown | Network traffic detected: IP country count 35 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 82.221.103.244:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 67.215.246.10:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 189.250.0.174:1045 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 92.249.157.115:26816 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 69.119.127.215:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 161.230.30.190:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 180.245.10.11:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 89.240.209.7:16831 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 59.97.170.49:8000 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 206.188.117.12:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 27.57.254.186:62443 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 121.237.191.0:5366 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 91.103.78.235:56425 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 113.69.119.93:51413 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 173.172.64.220:50321 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 79.44.24.80:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 77.70.30.189:8999 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 81.183.59.95:17494 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 217.65.108.62:37033 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 94.36.132.239:51413 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 193.77.69.5:17572 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 87.92.146.184:24284 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 95.87.199.169:17642 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 86.92.71.126:19423 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 67.167.124.173:56507 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 89.64.54.152:12405 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 98.115.85.132:51413 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 47.55.190.78:52379 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 37.79.91.224:39349 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 185.14.28.165:55090 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 52.8.36.62:6911 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 3.211.230.23:6926 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 5.9.67.240:1910 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 119.8.127.135:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 49.34.70.36:63972 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 219.79.117.83:18994 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 121.45.79.34:49093 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 176.63.24.100:49269 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 208.110.106.75:54313 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 118.14.200.58:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 178.140.10.27:19559 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 213.136.79.7:11916 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 79.140.26.93:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 1.164.146.117:22338 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 134.249.127.48:34277 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 185.165.160.176:13329 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 126.142.30.153:51413 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 54.39.2.195:62898 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 149.255.29.135:49001 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 198.12.121.229:51413 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 112.168.71.78:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 88.90.139.39:22425 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 62.205.202.181:29690 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 183.167.31.157:5691 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 212.32.243.15:60160 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 94.251.128.6:1033 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 2.135.114.157:38811 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 176.65.116.74:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 195.38.11.55:8621 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 102.142.65.153:29101 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 94.190.193.153:50155 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 42.111.6.220:62544 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 80.251.153.186:49001 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 208.96.115.15:50321 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 2.61.72.86:50808 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 84.17.52.74:45381 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 18.218.241.3:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 92.240.51.15:25313 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 13.58.27.33:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 18.223.137.220:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 161.97.90.50:6882 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 110.87.72.111:18086 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 188.242.61.133:40343 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 84.107.14.129:6889 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 78.182.153.125:35027 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 54.194.137.170:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 210.6.117.216:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 38.121.71.145:6881 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 47.92.124.237:42260 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 188.163.58.192:23951 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 188.138.137.196:1152 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 212.46.18.149:3276 |
Source: global traffic | UDP traffic: 192.168.2.3:17720 -> 176.63.21.208:31987 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKx-amz-id-2: HyilXiFtOXAsln92CQqL/dAHcjYSH+NZKKPeIo4bscF/0otjHq+htbtggk5O8KuHu3fE4RhlOKA=x-amz-request-id: CB480E447BBB2D30Content-Type: binary/octet-streamServer: AmazonS3X-LLID: 3b3ebb0bab65070eb1152e6fc546d602Age: 24201Date: Sat, 30 Jan 2021 11:51:07 GMTLast-Modified: Wed, 13 Jan 2021 22:50:48 GMTContent-Length: 4901304Connection: closeData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 23 d0 9d 9a 67 b1 f3 c9 67 b1 f3 c9 67 b1 f3 c9 6e c9 60 c9 72 b1 f3 c9 67 b1 f2 c9 c1 b1 f3 c9 79 e3 66 c9 61 b1 f3 c9 6e c9 70 c9 6e b1 f3 c9 6e c9 77 c9 42 b1 f3 c9 6e c9 61 c9 66 b1 f3 c9 6e c9 67 c9 66 b1 f3 c9 6e c9 62 c9 66 b1 f3 c9 52 69 63 68 67 b1 f3 c9 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 05 00 16 1d e1 4d 00 00 00 00 00 00 00 00 e0 00 03 01 0b 01 09 00 00 ce 00 00 00 3a 02 00 00 00 00 00 fd 9a 00 00 00 10 00 00 00 e0 00 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 40 03 00 00 04 00 00 1a ab 4b 00 02 00 00 85 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 f0 fa 00 00 33 00 00 00 d4 ec 00 00 c8 00 00 00 00 f0 02 00 78 40 00 00 00 00 00 00 00 00 00 00 d8 8e 4a 00 e0 3a 00 00 00 00 00 00 00 00 00 00 90 e2 00 00 1c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 00 00 90 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 4b cc 00 00 00 10 00 00 00 ce 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 72 64 61 74 61 00 00 75 1b 00 00 00 e0 00 00 00 1c 00 00 00 d2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 64 61 74 61 00 00 00 d8 d9 01 00 00 00 01 00 00 02 00 00 00 ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 43 52 54 00 00 00 00 10 00 00 00 00 e0 02 00 00 02 00 00 00 f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 73 72 63 00 00 00 78 40 00 00 00 f0 02 00 00 42 00 00 00 f2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |